## Publish uploaded files

`POST /v1/chats/:chatId/files/uploads/publish`

Creates one message with previously uploaded files. `uploadIds` contains IDs from the upload route responses. Repeating after an unknown outcome can create a second message: the client needs its own idempotency ledger.

## Parameters

| Parameter | Type | Required | Description |
|-----------|------|:--------:|-------------|
| `chatId` (path) | number | yes | Chat ID |
| `uploadIds` (body) | number[] | yes | 1 to 10 positive IDs |
| `message` (body) | string | no | Caption |
| `replyId` (body) | number | no | Message ID to reply to |
| `asFile` (body) | boolean | no | Send as a file |
| `templateId` (body) | string | no | Template ID |

Requires the `im` scope and a write-enabled key. Other fields and query parameters are rejected with `400 INVALID_PARAMS`.

## Examples

### curl — personal key

```bash
curl -X POST https://vibecode.bitrix24.com/v1/chats/42/files/uploads/publish \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"uploadIds":[7701],"message":"Caption"}'
```

### curl — OAuth application

```bash
curl -X POST https://vibecode.bitrix24.com/v1/chats/42/files/uploads/publish \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"uploadIds":[7701],"message":"Caption"}'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/42/files/uploads/publish', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({"uploadIds": [7701], "message": "Caption"}),
})
const { success, data, error } = await res.json()
console.log(success ? data : error)
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/42/files/uploads/publish', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({"uploadIds": [7701], "message": "Caption"}),
})
const { success, data, error } = await res.json()
console.log(success ? data : error)
```

## Response fields

| Field | Type | Description |
|------|-----|---------|
| `success` | boolean | `true` on success |
| `data.messageId` | number | ID of the created message |

## Response example

```json
{
  "success": true,
  "data": {
    "messageId": 52601
  }
}
```

## Error response example

```json
{
  "success": false,
  "error": {
    "code": "INVALID_PARAMS",
    "message": "`uploadIds` must be an array of 1 to 10 positive integers."
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|---------|
| 400 | `INVALID_PARAMS`, `INVALID_CHAT_ID` | Invalid body, chat ID, or unexpected parameters |
| 401 | `TOKEN_MISSING` | No Bitrix24 access tokens |
| 403 | `SCOPE_DENIED`, `WRITE_BLOCKED_READONLY_KEY`, `BITRIX_ACCESS_DENIED` | Missing scope, write permission, or Bitrix24 access |
| 404 | `ENTITY_NOT_FOUND` | Chat or file not found |
| 422 | `BITRIX_ERROR` | Other Bitrix24 refusal |
| 429 | `QUEUE_TIMEOUT` | Bitrix24 request queue is busy |

Files are published in one message. The platform does not retry; after an unknown outcome, check your own state before another call to avoid a duplicate. Named refusals can map to `400`, `403`, or `404`; `error.b24Code` is not guaranteed.

Full list of common API errors — [Errors](/docs/errors).

## See also

- [Upload to folder](/docs/chats/files/upload-to-folder)
- [Check existence](/docs/chats/files/upload-status)
- [Discard file](/docs/chats/files/upload-discard)
- [Chat files](/docs/chats/files)
