Image Upload API

Upload an Image by API and Get a CDN URL Back

Upload an image from your app and get a CDN URL back. Three REST calls, presigned PUT, permanent public links or expiring signed ones. No SDK.

Image upload API

An image upload API has one job. Take the bytes of a JPEG or PNG out of your app and hand back a URL that renders in a browser. cdn22.net does that in three REST calls with no SDK to install, and a public image is live on a global CDN the moment the third call returns.

Here is the whole flow from curl. Step 1 posts the image metadata and gets back a presigned PUT target plus a file id. size is required and must be the exact byte count. type becomes the stored Content-Type, which is what decides whether a browser renders the image or downloads it.

bash
# 1. ask for a presigned upload URL
curl -sf -X POST https://api.cdn22.net/v1/files/<FOLDER_ID> \
  -H "Authorization: $CDN22_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"filesMetadata":[{"name":"avatar.png","size":48213,"type":"image/png"}]}'

# {"success":true,"urls":[{
#   "url": "https://<bucket>.s3.<region>.amazonaws.com/...&X-Amz-Signature=...",
#   "id":  "1b9d6bcd-bbfd-4b2d-9b5d-ab8dfbbd4bed",
#   "key": "<owner>/<folder>/avatar.png" }]}

# 2. PUT the bytes straight to storage. No Authorization header on this one.
curl -sf --upload-file ./avatar.png \
  -H "Content-Type: image/png" \
  "<PRESIGNED_URL>"

# 3. confirm, and the CDN URL goes live
curl -sf -X POST https://api.cdn22.net/v1/files/confirm-upload \
  -H "Authorization: $CDN22_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"ids":["1b9d6bcd-bbfd-4b2d-9b5d-ab8dfbbd4bed"]}'

# public image now at https://cdn.cdn22.net/<owner>/<folder>/avatar.png

Step 2 carries no Authorization header. The signature baked into the presigned URL is the authorization, and sending your API key on top of it returns 403 SignatureDoesNotMatch. That is the most common way this flow breaks the first time.

In JavaScript the same three calls split across your server and the browser. Keep the two key-bearing calls on the server so CDN22_API_KEY never ships to a client, and let the browser do only the PUT. A 12-megapixel phone photo then goes straight to storage instead of through your Node process.

js
// server: mint the presigned target and finalize
const api = 'https://api.cdn22.net/v1';
const auth = { Authorization: process.env.CDN22_API_KEY, 'Content-Type': 'application/json' };

export async function startImageUpload({ name, size, type }) {
  const res = await fetch(`${api}/files/${FOLDER_ID}`, {
    method: 'POST', headers: auth,
    body: JSON.stringify({ filesMetadata: [{ name, size, type }] }),
  });
  const { urls } = await res.json();
  return urls[0];                                  // { url, id, key }
}

export async function finishImageUpload(id) {
  await fetch(`${api}/files/confirm-upload`, {
    method: 'POST', headers: auth, body: JSON.stringify({ ids: [id] }),
  });
}

// browser: only the PUT, against the url your server returned
async function putImage(file, presignedUrl) {
  await fetch(presignedUrl, {
    method: 'PUT',
    headers: { 'Content-Type': file.type },
    body: file,
  });
}

That shape fits most places images enter a product. A CMS or an admin panel posts an editor upload and stores the returned URL on the row. An avatar form checks dimensions client-side, uploads, and writes the CDN URL to the user record. A product catalog pushes photos per SKU into one folder per product. A support widget attaches screenshots to a ticket. A bot re-hosts an incoming attachment so the link still resolves after the chat platform's own signature expires, which Discord bot file storage walks through end to end.

A few boundaries worth knowing before you wire this in. One metadata call covers up to 100 images and confirm-upload takes the matching ids in one batch. Your storage quota is checked at step 1, so an over-quota request fails there with a 400 instead of after the bytes have moved. For a file big enough that a single PUT is a liability, the same API exposes multipart upload, which splits it into parts you can send in parallel and retry individually.

Pass ttlSeconds with the metadata, anywhere from 60 seconds to 365 days, and the image is deleted automatically once it passes. Leave it out and the file stays until you call DELETE /v1/files/{id}.

A public image is a plain HTTPS CDN address with no token in it, so it works in an <img> tag, an email, a webhook payload, or an OpenGraph card, and it keeps resolving until you delete the file. There is no referrer check and no hotlink protection. Anything that should not be freely embeddable goes in a private folder instead, where no public URL is ever minted and your backend calls GET /v1/files/signed/{id}?expiresIn=SECONDS for a link valid between 60 seconds and 7 days, 600 seconds by default.

The one thing this API will not do is transform your images. cdn22.net serves the exact bytes you sent, so there is no resize query parameter and no automatic WebP or AVIF conversion. Generate the srcset sizes and formats you need with sharp, squoosh, a CI step, or your framework's image component, upload each variant, and the CDN delivers them all. That is also why nothing here bills per transformation.

Nothing is image-specific under the hood either, so JPEG, PNG, WebP, AVIF, GIF, and SVG take the same path as a PDF or a zip.

Pricing is prepaid credits, not a free image host. Storage, CDN delivery, and requests draw from one balance with no subscription and no separate egress line, so an image library that gets written once and read often costs what the bandwidth costs. Affordable CDN file hosting works through the arithmetic. To start, create a project, mint a key on your API keys page, and run the three calls above against a real folder.

The file upload API documents the same endpoints for non-image files, the image CDN covers the delivery side, and the file upload CLI is the shell version of this flow.

Benefits With No Complexity

Global CDN delivery

Your files are served from 450+ edge locations worldwide.

