> ## Documentation Index
> Fetch the complete documentation index at: https://docs.classquill.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload Blog Image

> Upload an image to the `blog-images` Supabase storage bucket and return its public
URL (use as a post's `featured_image` or inline in `content`). By default the image
is stored under the calling key's OWN organisation.

* target=org (default) → `org/<org_id>/<uuid>-<filename>` (the key's own org).
* target=platform      → `platform/<brand>/<uuid>-<filename>`; reserved for EquateIt
  marketing sites — requires the key's platform-blog capability.

415 on an unsupported MIME type, 413 over 10 MB. Requires `blog:write`.



## OpenAPI

````yaml /openapi.json post /v1/blog-images
openapi: 3.1.0
info:
  title: ClassQuill Public API
  description: >-
    REST API for ClassQuill tutoring organisations. Pipe your sessions,
    invoices, payments, tutor earnings, students, and more into your own tools.
    Most endpoints are reads; a focused set of writes (each gated by a *:write
    scope) create or update data, including creating student/tutor/parent
    accounts.


    Authenticate every request with an org API key:

        Authorization: Token token=cq_live_...

    Mint keys in the ClassQuill app under Settings → Developers.
  version: 1.0.0
servers: []
security:
  - ApiKeyAuth: []
tags:
  - name: General
  - name: Sessions
  - name: Tutors
  - name: Students & Parents
  - name: Billing
  - name: Curriculum
  - name: Coursework
  - name: Operations
  - name: Pricing
  - name: Bookings
  - name: Blog
  - name: Reports
paths:
  /v1/blog-images:
    post:
      tags:
        - Blog
      summary: Upload Blog Image
      description: >-
        Upload an image to the `blog-images` Supabase storage bucket and return
        its public

        URL (use as a post's `featured_image` or inline in `content`). By
        default the image

        is stored under the calling key's OWN organisation.


        * target=org (default) → `org/<org_id>/<uuid>-<filename>` (the key's own
        org).

        * target=platform      → `platform/<brand>/<uuid>-<filename>`; reserved
        for EquateIt
          marketing sites — requires the key's platform-blog capability.

        415 on an unsupported MIME type, 413 over 10 MB. Requires `blog:write`.
      operationId: upload_blog_image_v1_blog_images_post
      parameters:
        - name: target
          in: query
          required: false
          schema:
            type: string
            description: org (default) | platform
            default: org
            title: Target
          description: org (default) | platform
        - name: brand
          in: query
          required: false
          schema:
            type: string
            description: equateit | classquill (platform only)
            default: classquill
            title: Brand
          description: equateit | classquill (platform only)
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/Body_upload_blog_image_v1_blog_images_post'
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BlogImageUploadResult'
        '401':
          description: Missing, malformed, revoked, or expired credentials.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '403':
          description: The credential lacks the scope this endpoint requires.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '422':
          description: Validation error — `error.details.errors` lists the fields.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: >-
            Rate limit exceeded — honour Retry-After and the RateLimit-*
            headers.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
components:
  schemas:
    Body_upload_blog_image_v1_blog_images_post:
      properties:
        file:
          type: string
          contentMediaType: application/octet-stream
          title: File
      type: object
      required:
        - file
      title: Body_upload_blog_image_v1_blog_images_post
    BlogImageUploadResult:
      properties:
        url:
          type: string
          title: Url
        path:
          type: string
          title: Path
        size_bytes:
          type: integer
          title: Size Bytes
      type: object
      required:
        - url
        - path
        - size_bytes
      title: BlogImageUploadResult
      description: >-
        POST /v1/blog-images result — the public URL of the uploaded image (use
        as a

        post's `featured_image` or inline in `content`), the storage path it was
        written

        to inside the `blog-images` bucket, and its size in bytes.
    ApiError:
      description: Canonical error envelope for every /v1 error response (4xx/5xx).
      properties:
        error:
          $ref: '#/components/schemas/ApiErrorBody'
      required:
        - error
      title: ApiError
      type: object
    ApiErrorBody:
      description: The `error` object every /v1 error response carries.
      properties:
        code:
          description: >-
            Stable machine-readable error code: bad_request, unauthorized,
            forbidden, not_found, conflict, validation_error, rate_limited, or
            internal_error.
          examples:
            - not_found
          title: Code
          type: string
        message:
          description: Human-readable explanation, safe to surface to end users.
          examples:
            - Session not found
          title: Message
          type: string
        status:
          description: The HTTP status code, repeated in the body.
          examples:
            - 404
          title: Status
          type: integer
        details:
          additionalProperties: true
          description: >-
            Error-specific context. 422 carries the field errors under `errors`;
            429 carries `retry_after_seconds`.
          title: Details
          type: object
      required:
        - code
        - message
        - status
      title: ApiErrorBody
      type: object
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: Org API key as `Token token=cq_live_...`

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.