Transloadit
Pricing
  • File Uploads
  • File Importing
  • Batch Processing
  • Video Encoding
  • Audio Encoding
  • Image Processing
  • Document Processing
  • Artificial Intelligence
  • File Filtering & Security
  • Media Cataloging
  • File Compression
  • Code Evaluation
  • File Exporting
  • Smart CDN
  • View all services
  • Explore integrations
  • Explore live demos
  • Uppy
  • TransloaditKit
  • Android SDK
  • Node.js SDK
  • Python SDK
  • Ruby SDK
  • Go SDK
  • Java SDK
  • PHP SDK
  • Zapier
  • MCP Server
  • Transloadit CLI
  • Terraform
  • Essentials
  • Best Practices
  • FAQ
  • Robots
  • API
  • Formats
  • Build your first app
  • About
  • Comparisons
  • Open Source
  • Testimonials
  • Jobs
  • Security
  • Posts
  • DevTimes
  • DevTips
  • Press
  • Research
  • Case Studies
  • Solutions
  • Guides
  • Glossary
  • Legal
  • Tools
  • Helping Coursera bring education to millions around the world
  • Transloadit Support
  • Open Source Support
  • Service level agreement
EssentialsRobotsFAQAPIFormatsBest Practices

How can I make sure that an image is actually from my correct user?

Your application’s backend must authenticate the user and authorize the upload. Keep the Transloadit Auth Secret on that trusted backend. Derive permitted instructions from the authenticated session; blindly signing a browser-supplied user ID does not verify it.

Signature Authentication protects the exact serialized params string. For ordinary signed requests, changing params.fields after signing invalidates the signature. It does not sign separate multipart fields or uploaded file bytes. A later unsigned multipart field can replace a same-named signed field in the merged Assembly fields, so signing params.fields.user_id does not make the final fields.user_id trustworthy.

Enable Signature Authentication for your Workspace when accepting signed browser requests. Include a short-lived auth.expires and return the original serialized params with its signature. Expiration limits the reuse window; it is not a single-use guarantee. Assembly creation can reuse identical signed params before expiry, including params with a nonce. A copied request does not prove that its sender is still logged in. Valid Bearer authentication satisfies the signature requirement without checking a supplied signature; protect Bearer tokens according to their scope.

For an association controlled by your application, create the Assembly from your trusted backend and record its returned assembly_id with the authenticated user. Follow the Resumable Uploads guide to let the client upload files to that existing Assembly, and keep its upload access private. This is a different integration from Uppy’s Transloadit plugin, which creates the Assembly from the browser using assemblyOptions.

Before granting access to results, check the Assembly Status against your app-owned record. For Webhooks, first verify the delivery’s signature, then check its Assembly ID against that record. Do not derive ownership from returned fields or an Assembly ID claimed by a client. This records the upload your application authorized; it does not establish who created the image or prove the contents of the uploaded bytes.

See also:

How can I limit the size of files uploaded by my users?
How to rename files when exporting them to cloud storage?
What if videos enter an image workflow?
Contact support⁠

TransloaditChecking status…

Product

  • Services
  • Pricing
  • Demos
  • Tools
  • Security
  • Support

Company

  • About/Press
  • Blog/Jobs
  • Comparisons/Compliance matrix
  • Research
  • Open source
  • Solutions
  • Pioneers of the web

Docs

  • Getting started
  • Transcoding
  • FAQ
  • API
  • Guides/DevTips
  • Supported formats

More

  • Platform status⁠
  • Community forum⁠
  • Uppy
  • tus⁠

© 2009–2026 Transloadit-II GmbH

PrivacyTermsImprint
EnglishDeutschEspañolPortuguês (Brasil)