> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.joincandidhealth.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.joincandidhealth.com/_mcp/server.

# Create Encounter Attachment V2

PUT https://api.joincandidhealth.com/api/encounter-attachments/v1/{encounter_id}/v2
Content-Type: multipart/form-data

Uploads a file to the encounter. The file will be stored in the
encounter's attachments.

Reference: https://docs.joincandidhealth.com/api-reference/encounter-attachments/v-1/create-with-description

## Authentication

- OAuth2 — send the obtained token as `Authorization: Bearer <token>`

## Servers

- `https://api.joincandidhealth.com` (Production, default)
- `https://api-staging.joincandidhealth.com` (Staging)
- `https://sandbox-api.joincandidhealth.com` (CandidSandbox)
- `https://staging-api.joincandidhealth.com` (CandidStaging)
- `http://localhost:5050` (Local)

## Request

### Path parameters

- `encounter_id` (UUID, required)

### Body (multipart/form-data)

This endpoint expects a multipart form containing a file.

- `attachment_file` (file, required) — The file for upload. The maximum file size is 25MB. The allowed mime types are: - application/pdf - image/png - image/jpeg - text/plain - text/csv - application/vnd.openxmlformats-officedocument.wordprocessingml.document - application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
- `attachment_type` (enum, required)
- `description` (string, optional)

## Response

### 200

- `UUID`

## Examples

**Request**

```json
{
  "attachment_file": "<file: <filename1>>",
  "attachment_type": "DOCUMENTATION"
}
```

**Response**

```json
"d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32"
```

**SDK Code**

```python
import requests

url = "https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2"

files = { "attachment_file": "open('<filename1>', 'rb')" }
payload = {
    "attachment_type": "DOCUMENTATION",
    "description": 
}
headers = {"Authorization": "<token>."}

response = requests.put(url, data=payload, files=files, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2';
const form = new FormData();
form.append('attachment_file', '<filename1>');
form.append('attachment_type', 'DOCUMENTATION');
form.append('description', '');

const options = {method: 'PUT', headers: {Authorization: '<token>.'}};

options.body = form;

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2"

	payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_file\"; filename=\"<filename1>\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_type\"\r\n\r\nDOCUMENTATION\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"description\"\r\n\r\n\r\n-----011000010111000001101001--\r\n")

	req, _ := http.NewRequest("PUT", url, payload)

	req.Header.Add("Authorization", "<token>.")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)
request["Authorization"] = '<token>.'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_file\"; filename=\"<filename1>\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_type\"\r\n\r\nDOCUMENTATION\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"description\"\r\n\r\n\r\n-----011000010111000001101001--\r\n"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2")
  .header("Authorization", "<token>.")
  .body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_file\"; filename=\"<filename1>\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_type\"\r\n\r\nDOCUMENTATION\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"description\"\r\n\r\n\r\n-----011000010111000001101001--\r\n")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2', [
  'multipart' => [
    [
        'name' => 'attachment_file',
        'filename' => '<filename1>',
        'contents' => null
    ],
    [
        'name' => 'attachment_type',
        'contents' => 'DOCUMENTATION'
    ]
  ]
  'headers' => [
    'Authorization' => '<token>.',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2");
var request = new RestRequest(Method.PUT);
request.AddHeader("Authorization", "<token>.");
request.AddParameter("undefined", "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_file\"; filename=\"<filename1>\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"attachment_type\"\r\n\r\nDOCUMENTATION\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"description\"\r\n\r\n\r\n-----011000010111000001101001--\r\n", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "<token>."]
let parameters = [
  [
    "name": "attachment_file",
    "fileName": "<filename1>"
  ],
  [
    "name": "attachment_type",
    "value": "DOCUMENTATION"
  ],
  [
    "name": "description",
    "value": 
  ]
]

let boundary = "---011000010111000001101001"

var body = ""
var error: NSError? = nil
for param in parameters {
  let paramName = param["name"]!
  body += "--\(boundary)\r\n"
  body += "Content-Disposition:form-data; name=\"\(paramName)\""
  if let filename = param["fileName"] {
    let contentType = param["content-type"]!
    let fileContent = String(contentsOfFile: filename, encoding: String.Encoding.utf8)
    if (error != nil) {
      print(error as Any)
    }
    body += "; filename=\"\(filename)\"\r\n"
    body += "Content-Type: \(contentType)\r\n\r\n"
    body += fileContent
  } else if let paramValue = param["value"] {
    body += "\r\n\r\n\(paramValue)"
  }
}

let request = NSMutableURLRequest(url: NSURL(string: "https://api.joincandidhealth.com/api/encounter-attachments/v1/d5e9c84f-c2b2-4bf4-b4b0-7ffd7a9ffc32/v2")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```