GoHighLevel Conversations API

Upload File Attachments

POST/conversations/messages/upload

POST /conversations/messages/upload Post the necessary fields for the API to upload files. The files need to be a buffer with the key "fileAttachment". The allowed file types are: JPGJPEGPNGMP4MPEGZIPRARPDFDOCDOCXTXTMP3WAV The API will return an object with the URLs It takes 6 body fields, requires the conversations/message.write scope and authenticates with a sub-account (location) token.

Request and authentication

Method
POST
Full URL
https://services.leadconnectorhq.com/conversations/messages/upload
Scopes
conversations/message.write
Token type
Sub-account (location) token
Accepted auth
OAuth Access Token, Private Integration Token
API version header
Version: 2021-07-28
Schema verified
22 June 2026

Request body

JSON body fields. Nested objects are shown indented under their parent.

NameTypeDescription
conversationIdstring

Conversation Id

Example: ve9EPM428h8vShlRW1KT

contactIdstring

Contact Id

Example: ve9EPM428h8vShlRW1KT

workflowIdstring

Workflow Id

Example: ve9EPM428h8vShlRW1KT

campaignIdstring

Campaign Id

Example: ve9EPM428h8vShlRW1KT

locationIdrequiredstring
attachmentUrlsrequiredarray

Response fields

Top-level fields returned on a successful call.

NameTypeDescription
uploadedFilesrequiredobject
twilioMediaSidsarray

Twilio media SIDs for group SMS (when isGroupSms=true)

Example: MExxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Example request

Copy-paste ready. Swap YOUR_TOKEN for your access token or Private Integration Token.

curl -X POST 'https://services.leadconnectorhq.com/conversations/messages/upload' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Version: 2021-07-28' \
  -H 'Content-Type: application/json' \
  -d '{
    "conversationId": "ve9EPM428h8vShlRW1KT",
    "contactId": "ve9EPM428h8vShlRW1KT",
    "workflowId": "ve9EPM428h8vShlRW1KT"
  }'

Skip the schema lookup

Hylo gives your AI agent this schema — and the other 52 documented here — without you looking anything up. Ask in plain English; it picks the endpoint, fills the body, and can run the call against your own sub-account.

More conversations endpoints