# Get a photo upload URL

Operation ID: `patient.photoUploadUrl`

Return a pre-signed Wasabi S3-compatible PUT URL (valid 600 seconds) the client can upload a photo to directly. Requires a patient Bearer JWT.

## Public method

`getPhotoUploadUrl`

Signature: `patient.getPhotoUploadUrl()`

Return type: `Promise<PhotoUploadUrlResponse>`

## Authentication

Classification: **AUTHENTICATED**

Schemes: `bearerAuth`

## Prerequisites

None documented.

## HTTP

`GET /patients/photo/upload-url`

## Path parameters

None.

## Query parameters

None.

## Body parameters

None.

Request model: None.

## Request example

None declared in canonical OpenAPI.

## Success responses

| Status | Shape | Content type | Description |
|---|---|---|---|
| `200` | [`patient.PhotoUploadUrlResponse`](../models/patient.PhotoUploadUrlResponse.md) | application/json | Pre-signed upload URL |

## Success response examples

### 200

```json
{
  "key": "patients/patient-example-001/photo.png",
  "url": "https://example.com/uploads/patient-photo"
}
```

## Common errors

| Status | Shape | Content type | Description |
|---|---|---|---|
| `401` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | Authorization required — missing, invalid, expired, or non-patient Bearer JWT |
| `404` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | The authenticated patient has no FHIR Patient record |
| `503` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | Photo storage is not configured for this deployment |

## Error examples

### 401 — Missing or invalid access token

```json
{
  "error": "Authorization required"
}
```

### 404 — Patient not found

```json
{
  "error": "Patient not found"
}
```

### 503 — Photo storage not configured

```json
{
  "error": "Photo storage not configured"
}
```

## NodeJS / TypeScript implementation

```ts
import { HCSDK } from "@healthcloudai/hc-sdk";
```

```ts
const result = await patient.getPhotoUploadUrl();
```

## cURL

```bash
curl -X GET \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  'https://dev-api-patient.health.cloud/patients/photo/upload-url'
```

## Notes

None.

## Prepared Test Console scenario

No canonical scenario is currently associated.

## Real response

No approved real integration response is currently published. Unapproved candidates are never rendered as examples.
