Getting Started

The LobFile API will allow you (or an application you are writing/using) to automate tasks like uploading and managing your files.

To use this API, you need an API Key. Access to the API is free, no matter what plan tier you have. Your API key can be found on the Account Info section of the dashboard once you have created an account, verified your Email, and logged in.

If you find this service useful, or if you need more performance out of LobFile (like faster downloads or more account space), please consider subscribing to one of the Plans that are available.

If you find any issues or find the documentation to be incomplete or not working, feel free to send me a message in Discord or via Email.


Rate Limits

LobFile is configured with a global rate limit of 2 requests per second per IP, shared across lobfile.com, lithi.io and lithi.pw. Short bursts above that are tolerated. If you exceed this rate limit you will receive a HTTP status code of 429. Downloads are also capped at 24 at a time per IP, and further connections get the same 429.

Please be respectful with your use of the API in your integration and use case. If for some reason you need a higher rate limit, let me know on Discord or via Email.


API Requests

The only API endpoint that requires formData instead of JSON is UPLOAD . The other endpoints return JSON. DELETE-FILES and TOGGLE-FAVORITE take a JSON body, the GET endpoints take query parameters or nothing, and each one answers 405 to the wrong HTTP method. File downloads return the file itself.

Be sure to review and follow the examples provided in this documentation when building your integration. They will provide working cURL examples to show you the correct structure for requests and the expected responses.


API Responses

All HTTP requests will respond with the most relevant HTTP status code. A HTTP status code of 200 means the request was fully successful.

API response bodies are application/json, file downloads aside. However, you must plan for cases where the server cannot return valid JSON (for example, server issues, network edge errors, or rate limits). Your integration should detect non-JSON responses and handle them gracefully.

All responses include a 'success' boolean. When success is false, an 'error' object is present with a 'message' and a 'code' to branch on. UPLOAD is the exception: its 'error' is a plain string. Otherwise, expect whatever fields are documented for the specific endpoint.

CodeStatusMeaning
AUTH_REQUIRED401No API key was sent.
AUTH_INVALID_KEY401The API key does not match an account.
ACCOUNT_NOT_VERIFIED401The account's Email has not been verified yet.
METHOD_NOT_ALLOWED405Wrong HTTP method for the endpoint.
INVALID_INPUT400The JSON body is missing or not the documented shape.
FILE_NOT_FOUND404TOGGLE-FAVORITE: no such file on the account.
LOOKUP_FAILED500GET-FILE-LIST: usage could not be read.
LOOKUP_ERROR500TOGGLE-FAVORITE: the new state could not be read back.
INTERNAL_LOOKUP_ERROR500GET-ACCOUNT-INFO: the account could not be read.

Example JSON (200 Success):

{
  "success": true,
  "url": "https://lobfile.com/file/example.zip"
}

Example JSON (401 Error):

{
  "success": false,
  "error": {
    "message": "Your LobFile account is not yet activated.",
    "code": "ACCOUNT_NOT_VERIFIED"
  }
}

Authentication

Every endpoint except file downloads must be authenticated with your API key. Include it in the "X-API-Key" header on every request. UPLOAD also accepts it as an "api_key" form field, for tools that cannot set headers. Never put your key in a query string.

You can find your key on the Account info section of the dashboard after creating an account, verifying your Email, and signing in.

// cURL example (GET):

curl -sS \
  -H "X-API-Key: YOUR_API_KEY" \
  https://lobfile.com/api/v3/rest/get-account-info

FILE

Endpoint: https://lobfile.com/file/:filename

Request Method: GET or HEAD

Request Parameter Type: NONE

Auth Header: None (public)

Purpose: Download a file from LobFile by filename (with or without extension), or fetch its SHA256 digest.

