# Uploads

Create, finalize and revoke private image uploads.

 - [POST /v1/uploads](https://api-docs.shuffll.com/engage/openapi/uploads/uploads_create.md): Create a private PNG/JPEG/WebP upload (1–10485760 bytes). Finalize within 15 minutes; signed PUT capability lasts 2 hours and cannot overwrite. No remote URL ingestion.
 - [GET /v1/uploads/{id}](https://api-docs.shuffll.com/engage/openapi/uploads/uploads_get.md): Read upload status and finalization deadline. Revocation/expiry blocks finalization but does not revoke an already issued 2-hour storage capability.
 - [DELETE /v1/uploads/{id}](https://api-docs.shuffll.com/engage/openapi/uploads/uploads_revoke.md): Revoke an unfinished upload session. Existing storage PUT capability still lasts up to 2 hours; finalization is denied.
 - [POST /v1/uploads/{id}/finalize](https://api-docs.shuffll.com/engage/openapi/uploads/uploads_finalize.md): Verify completed owned object size, raster bytes and MIME, then atomically create a private ready asset.
