Upload a New File to the Root of the Storage disk.storage.uploadFile
Choose a tool for developing with an AI agent:
- use Alaio Vibecode to build an app for Bitrix24 from a task description without knowing any programming language. The agent writes the code and deploys the app to a server, with no manual hosting setup
- use the MCP server to develop a REST API integration in your own project. The agent refers to the official REST documentation
Scope:
diskWho can execute the method: a user with "Add" access permission for the required storage
The method disk.storage.uploadFile uploads a new file to the root of the storage.
Method Parameters
Required parameters are marked with *
|
Name |
Description |
|
id* |
Identifier of the storage where the file needs to be uploaded. The identifier can be obtained using the method disk.storage.getList |
|
data* |
An array with the field |
|
fileContent* |
An array containing the file name and a string with Base64 |
|
rights |
An array of access permissions for the uploaded file in the format
User categories:
The list of available |
|
generateUniqueName |
Generate a unique file name if a file with that name already exists. For example, file (1).docx. Possible values:
Default is |
Code Examples
How to Use Examples in Documentation
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"id":1357,"data":{"NAME":"picture.png"},"fileContent":["picture.png","iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII="],"generateUniqueName":true,"rights":[{"TASK_ID":79,"ACCESS_CODE":"U1271"}]}' \
https://**put_your_bitrix24_address**/rest/**put_your_user_id_here**/**put_your_webhook_here**/disk.storage.uploadFile
curl -X POST \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"id":1357,"data":{"NAME":"picture.png"},"fileContent":["picture.png","iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII="],"generateUniqueName":true,"rights":[{"TASK_ID":79,"ACCESS_CODE":"U1271"}],"auth":"**put_access_token_here**"}' \
https://**put_your_bitrix24_address**/rest/disk.storage.uploadFile
// This snippet is an ES module: top-level await requires type="module" or a bundler.
// $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
import { Text } from '@bitrix24/b24jssdk'
import type { B24Frame, ISODate } from '@bitrix24/b24jssdk'
declare const $b24: B24Frame
// Shape of the payload returned in result (match the "response handling" section of the page)
type UploadFileResult = {
ID: number
NAME: string
CODE: string | null
STORAGE_ID: string
TYPE: string
PARENT_ID: string
DELETED_TYPE: number
GLOBAL_CONTENT_VERSION: number
FILE_ID: number
SIZE: string
CREATE_TIME: ISODate
UPDATE_TIME: ISODate
DELETE_TIME: ISODate | null
CREATED_BY: string
UPDATED_BY: string
DELETED_BY: string | null
DOWNLOAD_URL: string
DETAIL_URL: string
}
try {
const response = await $b24.actions.v2.call.make<UploadFileResult>({
method: 'disk.storage.uploadFile',
params: {
id: 1357,
data: {
NAME: 'picture.png',
},
fileContent: [
'picture.png',
'iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII=',
],
generateUniqueName: true,
rights: [
{
TASK_ID: 79,
ACCESS_CODE: 'U1271',
},
],
},
requestId: Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
} else {
const result = response.getData()!.result
console.info(result.ID, result.NAME, result.DOWNLOAD_URL)
}
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
<script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
<script>
async function uploadFile() {
try {
// Initialize the SDK inside a Bitrix24 frame
const $b24 = await B24Js.initializeB24Frame()
const response = await $b24.actions.v2.call.make({
method: 'disk.storage.uploadFile',
params: {
id: 1357,
data: {
NAME: 'picture.png',
},
fileContent: [
'picture.png',
'iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII=',
],
generateUniqueName: true,
rights: [
{
TASK_ID: 79,
ACCESS_CODE: 'U1271',
},
],
},
requestId: B24Js.Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
return
}
const result = response.getData().result
console.info(result.ID, result.NAME, result.DOWNLOAD_URL)
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
}
document.addEventListener('DOMContentLoaded', uploadFile)
</script>
from b24pysdk.errors import BitrixAPIError, BitrixSDKException
try:
bitrix_response = client.disk.storage.uploadfile(
bitrix_id=1357,
data={
"NAME": "picture.png",
},
file_content=[
"picture.png",
"iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII=",
],
generate_unique_name=True,
rights=[
{
"TASK_ID": 79,
"ACCESS_CODE": "U1271",
},
],
).response
result = bitrix_response.result
print(result)
except BitrixAPIError as error:
print(
"Bitrix API error",
f"error: {error.error}",
f"error_description: {error.error_description}",
sep="\n",
)
except BitrixSDKException as error:
print(f"Bitrix SDK error: {error.message}")
except Exception as error:
print(f"Unexpected error: {error}")
try {
$response = $b24Service
->core
->call(
'disk.storage.uploadFile',
[
'id' => 1357,
'data' => [
'NAME' => 'picture.png'
],
'fileContent' => [
'picture.png',
'iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII='
],
'generateUniqueName' => true,
'rights' => [
[
'TASK_ID' => 79,
'ACCESS_CODE' => 'U1271'
]
]
]
);
$result = $response
->getResponseData()
->getResult();
echo 'Success: ' . print_r($result, true);
processData($result);
} catch (Throwable $e) {
error_log($e->getMessage());
echo 'Error uploading file: ' . $e->getMessage();
}
BX24.callMethod(
"disk.storage.uploadFile",
{
id: 1357,
data: {
NAME: "picture.png"
},
fileContent: [
'picture.png',
'iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII=',
],
generateUniqueName: true,
rights: [
{
TASK_ID: 79,
ACCESS_CODE: 'U1271'
}
]
},
function (result)
{
if (result.error())
console.error(result.error());
else
console.dir(result.data());
}
);
require_once('crest.php');
$result = CRest::call(
'disk.storage.uploadFile',
[
'id' => 1357,
'data' => [
'NAME' => 'picture.png'
],
'fileContent' => [
'picture.png',
'iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII='
],
'generateUniqueName' => true,
'rights' => [
[
'TASK_ID' => 79,
'ACCESS_CODE' => 'U1271'
]
]
]
);
echo '<PRE>';
print_r($result);
echo '</PRE>';
// client and ctx are already created — see the Go SDK section
res, err := client.Core().Call(ctx, "disk.storage.uploadFile", b24.Params{
"id": 1357,
"data": b24.Params{
"NAME": "picture.png",
},
"fileContent": []string{"picture.png", "iVBORw0KGgoAAAANSUhEUgAAAD4AAABDCAYAAADEfbZbAAAACXBIWXMAABJ0AAASdAHeZh94...RK5CYII="},
"generateUniqueName": true,
"rights": []b24.Params{
{
"TASK_ID": 79,
"ACCESS_CODE": "U1271",
},
},
})
if err != nil {
return fmt.Errorf("disk.storage.uploadFile: %w", err)
}
var item struct {
ID b24.ID `json:"ID"`
Name string `json:"NAME"`
StorageID b24.ID `json:"STORAGE_ID"`
Type string `json:"TYPE"`
ParentID b24.ID `json:"PARENT_ID"`
DeletedType int `json:"DELETED_TYPE"`
}
if err := json.Unmarshal(res.Result, &item); err != nil {
return fmt.Errorf("parse response: %w", err)
}
fmt.Println(item.ID, item.Name)
Response Handling
HTTP Status: 200
{
"result": {
"ID": 9035,
"NAME": "picture.png",
"CODE": null,
"STORAGE_ID": "1357",
"TYPE": "file",
"PARENT_ID": "8875",
"DELETED_TYPE": 0,
"GLOBAL_CONTENT_VERSION": 1,
"FILE_ID": 32895,
"SIZE": "1679",
"CREATE_TIME": "2026-02-02T16:01:59+02:00",
"UPDATE_TIME": "2026-02-02T16:01:59+02:00",
"DELETE_TIME": null,
"CREATED_BY": "1269",
"UPDATED_BY": "1269",
"DELETED_BY": null,
"DOWNLOAD_URL": "https://test.bitrix24.com/rest/download.json?auth=b8d880690000071b006e2cf2000004f50000078dbaf74c54ad1b4e4205aba7ab57a395&token=disk%7CaWQ9OTAzNSZfPWU5eXpWQXpsVmJrdFE0OTJ3azBKQzNFVFVMek5UMTRU%7CImRvd25sb2FkfGRpc2t8YVdROU9UQXpOU1pmUFdVNWVYcFdRWHBzVm1KcmRGRTBPVEozYXpCS1F6TkZWRlZNZWs1VU1UUlV8YjhkODgwNjkwMDAwMDcxYjAwNmUyY2YyMDAwMDA0ZjUwMDAwMDc4ZGJhZjc0YzU0YWQxYjRlNDIwNWFiYTdhYjU3YTM5NSI%3D.DJafMz5LAuRzlGbCxNLoGiCleoFwz1qGyj4iPf7n110%3D",
"DETAIL_URL": "https://test.bitrix24.com/company/personal/user/1269/disk/file/picture.png"
},
"time": {
"start": 1770051719,
"finish": 1770051719.707384,
"duration": 0.7073841094970703,
"processing": 0,
"date_start": "2026-02-02T16:01:59+02:00",
"date_finish": "2026-02-02T16:01:59+02:00",
"operating_reset_at": 1770052319,
"operating": 0.34273815155029297
}
}
Returned Data
|
Name |
Description |
|
result |
An array with file fields |
|
ID |
Identifier of the file |
|
NAME |
Name of the file |
|
CODE |
Symbolic code of the file |
|
STORAGE_ID |
Identifier of the storage where the file is located |
|
TYPE |
Type of the object |
|
PARENT_ID |