NOTES

  • Valid request format: /file/:filename[.extension][.sha256]
  • The file extension is optional: both /file/example and /file/example.png will work.
  • /image/, /video/, /audio/ and /text/ take the same filename and only serve a file of that type. Anything else gets a 302 to its /file/ link, which works for every file. A name that does not exist is a 404 under any prefix.
  • HTML, XML, SVG, scripts and other text formats are served as text/plain, so they display as text and never render or run. text/csv, text/rtf, text/calendar and text/vcard keep their own type.
  • A single byte range is supported (206). The ETag is the file's SHA256, and a matching If-None-Match gets a 304. HEAD returns headers only and is not counted as a download.
  • Errors are plain text: 400 for a malformed name, 403 for a quarantined file or a rejected request, 404, 416 for a byte range that starts past the end of the file, 429 past 24 simultaneous downloads from one IP, and 509 when the owner or the host is out of bandwidth. A request whose Accept header includes text/html, which is what a browser sends, gets the same status with an HTML error page instead.
  • Add ?force-download to send the file as an attachment, so a browser saves it rather than showing it.
  • Link previewers from Discord, Facebook (also used by Messenger, Instagram and iMessage), WhatsApp, Telegram and Teams get a preview card (Open Graph HTML, status 200) in place of the file, even when the file can't be served. Add ?raw to get the file itself with one of those user agents.
  • Append .sha256 to a filename under /file/ to get its SHA256 digest (plain text, not JSON).
  • Mirrors supported for all files, typed links included:

RESPONSE

FieldTypeDescription
-BinaryFor file requests, the response body is the raw file content (not JSON).
-text/plainFor .sha256 requests, returns the digest as 64 hex characters with no trailing newline.

Download file with extension:

curl -fSL https://lobfile.com/file/example.png -o example.png

Download file without extension:

curl -fSL https://lobfile.com/file/example -o example.png

Fetch SHA256 digest (returns plain text, not JSON):

curl -s https://lobfile.com/file/example.png.sha256

UPLOAD

Endpoint: https://lobfile.com/api/v3/upload

Request Method: POST

Request Parameter Type: multipart/form-data

Auth Header: X-API-Key

Purpose: Upload a file to LobFile.

NOTES

  • Upload limitations (file size, file type, etc.) depend on your account tier.
  • Almost all file extensions are allowed, except on the Free tier.
  • The file name must have an extension of 32 characters or fewer, and empty files are rejected. Send one file per request.
  • Uploading a file your account already holds returns the existing link. No second copy is stored and no slot is used.
  • The link uses your Default Link Domain, and ends in the extension only when Include Extensions is on. Both forms of the link work.
  • Errors on this endpoint are a plain string in error, with no code. An extension your plan does not allow is a 403.
  • You may optionally provide a sha_256 field so the server can verify the file digest.

POST FIELDS

FieldTypeDescription
filemultipart/form-dataThe file contents you want to upload.
sha_256stringOptional. Server verifies the uploaded file's SHA256 matches this hex digest (case does not matter) and rejects a mismatch with 422.
api_keystringOptional. For tools that cannot set headers. Used in place of the X-API-Key header when both are sent.

RESPONSE JSON

FieldTypeDescription
successbooleanIndicates whether the upload succeeded.
urlstringFull URL to the uploaded file (on success).
errorstringPresent on failure with error message.

Upload a file:

curl -sS -X POST https://lobfile.com/api/v3/upload \
  -H "X-API-Key: YOUR_API_KEY" \
  -F "file=@/path/to/example.png"

Upload a file with SHA256 verification:

curl -sS -X POST https://lobfile.com/api/v3/upload \
  -H "X-API-Key: YOUR_API_KEY" \
  -F "file=@/path/to/example.png" \
  -F "sha_256=YOUR_SHA256_DIGEST"

Example success JSON:

{
  "success": true,
  "url": "https://lobfile.com/image/example.png"
}

The path names the type for images, video, audio and text (/image/, /video/, /audio/, /text/). Everything else comes back as /file/, and the Typed Links setting turns this off.

Example error JSON:

{
  "success": false,
  "error": "Invalid API key"
}

GET-FILE-LIST

Endpoint: https://lobfile.com/api/v3/rest/get-file-list

Request Method: GET

Request Parameter Type: GET

Auth Header: X-API-Key

Purpose: Retrieve the account's file list and usage/limits metadata.

NOTES

  • Supports server-side sorting and pagination with safe defaults (see tables below).
  • Usage and limit values include monthly bandwidth fields in bytes:account_usage.bandwidth_used_month and account_limits.max_bandwidth_monthly.

