Upload control with signed uploads
Signed uploads enable flexible access control for project uploads. You can configure granular access by specifying scope and operation limits. Signed uploads work with File Uploader, jQuery File Uploader (deprecated), and Upload API.
Enable signed uploads
- Go to your Dashboard and select an existing project or create a new one.
- Click Enable next to Signed Uploads in the uploading settings.
Once enabled, uploads without a valid credential are rejected. Make sure your backend issues credentials to your clients before you turn the setting on.
Credentials
There are two kinds of credentials. Both are generated on your backend:
- Token: Time-limited JWT (up to 24 hrs) that can restrict upload methods and total operation count. Use for all new integrations and granular access control.
- Signature, (deprecated), pair of request parameters with no method or count restrictions before expiration.
Note: For control over your upload spend and security, use tokens for new integrations.
All integration details are described in the Upload API authentication reference.
File Uploader integration
For File Uploader, set the secure signature and secure expire options directly, or use secureUploadsSignatureResolver to fetch a fresh signature automatically as it nears expiration.
Note: jQuery File Uploader was deprecated on September 1, 2025. The signed uploads integration still works, but we recommend migrating to File Uploader.