Upload a receipt
curl --request POST \
--url https://api.grainledger.com/api/v1/transactions/{id}/attachments \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-fileconst form = new FormData();
form.append('file', '<string>');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://api.grainledger.com/api/v1/transactions/{id}/attachments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.grainledger.com/api/v1/transactions/{id}/attachments"
files = { "file": ("example-file", open("example-file", "rb")) }
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, files=files, headers=headers)
print(response.text){
"id": "<string>",
"fileName": "<string>",
"mimeType": "<string>",
"fileSize": 123,
"source": "<string>",
"createdAt": "2023-11-07T05:31:56Z"
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}Transactions
Upload a receipt
Attaches a PDF or image (JPEG, PNG, GIF, WebP, or HEIC) of up to 5 MB. Requires transactions:write.
POST
https://api.grainledger.com
/
api
/
v1
/
transactions
/
{id}
/
attachments
Upload a receipt
curl --request POST \
--url https://api.grainledger.com/api/v1/transactions/{id}/attachments \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-fileconst form = new FormData();
form.append('file', '<string>');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://api.grainledger.com/api/v1/transactions/{id}/attachments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.grainledger.com/api/v1/transactions/{id}/attachments"
files = { "file": ("example-file", open("example-file", "rb")) }
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, files=files, headers=headers)
print(response.text){
"id": "<string>",
"fileName": "<string>",
"mimeType": "<string>",
"fileSize": 123,
"source": "<string>",
"createdAt": "2023-11-07T05:31:56Z"
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}{
"code": "forbidden",
"message": "You do not have access to this organization.",
"error": "You do not have access to this organization.",
"details": {
"fields": [
{
"field": "amount",
"code": "invalid_type"
}
]
}
}Authorizations
ApiKeyAuthGrainOAuth2BearerAuth
Organization API key created in Grain Settings → API. The key determines the organization and is limited to its assigned resource scopes. Write scopes imply the corresponding read scope.
Headers
Required with OAuth access tokens for resource requests. Omit only for GET /api/v1/organizations. Optional with organization API keys; if supplied with an API key, it must match the key's organization.
Path Parameters
Resource ID
Last modified on October 10, 2026