QUERY PARAMETERS

FieldTypeDescription
columnStringSort column. Allowed: upload_time, name, favorite, size, hits, access_time, file_extension. Default: upload_time.
directionStringSort direction. Allowed: asc, desc. Default: desc.
pageInteger1-based page number. Default: 1.
limitIntegerPage size (max 500). Default: 200.

Results are ordered by the chosen column/direction; items flagged for deletion are excluded.

RESPONSE JSON

FieldTypeDescription
successBoolRequest result.
errorObjectPresent on failure: message, code.
preferred_domainStringDomain to use when building file links.
show_file_extensionsBoolWhether links include file extensions.
return_typed_linksBoolWhether the account uses typed links. When true, build each link with the link_type of the file in place of /file/.
sorting.columnStringApplied sort column.
sorting.directionStringApplied sort direction.
sorting_options.columns[]Array<String>All allowed columns.
sorting_options.directions[]Array<String>All allowed directions.
pagination.pageIntegerCurrent page (1-based).
pagination.limitIntegerRequested page size.
pagination.total_filesIntegerTotal files in account.
account_usage.space_usedIntegerBytes used by all files.
account_usage.slots_usedIntegerNumber of files.
account_usage.bandwidth_used_monthIntegerBandwidth consumed so far this month (bytes).
account_limits.space_quotaIntegerMax bytes allowed for the account.
account_limits.slots_quotaIntegerMax number of files allowed.
account_limits.max_file_sizeIntegerMaximum upload size per file (bytes).
account_limits.max_file_download_speedIntegerMax download rate in Mbps.
account_limits.max_bandwidth_monthlyIntegerMax monthly bandwidth allowance (bytes).
file_list[n][name]StringUnique file name/ID.
file_list[n][original_name]StringFile's original name.
file_list[n][extension]StringFile extension.
file_list[n][size]IntegerSize in bytes.
file_list[n][content_type]StringMIME type the file is served with, which can differ from what was uploaded. Anything a browser could render as a page (text/*, message/*, XML, JavaScript) is served as text/plain. text/csv, text/rtf, text/calendar and text/vcard keep their own type.
file_list[n][link_type]StringLink prefix the file qualifies for: image, video, audio, text or file. /file/ works for every file.
file_list[n][hits]IntegerNumber of downloads.
file_list[n][sha256]StringSHA256 checksum.
file_list[n][is_favorite]BoolMarked as favorite.
file_list[n][time_added]StringUpload timestamp.
file_list[n][last_accessed]StringLast access timestamp.

Timestamps are returned as strings; treat as UTC unless otherwise noted by the API.

Retrieve the account file list (defaults: upload_time desc, page 1, limit 200):

curl -sS -X GET "https://lobfile.com/api/v3/rest/get-file-list" \
  -H "X-API-Key: YOUR_API_KEY"

Retrieve the account file list (sort by name asc, page 2, limit 100):

curl -sS -X GET "https://lobfile.com/api/v3/rest/get-file-list?column=name&direction=asc&page=2&limit=100" \
  -H "X-API-Key: YOUR_API_KEY"

Example (truncated) success JSON:

{
  "success": true,
  "preferred_domain": "lobfile.com",
  "show_file_extensions": true,
  "return_typed_links": true,
  "sorting": {
    "column": "upload_time",
    "direction": "desc"
  },
  "pagination": {
    "page": 1,
    "limit": 200,
    "total_files": 2
  },
  "file_list": [
    {
      "name": "aB3dE7gH",
      "original_name": "screenshot",
      "extension": "png",
      "size": 184320,
      "content_type": "image/png",
      "link_type": "image",
      "hits": 42,
      "sha256": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
      "is_favorite": true,
      "time_added": "2026-09-19 14:02:11",
      "last_accessed": "2026-09-19 15:40:06"
    },
    {
      "name": "kL9mN2pQ",
      "original_name": "pack",
      "extension": "zip",
      "size": 5242880,
      "content_type": "application/zip",
      "link_type": "file",
      "hits": 3,
      "sha256": "2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae",
      "is_favorite": false,
      "time_added": "2026-09-18 09:15:44",
      "last_accessed": "2026-09-18 09:16:02"
    }
  ]
}

Example error (invalid key):

HTTP/1.1 401
{
  "success": false,
  "error": {
    "message": "Invalid API key.",
    "code": "AUTH_INVALID_KEY"
  }
}

TOGGLE-FAVORITE

Endpoint: https://lobfile.com/api/v3/rest/toggle-favorite

Request Method: POST

Request Parameter Type: application/json

Auth Header: X-API-Key

Purpose: Toggle a specific file's favorite status. The response includes the new boolean value.

