Uploads a banner or product image.
POST
/api/hostedpaymentpages/images/upload
deprecated
Requires: HostedPaymentPage.HostedPaymentPages.Update, merchant scope.
Returns the generated blob filename plus its CDN preview URL. Accepts multipart/form-data (max 2 MB, max 4000x4000 pixels; gif, jpg, jpeg, png, or webp). The stored filename is server-generated; place the returned `blobName` in a page's `bannerImage` or `productImageBlobName`. Invalid uploads return a field-attributed 400 validation error.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
multipart/form-data
, required
| Field | Type | Description |
|---|---|---|
File
required |
string (binary) | The uploaded image content. The multipart filename is used only to read the claimed extension for the magic-byte cross-check; it never becomes the stored name. Required: the endpoint rejects a missing file with a field-attributed validation error. |
ExtraProperties
required |
object |
This request body has no documented fields.
Responses
200 OK
Body: HppImageUploadResultDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
blobName
required |
string | The server-generated blob filename (`{guid}.{ext}`). Passes the `HppImageBlobName` validator; assign it to `bannerImage` or `productImageBlobName` on a page create / update. nullable |
previewUrl
required |
string | The resolved CDN URL at which the stored image renders (`{cdn}/hosted-page-imgs/host/{blobName}`). nullable |
contentType
required |
string | The image MIME type derived from the verified magic bytes and stored on the blob. nullable |
width
required |
integer (int32) | The decoded image width in pixels. |
height
required |
integer (int32) | The decoded image height in pixels. |
sizeBytes
required |
integer (int64) | The stored byte size of the image. |
This response has no documented body fields.
400 Bad Request
Body:
Each item has these fields.
| Field | Type | Description |
|---|
This response has no body.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.