Create an artifact upload session
curl --request POST \
--url https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_type": "support_bundle",
"total_size": 2,
"part_count": 2,
"checksum": "<string>",
"part_size": 123,
"content_type": "<string>"
}
'import requests
url = "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts"
payload = {
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_type": "support_bundle",
"total_size": 2,
"part_count": 2,
"checksum": "<string>",
"part_size": 123,
"content_type": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
operation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
artifact_type: 'support_bundle',
total_size: 2,
part_count: 2,
checksum: '<string>',
part_size: 123,
content_type: '<string>'
})
};
fetch('https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'operation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'artifact_type' => 'support_bundle',
'total_size' => 2,
'part_count' => 2,
'checksum' => '<string>',
'part_size' => 123,
'content_type' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts"
payload := strings.NewReader("{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"artifact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"client_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"storage_key": "<string>",
"status": "pending",
"part_size": 123,
"part_count": 123,
"missing_parts": [
123
],
"management_operation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"client_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"type": "support_bundle",
"status": "queued",
"requested_by_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"started_at": "2023-11-07T05:31:56Z",
"completed_at": "2023-11-07T05:31:56Z",
"execution_time": "2023-11-07T05:31:56Z"
}
}
}{
"http_status": 400,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The JSON payload could not be unmarshalled."
}
]
}{
"http_status": 401,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "login",
"message": "Unauthorized"
}
]
}{
"http_status": 403,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "You do not have permission to access this resource"
}
]
}{
"http_status": 404,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The requested client could not be found."
}
]
}{
"http_status": 409,
"timestamp": "2026-07-01T13:44:43.247Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "",
"message": "management operation already has an associated artifact"
}
]
}{
"http_status": 429,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "middleware",
"message": "Too many requests. Please try again later."
}
]
}{
"http_status": 500,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The request could not be handled due to an unexpected database error."
}
]
}Clients
Create an artifact upload session
Endpoint for clients to create an artifact upload session and associate it with a running management operation.
Note: caller must be a client. For users, this endpoint will return a 403 as they are not expected or allowed to call this endpoint.
POST
/
api
/
v2
/
clients
/
management
/
artifacts
Create an artifact upload session
curl --request POST \
--url https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_type": "support_bundle",
"total_size": 2,
"part_count": 2,
"checksum": "<string>",
"part_size": 123,
"content_type": "<string>"
}
'import requests
url = "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts"
payload = {
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_type": "support_bundle",
"total_size": 2,
"part_count": 2,
"checksum": "<string>",
"part_size": 123,
"content_type": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
operation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
artifact_type: 'support_bundle',
total_size: 2,
part_count: 2,
checksum: '<string>',
part_size: 123,
content_type: '<string>'
})
};
fetch('https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'operation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'artifact_type' => 'support_bundle',
'total_size' => 2,
'part_count' => 2,
'checksum' => '<string>',
'part_size' => 123,
'content_type' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts"
payload := strings.NewReader("{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-tenant.bloodhoundenterprise.io/api/v2/clients/management/artifacts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"operation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"artifact_type\": \"support_bundle\",\n \"total_size\": 2,\n \"part_count\": 2,\n \"checksum\": \"<string>\",\n \"part_size\": 123,\n \"content_type\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"artifact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"client_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"storage_key": "<string>",
"status": "pending",
"part_size": 123,
"part_count": 123,
"missing_parts": [
123
],
"management_operation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"client_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"artifact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"type": "support_bundle",
"status": "queued",
"requested_by_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"started_at": "2023-11-07T05:31:56Z",
"completed_at": "2023-11-07T05:31:56Z",
"execution_time": "2023-11-07T05:31:56Z"
}
}
}{
"http_status": 400,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The JSON payload could not be unmarshalled."
}
]
}{
"http_status": 401,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "login",
"message": "Unauthorized"
}
]
}{
"http_status": 403,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "You do not have permission to access this resource"
}
]
}{
"http_status": 404,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The requested client could not be found."
}
]
}{
"http_status": 409,
"timestamp": "2026-07-01T13:44:43.247Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "",
"message": "management operation already has an associated artifact"
}
]
}{
"http_status": 429,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "middleware",
"message": "Too many requests. Please try again later."
}
]
}{
"http_status": 500,
"timestamp": "2024-02-19T19:27:43.866Z",
"request_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"errors": [
{
"context": "clients",
"message": "The request could not be handled due to an unexpected database error."
}
]
}Authorizations
JWTBearerTokenSignedRequest & RequestDate & HMACSignature
Authorization: Bearer $JWT_TOKEN
Headers
Prefer header, used to specify a custom timeout in seconds using the wait parameter as per RFC7240. Passing in wait=-1 bypasses all timeout limits when the feature is enabled.
Pattern:
^wait=(-1|[0-9]+)$Body
application/json
Available options:
support_bundle Required range:
x >= 1Required range:
x >= 1Available options:
sha256, sha512 Hex-encoded checksum for the completed artifact.
Optional upload part size. When omitted or zero, the server default is used.
Optional artifact content type. Support bundle uploads default to application/zip.
Response
OK
Show child attributes
Show child attributes