Version: 3.4
Last Updated: October 6th, 2026
Getting Started
The LobFile API will allow you (or an application you are writing/using) to automate tasks like uploading and managing your files.
To use this API, you need an API Key. Access to the API is free, no matter what plan tier you have. Your API key can be found on the Account Info section of the dashboard once you have created an account, verified your Email, and logged in.
If you find this service useful, or if you need more performance out of LobFile (like faster downloads or more account space), please consider subscribing to one of the Plans that are available.
If you find any issues or find the documentation to be incomplete or not working, feel free to send me a message in Discord or via Email.
Rate Limits
LobFile is configured with a global rate limit of 2 requests per second per IP, shared across lobfile.com, lithi.io and lithi.pw. Short bursts above that are tolerated. If you exceed this rate limit you will receive a HTTP status code of 429. Downloads are also capped at 24 at a time per IP, and further connections get the same 429.
Please be respectful with your use of the API in your integration and use case. If for some reason you need a higher rate limit, let me know on Discord or via Email.
API Requests
The only API endpoint that requires formData instead of JSON is UPLOAD . The other endpoints return JSON. DELETE-FILES and TOGGLE-FAVORITE take a JSON body, the GET endpoints take query parameters or nothing, and each one answers 405 to the wrong HTTP method. File downloads return the file itself.
Be sure to review and follow the examples provided in this documentation when building your integration. They will provide working cURL examples to show you the correct structure for requests and the expected responses.
API Responses
All HTTP requests will respond with the most relevant HTTP status code. A HTTP status code of 200 means the request was fully successful.
API response bodies are application/json, file downloads aside. However, you must plan for cases where the server cannot return valid JSON (for example, server issues, network edge errors, or rate limits). Your integration should detect non-JSON responses and handle them gracefully.
All responses include a 'success' boolean. When success is false, an 'error' object is present with a 'message' and a 'code' to branch on. UPLOAD is the exception: its 'error' is a plain string. Otherwise, expect whatever fields are documented for the specific endpoint.
| Code | Status | Meaning |
|---|---|---|
| AUTH_REQUIRED | 401 | No API key was sent. |
| AUTH_INVALID_KEY | 401 | The API key does not match an account. |
| ACCOUNT_NOT_VERIFIED | 401 | The account's Email has not been verified yet. |
| METHOD_NOT_ALLOWED | 405 | Wrong HTTP method for the endpoint. |
| INVALID_INPUT | 400 | The JSON body is missing or not the documented shape. |
| FILE_NOT_FOUND | 404 | TOGGLE-FAVORITE: no such file on the account. |
| LOOKUP_FAILED | 500 | GET-FILE-LIST: usage could not be read. |
| LOOKUP_ERROR | 500 | TOGGLE-FAVORITE: the new state could not be read back. |
| INTERNAL_LOOKUP_ERROR | 500 | GET-ACCOUNT-INFO: the account could not be read. |
Example JSON (200 Success):
{
"success": true,
"url": "https://lobfile.com/file/example.zip"
}Example JSON (401 Error):
{
"success": false,
"error": {
"message": "Your LobFile account is not yet activated.",
"code": "ACCOUNT_NOT_VERIFIED"
}
}Authentication
Every endpoint except file downloads must be authenticated with your API key. Include it in the "X-API-Key" header on every request. UPLOAD also accepts it as an "api_key" form field, for tools that cannot set headers. Never put your key in a query string.
You can find your key on the Account info section of the dashboard after creating an account, verifying your Email, and signing in.
// cURL example (GET):
curl -sS \ -H "X-API-Key: YOUR_API_KEY" \ https://lobfile.com/api/v3/rest/get-account-info
FILE
Endpoint: https://lobfile.com/file/:filename
Request Method: GET or HEAD
Request Parameter Type: NONE
Auth Header: None (public)
Purpose: Download a file from LobFile by filename (with or without extension), or fetch its SHA256 digest.
NOTES
- Valid request format:
/file/:filename[.extension][.sha256] - The file extension is optional: both
/file/exampleand/file/example.pngwill work. /image/,/video/,/audio/and/text/take the same filename and only serve a file of that type. Anything else gets a 302 to its /file/ link, which works for every file. A name that does not exist is a 404 under any prefix.- HTML, XML, SVG, scripts and other text formats are served as text/plain, so they display as text and never render or run. text/csv, text/rtf, text/calendar and text/vcard keep their own type.
- A single byte range is supported (206). The ETag is the file's SHA256, and a matching If-None-Match gets a 304. HEAD returns headers only and is not counted as a download.
- Errors are plain text: 400 for a malformed name, 403 for a quarantined file or a rejected request, 404, 416 for a byte range that starts past the end of the file, 429 past 24 simultaneous downloads from one IP, and 509 when the owner or the host is out of bandwidth. A request whose Accept header includes text/html, which is what a browser sends, gets the same status with an HTML error page instead.
