Confirm Upload
Confirm a completed upload and bind it to a resource (step 2 of 2).
Call this after successfully PUTting your file to the presigned URL returned
by POST /uploads. Provide context_type and context_id to associate the
file with an existing workflow or assistant_session resource, or with the
selected workspace for playground. The file is moved to its final location
and status transitions from pending to uploaded.
This endpoint is idempotent: if the upload was already confirmed, the current state is returned without re-processing.
Storage quota is checked against the workspace at confirm time. If confirming
would exceed the workspace storage limit, a 402 is returned and the file
remains in its staging location (the upload record stays pending so you can
delete the staging file and try a smaller file).
Binding to a workspace-scoped resource requires the caller to hold at least the
editor role in that workspace (viewers get 403); the workspace is inferred from
the resource when X-Workspace-Id is omitted. Workspace membership is always
required (non-members get 404). The internal playground context replaces the
editor requirement with current platform-admin identity. API-key callers are
workspace-scoped already and bypass the role check for non-playground contexts.
Dual-auth: Bearer JWT or API key (scope uploads:write).
Authentication
Onepin live API key (op_live_...). Test and public keys are reserved in Phase 1.
Path parameters
Headers
Request
Type of resource this upload is being attached to: workflow, playground, or assistant_session.
ID of the resource to attach this upload to. Must be an existing resource of the given context_type that the caller has access to.

