Skip to content
POST /file/{id}/share

Grants one user, one team, or the whole organization the right to open and download the file. `level` must be `view` — a file has nothing to `use` and no settings to `edit`, and an `edit` grantee could re-share data pulled from a connection they may not see — so any other level is `400 invalid_share_level`. Re-granting the same grantee replaces the row rather than stacking one. The grantee must be an active member of this organization (or a team of it), and sharing with yourself is `403`, as on every other resource. A grantee opens the file with the same `GET /file/{id}/content` (and MCP `elaichi://file/{id}`) and sees it in `GET /file` with `access: "view"`; sharing never lets them share, revoke or delete it. Revoking, deleting or letting the file expire takes the access away. Audited as `file.shared`. Owner only, and there is no `file:share` permission to mirror — ownership is the gate. A caller who is not the owner gets `403` ("Only the owner…") whenever a tier reaches the file for them — an explicit grant, or `use` on its source connection or toolbox, restricted or not — because it is in their `GET /file` and they already know it exists; `404` when no tier resolves, including a listed row whose inherited chain has broken (`can_open: false` for a lapsed toolbox delegation or a deleted connection).

Path Parameters

idstring
required·

File id (file_…).

curl -X POST 'https://api.elaichi.ai/file/<id>/share' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json'
const response = await fetch('https://api.elaichi.ai/file/<id>/share', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
import os
import requests

url = "https://api.elaichi.ai/file/<id>/share"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}

response = requests.post(url, headers=headers)
print(response.json())