- Add
?force-downloadto send the file as an attachment, so a browser saves it rather than showing it. - Link previewers from Discord, Facebook (also used by Messenger, Instagram and iMessage), WhatsApp, Telegram and Teams get a preview card (Open Graph HTML, status 200) in place of the file, even when the file can't be served. Add
?rawto get the file itself with one of those user agents. - Append
.sha256to a filename under /file/ to get its SHA256 digest (plain text, not JSON). - Mirrors supported for all files, typed links included:
RESPONSE
| Field | Type | Description |
|---|---|---|
| - | Binary | For file requests, the response body is the raw file content (not JSON). |
| - | text/plain | For .sha256 requests, returns the digest as 64 hex characters with no trailing newline. |
Download file with extension:
curl -fSL https://lobfile.com/file/example.png -o example.png
Download file without extension:
curl -fSL https://lobfile.com/file/example -o example.png
Fetch SHA256 digest (returns plain text, not JSON):
curl -s https://lobfile.com/file/example.png.sha256
UPLOAD
Endpoint: https://lobfile.com/api/v3/upload
Request Method: POST
Request Parameter Type: multipart/form-data
Auth Header: X-API-Key
Purpose: Upload a file to LobFile.
NOTES
- Upload limitations (file size, file type, etc.) depend on your account tier.
- Almost all file extensions are allowed, except on the Free tier.
- The file name must have an extension of 32 characters or fewer, and empty files are rejected. Send one file per request.
- Uploading a file your account already holds returns the existing link. No second copy is stored and no slot is used.
- The link uses your Default Link Domain, and ends in the extension only when Include Extensions is on. Both forms of the link work.
- Errors on this endpoint are a plain string in
error, with no code. An extension your plan does not allow is a 403. - You may optionally provide a
sha_256field so the server can verify the file digest.
POST FIELDS
| Field | Type | Description |
|---|---|---|
| file | multipart/form-data | The file contents you want to upload. |
| sha_256 | string | Optional. Server verifies the uploaded file's SHA256 matches this hex digest (case does not matter) and rejects a mismatch with 422. |
| api_key | string | Optional. For tools that cannot set headers. Used in place of the X-API-Key header when both are sent. |
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | boolean | Indicates whether the upload succeeded. |
| url | string | Full URL to the uploaded file (on success). |
| error | string | Present on failure with error message. |
Upload a file:
curl -sS -X POST https://lobfile.com/api/v3/upload \ -H "X-API-Key: YOUR_API_KEY" \ -F "file=@/path/to/example.png"
Upload a file with SHA256 verification:
curl -sS -X POST https://lobfile.com/api/v3/upload \ -H "X-API-Key: YOUR_API_KEY" \ -F "file=@/path/to/example.png" \ -F "sha_256=YOUR_SHA256_DIGEST"
Example success JSON:
{
"success": true,
"url": "https://lobfile.com/image/example.png"
}The path names the type for images, video, audio and text (/image/, /video/, /audio/, /text/). Everything else comes back as /file/, and the Typed Links setting turns this off.
Example error JSON:
{
"success": false,
"error": "Invalid API key"
}GET-FILE-LIST
Endpoint: https://lobfile.com/api/v3/rest/get-file-list
Request Method: GET
Request Parameter Type: GET
Auth Header: X-API-Key
Purpose: Retrieve the account's file list and usage/limits metadata.
NOTES
- Supports server-side sorting and pagination with safe defaults (see tables below).
- Usage and limit values include monthly bandwidth fields in bytes:
account_usage.bandwidth_used_monthandaccount_limits.max_bandwidth_monthly.
QUERY PARAMETERS
| Field | Type | Description |
|---|---|---|
| column | String | Sort column. Allowed: upload_time, name, favorite, size, hits, access_time, file_extension. Default: upload_time. |
| direction | String | Sort direction. Allowed: asc, desc. Default: desc. |
| page | Integer | 1-based page number. Default: 1. |
| limit | Integer | Page size (max 500). Default: 200. |
Results are ordered by the chosen column/direction; items flagged for deletion are excluded.
