curl --request POST \
--url https://mcp.echozero.app/api/v1/uploads/generate-urls \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"mimeTypes": [
"image/png"
],
"type": "BOT_IMAGE"
}
'"<unknown>"{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Misc
Generate signed upload URLs
Mirrors GraphQL generateUploadUrls. If type is in auth-required types (e.g. AVATAR), x-api-key must resolve to a user.
POST
/
api
/
v1
/
uploads
/
generate-urls
curl --request POST \
--url https://mcp.echozero.app/api/v1/uploads/generate-urls \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"mimeTypes": [
"image/png"
],
"type": "BOT_IMAGE"
}
'"<unknown>"{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Authorizations
Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
application/json
Response
Signed URL rows.
The response is of type any.