NOTES

  • "Favorite" files are highlighted in the UI and excluded from Continuous Uploading deletions.
  • This endpoint toggles the current state; it does not require you to pass a target boolean.
  • Provide the file name without an extension.
  • A file that has already been deleted returns 404 FILE_NOT_FOUND.

JSON BODY FIELDS

FieldTypeDescription
fileStringThe file name/ID to toggle favorite on (do not include an extension).

RESPONSE JSON

FieldTypeDescription
successBoolRequest result.
errorObjectPresent on failure: message, code.
file_info.nameStringThe file name that was updated.
file_info.is_favoriteBoolThe new favorite state after toggling.

Toggle a file as favorite:

curl -sS -X POST "https://lobfile.com/api/v3/rest/toggle-favorite" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"file":"example"}'

Example success JSON:

{
  "success": true,
  "file_info": {
    "name": "example",
    "is_favorite": true
  }
}

Example error JSON (no such file):

HTTP/1.1 404
{
  "success": false,
  "error": {
    "message": "File not found or not updated.",
    "code": "FILE_NOT_FOUND"
  }
}

DELETE-FILES

Endpoint: https://lobfile.com/api/v3/rest/delete-files

Request Method: DELETE

Request Parameter Type: application/json

Auth Header: X-API-Key

Purpose: Delete one or more files owned by the authenticated account.

NOTES

  • Request body must be a JSON object with a files array of file names/IDs (strings).
  • Files become unavailable immediately after deletion. Files already deleted, quarantined, or not owned by you are ignored.
  • Endpoint returns only the names that were actually deleted in deleted; repeating the same request is effectively idempotent.
  • Entries that are not strings are skipped, and an empty files array returns 200 with nothing deleted.

JSON BODY FIELDS

FieldTypeDescription
filesArray<String>List of file names/IDs to delete. Example: { "files": ["s1ID", "9qsq67Q"] }

RESPONSE JSON

FieldTypeDescription
successBoolRequest result.
deletedArray<String>Names/IDs that were actually deleted this call.
errorObjectPresent on failure: message, code.

Delete a single file:

curl -sS -X DELETE "https://lobfile.com/api/v3/rest/delete-files" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "files": ["s1ID"] }'

Delete multiple files:

curl -sS -X DELETE "https://lobfile.com/api/v3/rest/delete-files" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "files": ["P9uRkgR8", "9qs7q67Q"] }'

Example success JSON:

{
  "success": true,
  "deleted": [
    "example"
  ]
}

Example invalid body (shows error shape):

HTTP/1.1 400
{
  "success": false,
  "error": {
    "message": "Invalid request body. Expected JSON object with 'files' array.",
    "code": "INVALID_INPUT"
  }
}

GET-ACCOUNT-INFO

Endpoint: https://lobfile.com/api/v3/rest/get-account-info

Request Method: GET

Request Parameter Type: NONE

Auth Header: X-API-Key

Purpose: Retrieve the authenticated account's profile, limits, and usage.

NOTES

  • Response groups data under account.info, account.limits, and account.usage.
  • Units: sizes are in bytes; download speed is in megabits per second (Mbps). Timestamps are strings in UTC. The timezone in your account settings only applies to the dashboard.
  • Monthly bandwidth values are included in account.limits.max_bandwidth_monthly and account.usage.bandwidth_used_month.
  • Your API key is included in the response under account.info.api_key, treat it as a secret.

QUERY PARAMETERS

FieldTypeDescription
This endpoint does not accept query parameters.