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | Bool | Request result. |
| error | Object | Present on failure: message, code. |
| preferred_domain | String | Domain to use when building file links. |
| show_file_extensions | Bool | Whether links include file extensions. |
| return_typed_links | Bool | Whether the account uses typed links. When true, build each link with the link_type of the file in place of /file/. |
| sorting.column | String | Applied sort column. |
| sorting.direction | String | Applied sort direction. |
| sorting_options.columns[] | Array<String> | All allowed columns. |
| sorting_options.directions[] | Array<String> | All allowed directions. |
| pagination.page | Integer | Current page (1-based). |
| pagination.limit | Integer | Requested page size. |
| pagination.total_files | Integer | Total files in account. |
| account_usage.space_used | Integer | Bytes used by all files. |
| account_usage.slots_used | Integer | Number of files. |
| account_usage.bandwidth_used_month | Integer | Bandwidth consumed so far this month (bytes). |
| account_limits.space_quota | Integer | Max bytes allowed for the account. |
| account_limits.slots_quota | Integer | Max number of files allowed. |
| account_limits.max_file_size | Integer | Maximum upload size per file (bytes). |
| account_limits.max_file_download_speed | Integer | Max download rate in Mbps. |
| account_limits.max_bandwidth_monthly | Integer | Max monthly bandwidth allowance (bytes). |
| file_list[n][name] | String | Unique file name/ID. |
| file_list[n][original_name] | String | File's original name. |
| file_list[n][extension] | String | File extension. |
| file_list[n][size] | Integer | Size in bytes. |
| file_list[n][content_type] | String | MIME type the file is served with, which can differ from what was uploaded. Anything a browser could render as a page (text/*, message/*, XML, JavaScript) is served as text/plain. text/csv, text/rtf, text/calendar and text/vcard keep their own type. |
| file_list[n][link_type] | String | Link prefix the file qualifies for: image, video, audio, text or file. /file/ works for every file. |
| file_list[n][hits] | Integer | Number of downloads. |
| file_list[n][sha256] | String | SHA256 checksum. |
| file_list[n][is_favorite] | Bool | Marked as favorite. |
| file_list[n][time_added] | String | Upload timestamp. |
| file_list[n][last_accessed] | String | Last access timestamp. |
Timestamps are returned as strings; treat as UTC unless otherwise noted by the API.
Retrieve the account file list (defaults: upload_time desc, page 1, limit 200):
curl -sS -X GET "https://lobfile.com/api/v3/rest/get-file-list" \ -H "X-API-Key: YOUR_API_KEY"
Retrieve the account file list (sort by name asc, page 2, limit 100):
curl -sS -X GET "https://lobfile.com/api/v3/rest/get-file-list?column=name&direction=asc&page=2&limit=100" \ -H "X-API-Key: YOUR_API_KEY"
Example (truncated) success JSON:
{
"success": true,
"preferred_domain": "lobfile.com",
"show_file_extensions": true,
"return_typed_links": true,
"sorting": {
"column": "upload_time",
"direction": "desc"
},
"pagination": {
"page": 1,
"limit": 200,
"total_files": 2
},
"file_list": [
{
"name": "aB3dE7gH",
"original_name": "screenshot",
"extension": "png",
"size": 184320,
"content_type": "image/png",
"link_type": "image",
"hits": 42,
"sha256": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"is_favorite": true,
"time_added": "2026-09-19 14:02:11",
"last_accessed": "2026-09-19 15:40:06"
},
{
"name": "kL9mN2pQ",
"original_name": "pack",
"extension": "zip",
"size": 5242880,
"content_type": "application/zip",
"link_type": "file",
"hits": 3,
"sha256": "2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae",
"is_favorite": false,
"time_added": "2026-09-18 09:15:44",
"last_accessed": "2026-09-18 09:16:02"
}
]
}Example error (invalid key):
HTTP/1.1 401
{
"success": false,
"error": {
"message": "Invalid API key.",
"code": "AUTH_INVALID_KEY"
}
}TOGGLE-FAVORITE
Endpoint: https://lobfile.com/api/v3/rest/toggle-favorite
Request Method: POST
Request Parameter Type: application/json
Auth Header: X-API-Key
Purpose: Toggle a specific file's favorite status. The response includes the new boolean value.
NOTES
- "Favorite" files are highlighted in the UI and excluded from Continuous Uploading deletions.
- This endpoint toggles the current state; it does not require you to pass a target boolean.
- Provide the file name without an extension.
- A file that has already been deleted returns 404 FILE_NOT_FOUND.
JSON BODY FIELDS
| Field | Type | Description |
|---|---|---|
| file | String | The file name/ID to toggle favorite on (do not include an extension). |
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | Bool | Request result. |
| error | Object | Present on failure: message, code. |
| file_info.name | String | The file name that was updated. |
| file_info.is_favorite | Bool | The new favorite state after toggling. |
Toggle a file as favorite:
curl -sS -X POST "https://lobfile.com/api/v3/rest/toggle-favorite" \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"file":"example"}'Example success JSON:
{
"success": true,
"file_info": {
"name": "example",
"is_favorite": true
}
}Example error JSON (no such file):
HTTP/1.1 404
{
"success": false,
"error": {
"message": "File not found or not updated.",
"code": "FILE_NOT_FOUND"
}
}DELETE-FILES
Endpoint: https://lobfile.com/api/v3/rest/delete-files
Request Method: DELETE
Request Parameter Type: application/json
Auth Header: X-API-Key
Purpose: Delete one or more files owned by the authenticated account.
