Drive API
List spaces, upload, download, move and delete files and folders, and manage sharing.
Drive stores files for your team. This API lists spaces, uploads, downloads, moves and deletes files, and manages sharing. In the product the containers are called spaces; the API calls them buckets.
Files are addressed by a key, a path-like name such as contracts/2026/acme.pdf. Folders are the parts of the path: a folder exists when a key starts with it. A key ending in / is a folder.
Endpoints
| Method | Path | What it does |
|---|---|---|
GET |
/orgs/{orgId}/drive/overview |
Recent files and storage by file type |
GET |
/orgs/{orgId}/drive/buckets |
List spaces (and files shared with you) |
POST |
/orgs/{orgId}/drive/buckets |
Create a space |
DELETE |
/orgs/{orgId}/drive/buckets/{bucketId} |
Delete a space |
GET |
/orgs/{orgId}/drive/buckets/{bucketId}/objects |
List a folder |
POST |
/orgs/{orgId}/drive/buckets/{bucketId}/objects |
Upload a file |
DELETE |
/orgs/{orgId}/drive/buckets/{bucketId}/objects?key= |
Delete a file or folder |
GET |
/orgs/{orgId}/drive/buckets/{bucketId}/download?key= |
Download a file |
POST |
/orgs/{orgId}/drive/buckets/{bucketId}/folders |
Create a folder |
POST |
/orgs/{orgId}/drive/buckets/{bucketId}/move |
Rename or move |
GET · POST |
/orgs/{orgId}/drive/buckets/{bucketId}/shares |
List or add shares |
DELETE |
/orgs/{orgId}/drive/buckets/{bucketId}/shares/{shareId} |
Remove a share |
Permissions
Access is decided per space, not per route.
- Team spaces (the shared workspace space and any custom spaces):
drive:readto list and download,drive:writeto upload, move and delete,drive:manageto create or delete a space and manage its shares. The resource is the space's key, so a role can be limited to one space. See Permissions reference. - Personal drives belong to one person. Only the owner, or people the owner has shared a folder with, can reach them. Permissions on roles do not apply to them.
A space you have no standing in answers 404 NOT_FOUND; one you can see but not change answers 403 FORBIDDEN.
Spaces
{
"id": "0190f700-…",
"key": "contracts",
"name": "Contracts",
"type": "custom",
"object_count": 128,
"total_bytes": 48211904,
"created_at": "2026-10-01T08:00:00Z"
}
type is user (a personal drive), org (the shared workspace space) or custom.
POST /drive/buckets takes key (lowercase letters, digits and hyphens, 2 to 63 characters, starting with a letter or digit; org and keys starting user- are reserved), name (up to 120 characters), and type. Use "type": "personal" for an extra personal drive owned by the caller: it needs a name, ignores key, and can only be created by a person, not an access key. Anything else creates a team space and needs drive:manage on that key. Response 201. Errors: 409 KEY_TAKEN, 400 VALIDATION_ERROR, 402 LIMIT_EXCEEDED.
DELETE /drive/buckets/{bucketId} answers 204. A space must be empty first (400 VALIDATION_ERROR, "bucket is not empty"). The shared workspace space and each person's main personal drive cannot be deleted.
The list response is { "buckets": [ … ], "shared": [ … ] }, where shared holds folders and files other people shared with you.
GET …/objects
List the contents of a folder, one level deep.
| Parameter | Notes |
|---|---|
prefix |
The folder, such as contracts/2026/. Empty for the top |
q |
Search by name within the folder and below |
limit |
Default 100, maximum 200 |
cursor |
The cursor from the previous page |
{
"data": {
"folders": [ { "prefix": "contracts/2026/", "name": "2026" } ],
"objects": [
{
"key": "contracts/acme.pdf",
"name": "acme.pdf",
"size": 184320,
"content_type": "application/pdf",
"sha256": "9f2c…",
"created_by": "0190f0a0-…",
"created_at": "2026-10-01T08:00:00Z",
"updated_at": "2026-10-04T09:00:00Z"
}
],
"cursor": "…"
}
}
cursor is absent on the last page.
POST …/objects (upload)
A multipart form with a file part and an optional key field. If key is left out, the file's own name is used. Uploading to an existing key replaces the file.
curl -s -X POST https://axisiq.co/api/v1/orgs/$ORG/drive/buckets/$BUCKET/objects \
-H "Authorization: Bearer $AXIS_KEY" \
-F "key=contracts/acme.pdf" -F "file=@acme.pdf"
Response 201 when the key is new, 200 when it replaced a file, both with the file object. A file over the upload limit is refused with 400 VALIDATION_ERROR and a message that states the limit. Free workspaces can also hit the storage cap (402 LIMIT_EXCEEDED).
Keys may be up to 1,024 bytes, cannot start with /, contain //, backslashes or control characters, and file keys must not end with /.
GET …/download?key=
Streams the file. The response includes ETag (the file's SHA-256), Last-Modified, and supports If-None-Match (answers 304) and Range for partial downloads. Images, PDFs, plain text, common video and audio are served for inline viewing; everything else, including HTML and SVG, is served as an attachment.
Folders, moving and deleting
POST …/folderswith{ "key": "contracts/2027/" }creates an empty folder. Response201{ "prefix": …, "name": … }.POST …/movewith{ "from": "contracts/old.pdf", "to": "contracts/2026/old.pdf" }renames a file. Give folder keys ending in/to move a whole folder. Response{ "moved": 1 }. Moving onto an existing key is409 KEY_TAKEN; moving between a file and a folder, or to the same place, is400 VALIDATION_ERROR.DELETE …/objects?key=deletes a file; with a key ending in/it deletes the whole folder. Response{ "deleted": 3 }. A folder move or delete that touches more than 2,000 files is refused with400 VALIDATION_ERROR; do it in smaller folders.
Important: Deletes cannot be undone.
Sharing
GET …/shares returns a plain array of shares. POST …/shares shares a folder, a file or the whole space in a personal drive or a team space. Only the drive's owner, or drive:manage on a team space, can do this. The shared workspace space has no shares; its roles decide access.
| Field | Type | Notes |
|---|---|---|
prefix |
string | The folder (ending /) or file key to share. Empty for everything |
email |
string | A member's email address. One of email, user_id or org_wide is required |
user_id |
string | Alternatively a member's id |
org_wide |
boolean | Share with the whole workspace |
mode |
string | Required: view or edit |
Response 201 with { id, prefix, grantee_id, grantee_name, org_wide, mode, created_at }. DELETE …/shares/{shareId} answers 204.
GET /orgs/{orgId}/drive/overview
Optional limit. Returns { "recent": [ … ], "types": [ { "content_type", "count", "bytes" } ] } across the spaces you can reach.
Related
- Content Studio: website images are uploaded through the content assets route
- PDF documents: generated PDFs are saved here
- In the product: Drive