API
Detect a file
Check a file against the active marks in an Enterprise workspace.
POST/api/v1/detect
Checks a file against this key's workspace. The body is multipart/form-data.
Authentication
Authorization: Bearer mf_…Send this header. There is no session cookie. curl and other server clients are accepted. A browser on another site is rejected.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| file | file | Yes | The file to check. The match is looked up only in this key's workspace. A file marked in another workspace does not resolve. |
Request
curl -X POST https://markedfile.com/api/v1/detect \
-H "Authorization: Bearer mf_…" \
-F "file=@leaked.pdf"Response
{
"id": "northwind",
"confidence": 0.9,
"layers": [
{
"name": "Opaque PDF fields",
"hit": true,
"detail": "1 authenticated field(s) recovered",
"screenshot": "No",
"crop": "No",
"reencode": "No"
}
],
"notes": [
"Confidence is a heuristic for validated layer matches, not a measured forensic probability."
]
}id is the identifier you assigned when that copy was marked, or null when this workspace has no match. confidence is a heuristic for the validated layers, not a measured probability. layers lists the carriers, and hit is true on the ones that agreed. notes describes what the check did. A deleted file does not resolve.
Errors
The error field in the JSON body is English.
| Status | Description |
|---|---|
| 400 | The file is empty. |
| 401 | The key is missing, revoked, or unknown. The JSON body includes "code": "api-key". |
| 403 | The workspace no longer has an active Enterprise plan (the body includes "code": "enterprise"), or the browser sent a cross-site or same-site fetch. |
| 413 | The file is over the plan upload limit, or the PDF has more pages than the plan allows. |
| 422 | The file could not be processed. |
| 429 | This key has run more than 80 detections in the current minute. |
Rate limit
80 requests per minute for this key. The counter is stored in the product database and survives a restart.