Identifier of the parent folder |
|
DELETED_TYPE |
Deletion status of the object. Possible values:
|
|
GLOBAL_CONTENT_VERSION |
Incremental version counter of the file |
|
FILE_ID |
Internal value of the file identifier |
|
SIZE |
Size of the file in bytes |
|
CREATE_TIME |
Date and time of file creation |
|
UPDATE_TIME |
Date and time of the last file update |
|
DELETE_TIME |
Date and time the file was moved to the trash |
|
CREATED_BY |
Identifier of the user who created the file |
|
UPDATED_BY |
Identifier of the user who made the last change |
|
DELETED_BY |
Identifier of the user who deleted the file |
|
DOWNLOAD_URL |
Link to download the file |
|
DETAIL_URL |
Link to open the file in the interface |
|
time |
Information about the execution time of the request |
Error Handling
HTTP Status: 400
{
"error":"ERROR_NOT_FOUND",
"error_description":"Could not find entity with id `X`"
}
|
Name |
Description |
|
error |
String error code. It consists of digits, Latin letters, and underscores. It may arrive empty — in that case only |
|
error_description |
Error message for the developer. Do not show it to the end user without processing |
Possible Error Codes
|
Code |
Description |
Value |
|
|
Invalid value of parameter |
Required parameter not specified |
|
|
Could not find entity with id |
Storage with the specified |
|
|
Error: required parameter NAME (DISK_BASE_SERVICE_22001) |
Required parameter |
|
|
Could not save file |
Failed to save the file. Check available space on the Drive and the correctness of the data encoding |
|
— |
Invalid rights format |
Invalid format of the |
|
|
Access denied |
Insufficient permissions to add the file |
Statuses and System Error Codes
HTTP Status: 4xx, 5xx
The errors described below are returned by the REST API itself, not by the logic of a specific method. They can arrive in response to any method.
|
Status |
Code |
Description |
|
|
|
An internal server error has occurred. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The server returned an unexpected response. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The request intensity limit has been exceeded |
|
|
|
The method is blocked because the request resource intensity limit has been exceeded. The block is lifted automatically once the accumulated execution time of the method no longer exceeds the limit |
|
|
|
The request contains no authorization data: neither an access token nor a webhook code was passed |
|
|
|
Methods are called over the HTTPS protocol only |
|
|
|
The REST API is blocked due to overload. This is a manual individual block. To have it lifted, contact Bitrix24 technical support |
|
|
|
REST API access is not active for this account. In Bitrix24 Cloud, check the current plan or trial status: Vibe+ plans include REST API access, while Essentials plans do not. A webhook receives a different error message — |
|
|
|
No active webhook with the specified user identifier and secret code was found |
|
|
|
No method with this name was found. The name is misspelled, the method does not exist in the REST API, or it is unavailable without the required scope |
|
|
|
The request requires broader permissions than the token has: for a webhook these are the permissions granted to it, for an application it is the scope. For an application, the error message ends with |
|
|
|
The access token has expired |
|
|
|
The application is installed, but the Bitrix24 administrator has granted access to it only to specific users |
|
|
|
The public part of the site is closed. To open it on an on-premise installation, disable the "Temporary closure of the public part of the site" option. Path to the setting: Desktop > Settings > Product Settings > Module Settings > Main Module > Temporary closure of the public part of the site |
Continue Learning
- Create a Folder in the Root of the Storage disk.storage.addFolder
- Get a list of files and folders in the root of the storage disk.storage.getChildren
- Get Description of Storage Fields disk.storage.getFields
- Get Application Storage Description disk.storage.getForApp
- Get a List of Available Storages disk.storage.getList
- Get Storage Types disk.storage.getTypes
- Get Storage Description disk.storage.get
- Rename Application Storage disk.storage.rename