Edge-cached worldwide

Files are cached close to your users for fast delivery.

Signed-URL security

Private files stay protected with time-limited access.

What You Get

Unlimited files

Upload as many files as you need.

Unlimited storage

There is no storage limit.

Public + Private storage

Private files are fully secured.

CDN ready links

Upload directly to 450+ edge locations worldwide.

Prepaid credits

No subscription. Pay only for the storage and bandwidth you use.

More coming soon

We have plenty of features coming!

How cdn22.net Works

1. Upload

Create a project and upload your first file.

2. Copy

Copy the CDN link.

3. Use Anywhere

Paste and enjoy the blazing speed.

Why Developers Choose cdn22.net

A Better Way to Store & Deliver Files

ImgBB APICloudinaryUploadcareFilestackcdn22.net
On-the-fly resize and format transforms
Drop-in upload widget included
No per-transformation charges
Expiring signed URLs for private images
Per-file auto-delete TTL set at upload
Same endpoints store non-image files
Prepaid usage credits, no monthly plan

Calculate Your Needs

Storage

0GB

Egress

0GB

CDN Bandwidth

0GB
Total: $0.000/month

Need storage, egress, and request fees broken out — and compared against AWS list price for the same bytes? Use the CDN & storage cost calculator.

Upload Your First Image and Copy the URL

Create a project, mint an API key, and run the three calls. Prepaid usage covers the storage and bandwidth you actually use, with no subscription and no separate egress invoice.

  • Global CDN delivery
  • Edge-cached worldwide
  • Signed-URL security
  • Unlimited files
  • Unlimited storage
  • Public + Private storage
  • No subscription — prepaid credits keep spend predictable
Start Using the Image Upload API

Frequently Asked Questions

What are the exact API calls to upload an image and get a CDN URL?
Three. POST /v1/files/{folderId} with {"filesMetadata":[{"name","size","type"}]} returns {success, urls:[{url,id,key}]}; PUT the raw bytes to that presigned url with no auth header; POST /v1/files/confirm-upload with {"ids":[id]}. After confirm, a public image is served from its permanent CDN URL worldwide.
Is there a free image upload API tier?
No. cdn22.net runs on prepaid credits, so storage, CDN delivery, and API requests all draw from one balance and you pay for what you actually use, with no subscription and no per-seat pricing. If a permanently free host is the requirement, this is the wrong tool. If you need image URLs that still resolve two years into a product's life, prepaid usage is the trade you are making.
How do I authenticate an image upload?
Send your API key as the raw Authorization header value, with no Bearer prefix, on POST /v1/files/{folderId} and POST /v1/files/confirm-upload. The middle PUT takes no auth header at all, because the signature inside the presigned URL is the authorization; adding your key there returns 403 SignatureDoesNotMatch. Create and revoke keys on the API keys page in your dashboard, one per environment or service so a leak is contained.
What are the limits on an image upload?
One metadata call covers up to 100 images, and confirm-upload takes the same batch of ids. The size field is required and must be the exact byte count, since it is what the presigned PUT is signed against. Your storage quota is checked at step 1, so an over-quota batch fails with a 400 before any bytes move. For files large enough that one PUT is risky, use the multipart endpoints instead.
Can I hotlink the CDN image URL from anywhere?
Yes. A confirmed public image is a plain HTTPS CDN address with no token in it, so it works in an <img> tag, an email, a webhook payload, or an OpenGraph card, and it keeps working until you delete the file. There is no referrer check and no hotlink protection. If an image must not be freely embeddable, upload it to a private folder and hand out signed URLs instead.
How do I delete an image, or make it expire on its own?
DELETE /v1/files/{id} removes it and the CDN URL stops resolving. For automatic cleanup, pass ttlSeconds (60 seconds to 365 days) or an absolute expiresAt with the step 1 metadata: signed URLs stop being issued at the expiry instant and an hourly sweep removes the bytes. Archive-storage folders require at least 90 days, matching their minimum billed retention.
Does the API resize or convert images?
No. cdn22.net stores and serves the exact bytes you upload, so there is no resize query parameter and no automatic WebP or AVIF conversion. Generate the variants you need with sharp, squoosh, a build step, or your framework's image component, upload each one, and the CDN delivers them all. It is also why there is no per-transformation charge to model.
Is this only for images, or any file?
Any file. These are the general file endpoints, so a PDF, a zip, or a 300 MB video takes exactly the same three calls as a PNG. The page is image-focused because image intake is the most common first integration. See the file upload API page for the same flow described without the image framing.
General Questions
Is there a subscription?
No. cdn22.net uses prepaid credits, so storage, bandwidth, and API usage are deducted from your balance as you go. The app explains the payment step before uploads are enabled — no monthly subscription and no per-user fees.
What is cdn22.net?
cdn22.net is a developer-first file platform that makes it simple to store, secure, and deliver files globally. It provides signed URLs, public/private access, and an API-first design so you can integrate file delivery into any app without the usual complexity.
How does billing work?
cdn22.net uses prepaid credits. As you use storage, bandwidth, and API requests, credits are deducted daily. When your balance runs low, we automatically recharge it using your saved card. If an auto-recharge doesn't go through, your files and links stay put — you simply update your payment method or top up manually to keep going. No monthly subscriptions — just simple usage-based pricing.
How secure is my data?
All files are encrypted at rest and in transit. You can use signed URLs for private files, control access with permissions, and rely on enterprise-grade infrastructure for data protection.

Related

cdn22.net
Copyright © 2026
All rights reserved
ContactGuidesGlossaryStatusSecurityLegal