RESPONSE JSON

FieldTypeDescription
successBoolRequest result.
errorObjectPresent on failure: message, code.
account.info.emailStringAccount email address.
account.info.levelStringAccount level/tier.
account.info.api_keyStringThe account's API key.
account.info.time_createdStringAccount creation time (UTC).
account.limits.space_quotaIntegerMax bytes allowed for the account.
account.limits.slots_quotaIntegerMax number of active files.
account.limits.max_file_sizeIntegerMax upload size per file (bytes).
account.limits.max_file_download_speedIntegerMax download speed (Mbps).
account.limits.max_bandwidth_monthlyIntegerMax monthly bandwidth allowance (bytes).
account.usage.space_usedIntegerTotal bytes used by files that are not deleted. Quarantined files count.
account.usage.slots_usedIntegerNumber of files that are not deleted. Quarantined files count.
account.usage.bandwidth_used_monthIntegerBandwidth consumed so far this month (bytes).

On failure, error.message and error.code are returned.

Fetch account info:

curl -sS -X GET "https://lobfile.com/api/v3/rest/get-account-info" \
  -H "X-API-Key: YOUR_API_KEY"

Example (truncated) success JSON:

{
  "success": true,
  "account": {
    "info": {
      "email": "you@example.com",
      "level": "PlanName",
      "api_key": "YOUR_API_KEY",
      "time_created": "2024-01-02 03:04:05"
    },
    "limits": {
      "space_quota": 1234,
      "slots_quota": 1234,
      "max_file_size": 1234,
      "max_file_download_speed": 1234,
      "max_bandwidth_monthly": 1234
    },
    "usage": {
      "space_used": 1233,
      "slots_used": 1233,
      "bandwidth_used_month": 1233
    }
  }
}

GET-ACCOUNT-SETTINGS

Endpoint: https://lobfile.com/api/v3/rest/get-account-settings

Request Method: GET

Request Parameter Type: NONE

Auth Header: X-API-Key

Purpose: Retrieve the authenticated account's settings.

NOTES

  • Response groups data under account.settings.
  • Units: filename length is a count of characters; inactivity is in days; timezone is an IANA ID (e.g. America/Los_Angeles).

QUERY PARAMETERS

FieldTypeDescription
This endpoint does not accept query parameters.

RESPONSE JSON

FieldTypeDescription
successBoolRequest result.
errorObjectPresent on failure: message, code.
account.settings.preferred_domainStringDefault link domain.
account.settings.return_file_extensionBoolWhether to include file extensions in URLs.
account.settings.return_typed_linksBoolWhether uploads return /image/, /video/, /audio/ and /text/ links where the file qualifies.
account.settings.continuous_uploadingBoolContinuous uploading (favorites excluded from deletion).
account.settings.preferred_filename_lengthIntegerDesired filename length (characters).
account.settings.inactivity_auto_delete_daysIntegerAuto-delete inactive files after X days (favorites excluded).
account.settings.timezone_autoBoolAuto-detect timezone from browser.
account.settings.timezoneStringExplicit IANA timezone. Always returned, used when timezone_auto is false.
account.settings_options.preferred_domain_options[]Array<String>Selectable domains (UI only).
account.settings_options.return_file_extension_options[]Array<Bool>Allowed values for "include extensions".
account.settings_options.return_typed_links_options[]Array<Bool>Allowed values for typed links.
account.settings_options.continuous_uploading_options[]Array<Bool>Allowed values for continuous uploading.
account.settings_options.preferred_filename_length_optionsArray<Integer>Min/max filename length, e.g. [4, 32].
account.settings_options.inactivity_auto_delete_days_optionsArray<Integer>Range of valid days, e.g. [0, 90].
account.settings_options.timezone_auto_options[]Array<Bool>Allowed values for auto timezone.
account.settings_options.timezone_options[]Array<String>IANA timezone choices (filtered list; UI only).

Note: account.settings_options is only present when authenticated via session (web UI).

Fetch account settings:

curl -sS -X GET "https://lobfile.com/api/v3/rest/get-account-settings" \
  -H "X-API-Key: YOUR_API_KEY"

Example (truncated) success JSON:

{
  "success": true,
  "account": {
    "settings": {
      "preferred_domain": "lobfile.com",
      "return_file_extension": true,
      "return_typed_links": true,
      "continuous_uploading": false,
      "preferred_filename_length": 12,
      "inactivity_auto_delete_days": 30,
      "timezone_auto": true,
      "timezone": "America/Los_Angeles"
    }
  }
}