API

Detect a file

Check a file against the active marks in an Enterprise workspace.

POST/api/v1/detect

Checks a file against this key's workspace. The body is multipart/form-data.

Authentication

Authorization: Bearer mf_…

Send this header. There is no session cookie. curl and other server clients are accepted. A browser on another site is rejected.

Parameters

NameTypeRequiredDescription
filefileYesThe file to check. The match is looked up only in this key's workspace. A file marked in another workspace does not resolve.

Request

curl -X POST https://markedfile.com/api/v1/detect \
  -H "Authorization: Bearer mf_…" \
  -F "file=@leaked.pdf"

Response

{
  "id": "northwind",
  "confidence": 0.9,
  "layers": [
    {
      "name": "Opaque PDF fields",
      "hit": true,
      "detail": "1 authenticated field(s) recovered",
      "screenshot": "No",
      "crop": "No",
      "reencode": "No"
    }
  ],
  "notes": [
    "Confidence is a heuristic for validated layer matches, not a measured forensic probability."
  ]
}

id is the identifier you assigned when that copy was marked, or null when this workspace has no match. confidence is a heuristic for the validated layers, not a measured probability. layers lists the carriers, and hit is true on the ones that agreed. notes describes what the check did. A deleted file does not resolve.

Errors

The error field in the JSON body is English.

StatusDescription
400The file is empty.
401The key is missing, revoked, or unknown. The JSON body includes "code": "api-key".
403The workspace no longer has an active Enterprise plan (the body includes "code": "enterprise"), or the browser sent a cross-site or same-site fetch.
413The file is over the plan upload limit, or the PDF has more pages than the plan allows.
422The file could not be processed.
429This key has run more than 80 detections in the current minute.

Rate limit

80 requests per minute for this key. The counter is stored in the product database and survives a restart.