List Storage assets
Lists bounded pages of Workspace assets with stable identities and current version metadata.
https://api2.transloadit.com/ dam/ assetsReturns metadata for current live assets in the authenticated Workspace, without downloading their bytes.
Pass next_cursor back as cursor with the same prefix to read the next page. Stop when next_cursor is null. Pages are bounded and do not form a snapshot: concurrent moves, writes, or deletion can change later pages.
The returned asset and version IDs can be saved and used with /transloadit/import. Use a trailing slash in the prefix to select a directory boundary, such as photos/ rather than photos.
Request example
Run this request in a server-side shell with curl and a suitable bearer token in TRANSLOADIT_TOKEN. If you need a token, expand the setup below.
Need a bearer token?
In a trusted server-side shell with curl and jq, set TRANSLOADIT_KEY and TRANSLOADIT_SECRET to your Auth Key and Auth Secret. Keep both credentials and the resulting token secret; never run this setup in browser code.
First, create a token with this endpoint’s required scopes. Your Auth Key must already grant those scopes.
if ! TOKEN_RESPONSE="$(curl --fail-with-body -sS \
--request POST \
--url 'https://api2.transloadit.com/token' \
--user "${TRANSLOADIT_KEY:?Set TRANSLOADIT_KEY}:${TRANSLOADIT_SECRET:?Set TRANSLOADIT_SECRET}" \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'aud=api2' \
--data-urlencode 'scope=dam:read dam:write')"; then
printf '%s\n' "$TOKEN_RESPONSE" >&2
exit 1
fi
TRANSLOADIT_TOKEN="$(printf '%s' "$TOKEN_RESPONSE" |
jq -er '.access_token | strings | select(length > 0)')" || exit 1
Keep this shell open and run the request below. Reuse the token while it remains valid.
curl --fail-with-body -sS --request GET --get \
--url "https://api2.transloadit.com/dam/assets" \
--header "Authorization: Bearer ${TRANSLOADIT_TOKEN:?Set TRANSLOADIT_TOKEN}" \
--data-urlencode 'params={"prefix":"photos/","limit":100}'
Authentication
This endpoint accepts signed params or a bearer token. See Authentication for setup instructions.
Required scopes for the Auth Key or bearer token: dam:read, dam:write.
Signed requests require both a signature and a future params.auth.expires timestamp. Bearer tokens do not require either.
Query parameters
params(JSON string). A JSON-encoded object whose supported keys are listed below.signature(string). Required for signed requests. Omit this field when using a bearer token.
Supported keys inside the signed params field
Authentication fields in this list apply to signed requests. With a bearer token, you can omit params.auth and the separate signature field. Compare the authentication-specific request parameters below.
Complete JSON Schema
params: Only the fields listed for this object are accepted.
| Field | Type and description |
|---|---|
params.required for signed requests; optional with a bearer token | Contains the Transloadit API key and signature-authentication metadata for a Storage metadata request.
|
params.required | stringISO 8601 expiration timestamp in the future. Required when a request is signed or requires signature authentication; bearer-authenticated requests may omit it. |
params.required | stringTransloadit API key used to authenticate requests |
params. | string | integerUnique, random value included in signed request params to make each signature unique and prevent accidental signature reuse. |
params. | string (minimum length: 1, maximum length: 512)Opaque continuation value from next_cursor in the previous response. Keep the same prefix while paging. Omit for the first page. |
params. | integer (default: 100, minimum: 1, maximum: 500)Maximum number of assets per page. Defaults to 100 and accepts up to 500; follow next_cursor until null. |
params. | string (default: "", maximum length: 512)Only list current asset paths starting with this case-sensitive prefix. The empty default includes the whole Workspace; include a trailing slash to select a directory boundary. |
Request parameters by authentication method
With signed params
Include your Auth Key as params.auth.key. When signing the request, include a future params.auth.expires timestamp and send the signature in the separate signature field. The field definitions below use paths inside params.
Complete JSON Schema
params: Only the fields listed for this object are accepted.
Uses the field definitions above: params.auth, params.cursor, params.limit, params.prefix
With a bearer token
Send the bearer token in the Authorization header. You can omit params.auth and the separate signature field. Other required parameters still apply. The field definitions below use paths inside params.
Complete JSON Schema
params: Only the fields listed for this object are accepted.
Uses the field definitions above: params.cursor, params.limit, params.prefix
| Field | Type and description |
|---|---|
params. | Contains the Transloadit API key and signature-authentication metadata for a Storage metadata request.
|
params. | stringISO 8601 expiration timestamp in the future. Required when a request is signed or requires signature authentication; bearer-authenticated requests may omit it. |
params. | stringTransloadit API key used to authenticate requests |
params. | string | integerUnique, random value included in signed request params to make each signature unique and prevent accidental signature reuse. |
Response
Here’s an example response body:
{
"assets": [
{
"asset_id": "AAAAAAAAAAAAAAAAAAAAAA",
"height": 600,
"mime": "image/jpeg",
"path": "renamed.jpg",
"size": 12345,
"version_id": "AAAAAAAAAAAAAAAAAAAAAQ",
"width": 800,
"workspace": "example-workspace"
}
],
"message": "The Storage assets were successfully listed.",
"next_cursor": null,
"ok": "DAM_ASSETS_LISTED",
"workspace": "example-workspace"
}2xx success
JSON response body. application/json text/plain; charset=utf-8
Response body schema
Complete JSON Schema
The response contains only the fields listed for this object.
| Field | Type and description | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
assetsrequired | Array<object>Array item schema
| ||||||||||||||||||||||
messagerequired | string (minimum length: 1) | ||||||||||||||||||||||
next_cursorrequired | null | string | ||||||||||||||||||||||
okrequired | string (always: "DAM_ASSETS_LISTED") | ||||||||||||||||||||||
workspacerequired | string (minimum length: 1)Workspace slug that owns this asset. Authenticate for the same Workspace when reading or managing it. |
Error response
JSON response body. application/json text/plain; charset=utf-8
Response body schema
Complete JSON Schema
The response may contain additional fields.
| Field | Type and description |
|---|---|
assembly_id | string |
error | string (minimum length: 1) |
http_code | number | string
|
message | stringHuman-readable explanation of the error. Its wording can vary; use the |
reason | null | string | number | boolean | Array<any value> | objectAny of the following schemas may apply: nullnullstringstringnumbernumberbooleanbooleanArray<any value>Array<any value>Array item schemaany valueobjectobjectAdditional property schemaany value |