> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs-unsw-v6.advance-uac.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-unsw-v6.advance-uac.com/_mcp/server.

# Upload a supporting document in one step

POST https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/{id}/documents/content
Content-Type: multipart/form-data

Stores a supporting document against the application in a single call: send the file as a `multipart/form-data` part named `file` and the bytes go through this API to storage. The document is listed by GET .../documents immediately, with no confirmation step.

Limited to 10MB. For anything larger, use POST .../documents, which returns a presigned URL and sends the bytes straight to storage without passing through this API.

The filename and content type are taken from the multipart part. 404 if the application is unknown.

Reference: https://docs-unsw-v6.advance-uac.com/unsw-advance-institution-api/applications/upload-a-supporting-document-in-one-step

## Authentication

- `Authorization` header (bearer token, required) — Paste a Keycloak access token (no "Bearer " prefix)

## Servers

- `https://unsw-v6-dev.advance-uac.com/institution-api` (Dev, default)
- `https://unsw-v6-test.advance-uac.com/institution-api` (Test)

## Request

### Path parameters

- `id` (string, required)

### Body (multipart/form-data)

This endpoint expects a multipart form containing an optional file.

- `file` (file, optional)

## Response

### 201

The document was stored.

- `id` (string, optional)
- `filename` (string, optional) — The file's original name.
- `contentType` (string, optional)
- `sizeBytes` (long, optional) — Size in bytes. Null while the document is still `PENDING`.
- `status` (enum, optional) — `UPLOADED` when the file bytes are stored and can be downloaded. `PENDING` when the entry was created but the bytes never arrived — ask for a fresh upload URL and retry, or delete the entry.
  - Allowed values: `PENDING`, `UPLOADED`
- `uploadedBy` (string, optional) — The principal that uploaded it.
- `uploadedAt` (datetime, optional) — When the entry was created, which for a `PENDING` document is not when anything was uploaded.

## Errors

### 413 Content Too Large Error

The file is larger than 10MB.

- `any`

## Examples

**Request**

```json
{
  "file": "<file: [object Object]>"
}
```

**Response**

```json
{
  "id": "string",
  "filename": "string",
  "contentType": "string",
  "sizeBytes": 1,
  "status": "PENDING",
  "uploadedBy": "string",
  "uploadedAt": "2022-03-10T12:15:50-04:00"
}
```

**SDK Code**

```python
import requests

url = "https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content"

files = { "file": "open('[object Object]', 'rb')" }
headers = {"Authorization": "Bearer <token>"}

response = requests.post(url, files=files, headers=headers)

print(response.json())
```

```javascript
const url = 'https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content';
const form = new FormData();
form.append('file', '[object Object]');

const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};

options.body = form;

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content"

	payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"[object Object]\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001--\r\n")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"[object Object]\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001--\r\n"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content")
  .header("Authorization", "Bearer <token>")
  .body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"[object Object]\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001--\r\n")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content', [
  'multipart' => [
    [
        'name' => 'file',
        'filename' => '[object Object]',
        'contents' => null
    ]
  ]
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddParameter("undefined", "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"[object Object]\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001--\r\n", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]
let parameters = [
  [
    "name": "file",
    "fileName": "[object Object]"
  ]
]

let boundary = "---011000010111000001101001"

var body = ""
var error: NSError? = nil
for param in parameters {
  let paramName = param["name"]!
  body += "--\(boundary)\r\n"
  body += "Content-Disposition:form-data; name=\"\(paramName)\""
  if let filename = param["fileName"] {
    let contentType = param["content-type"]!
    let fileContent = String(contentsOfFile: filename, encoding: String.Encoding.utf8)
    if (error != nil) {
      print(error as Any)
    }
    body += "; filename=\"\(filename)\"\r\n"
    body += "Content-Type: \(contentType)\r\n\r\n"
    body += fileContent
  } else if let paramValue = param["value"] {
    body += "\r\n\r\n\(paramValue)"
  }
}

let request = NSMutableURLRequest(url: NSURL(string: "https://unsw-v6-dev.advance-uac.com/institution-api/institution/applications/id/documents/content")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```