# Upload Apple Messages for Business review evidence

`POST /v1/amb/business-account-attachments`

Uploads a private PDF or MP4 for a later business submission and returns expiring download and preview links.

## Code samples

**CLI**

```sh
bird amb business-accounts attachments upload
```

Examples: [CLI](/docs/api/reference/create-amb-business-account-attachment.cli.md) · [cURL](/docs/api/reference/create-amb-business-account-attachment.curl.md)

## Example response `200`

```json
{
  "created_at": "2026-05-20T09:14:52Z",
  "updated_at": "2026-05-25T16:42:01Z",
  "id": "tca_01krdgeqcxet5s7t44vh8rt9mg",
  "status": "draft"
}
```

## Response body

- `created_at` (string, required)
- `updated_at` (string, required)
- `id` (string, required)
- `filename` (string, required): The uploaded file's name.
- `content_type` (string, required): The file's content type, determined from its contents.
- `size_bytes` (integer, required): The file's size in bytes.
- `description` (string): A short note describing what the file shows.
- `status` (string, required)

  Lifecycle of an attachment. `draft` is a file that has been uploaded but nothing
  has been registered or submitted with it yet, and it is discarded at its
  `expires_at`. `attached` means at least one registration has cited it, so it is
  kept permanently and can no longer be deleted.

  Possible values: `draft`, `attached`
- `download_url` (string, required): Short-lived signed URL for downloading or previewing the attachment. Valid for 24 hours from when the resource was fetched; request a fresh resource to obtain a new URL after expiry. Do not cache beyond `download_url_expires_at`. Registration authorities (10DLC and toll-free carriers) retrieve evidence via a separate, longer-lived token; this URL is not that token.
- `preview_url` (string): Optional signed URL for inline viewing on an isolated storage origin. Valid for one hour; fetch the attachment again to refresh it.
- `download_url_expires_at` (string, required): When `download_url` expires. Both fields are always present; the server returns an error rather than omitting them.
- `expires_at` (nullable string, required): When this attachment is discarded if nothing is registered or submitted with it. Null once its status is `attached`.

## Related resources

- [Should I use a Bird SDK or call the API directly?](/explained/platform/should-i-use-an-sdk-or-call-the-api-directly) (answer)
- [Build your first integration](/learn/paths/integration) (course)
- [Send your first email](/docs/get-started/send-your-first-email) (docs)

[Get an implementation brief](/learn/workspace?topic=api-basics)