NOTES
- Request body must be a JSON object with a
filesarray of file names/IDs (strings). - Files become unavailable immediately after deletion. Files already deleted, quarantined, or not owned by you are ignored.
- Endpoint returns only the names that were actually deleted in
deleted; repeating the same request is effectively idempotent. - Entries that are not strings are skipped, and an empty files array returns 200 with nothing deleted.
JSON BODY FIELDS
| Field | Type | Description |
|---|---|---|
| files | Array<String> | List of file names/IDs to delete. Example: { "files": ["s1ID", "9qsq67Q"] } |
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | Bool | Request result. |
| deleted | Array<String> | Names/IDs that were actually deleted this call. |
| error | Object | Present on failure: message, code. |
Delete a single file:
curl -sS -X DELETE "https://lobfile.com/api/v3/rest/delete-files" \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "files": ["s1ID"] }'Delete multiple files:
curl -sS -X DELETE "https://lobfile.com/api/v3/rest/delete-files" \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "files": ["P9uRkgR8", "9qs7q67Q"] }'Example success JSON:
{
"success": true,
"deleted": [
"example"
]
}Example invalid body (shows error shape):
HTTP/1.1 400
{
"success": false,
"error": {
"message": "Invalid request body. Expected JSON object with 'files' array.",
"code": "INVALID_INPUT"
}
}GET-ACCOUNT-INFO
Endpoint: https://lobfile.com/api/v3/rest/get-account-info
Request Method: GET
Request Parameter Type: NONE
Auth Header: X-API-Key
Purpose: Retrieve the authenticated account's profile, limits, and usage.
NOTES
- Response groups data under
account.info,account.limits, andaccount.usage. - Units: sizes are in bytes; download speed is in megabits per second (Mbps). Timestamps are strings in UTC. The timezone in your account settings only applies to the dashboard.
- Monthly bandwidth values are included in
account.limits.max_bandwidth_monthlyandaccount.usage.bandwidth_used_month. - Your API key is included in the response under
account.info.api_key, treat it as a secret.
QUERY PARAMETERS
| Field | Type | Description |
|---|---|---|
| This endpoint does not accept query parameters. | ||
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | Bool | Request result. |
| error | Object | Present on failure: message, code. |
| account.info.email | String | Account email address. |
| account.info.level | String | Account level/tier. |
| account.info.api_key | String | The account's API key. |
| account.info.time_created | String | Account creation time (UTC). |
| account.limits.space_quota | Integer | Max bytes allowed for the account. |
| account.limits.slots_quota | Integer | Max number of active files. |
| account.limits.max_file_size | Integer | Max upload size per file (bytes). |
| account.limits.max_file_download_speed | Integer | Max download speed (Mbps). |
| account.limits.max_bandwidth_monthly | Integer | Max monthly bandwidth allowance (bytes). |
| account.usage.space_used | Integer | Total bytes used by files that are not deleted. Quarantined files count. |
| account.usage.slots_used | Integer | Number of files that are not deleted. Quarantined files count. |
| account.usage.bandwidth_used_month | Integer | Bandwidth consumed so far this month (bytes). |
On failure, error.message and error.code are returned.
Fetch account info:
curl -sS -X GET "https://lobfile.com/api/v3/rest/get-account-info" \ -H "X-API-Key: YOUR_API_KEY"
Example (truncated) success JSON:
{
"success": true,
"account": {
"info": {
"email": "you@example.com",
"level": "PlanName",
"api_key": "YOUR_API_KEY",
"time_created": "2024-01-02 03:04:05"
},
"limits": {
"space_quota": 1234,
"slots_quota": 1234,
"max_file_size": 1234,
"max_file_download_speed": 1234,
"max_bandwidth_monthly": 1234
},
"usage": {
"space_used": 1233,
"slots_used": 1233,
"bandwidth_used_month": 1233
}
}
}GET-ACCOUNT-SETTINGS
Endpoint: https://lobfile.com/api/v3/rest/get-account-settings
Request Method: GET
Request Parameter Type: NONE
Auth Header: X-API-Key
Purpose: Retrieve the authenticated account's settings.
NOTES
- Response groups data under
account.settings. - Units: filename length is a count of characters; inactivity is in days; timezone is an IANA ID (e.g.
America/Los_Angeles).
QUERY PARAMETERS
| Field | Type | Description |
|---|---|---|
| This endpoint does not accept query parameters. | ||
RESPONSE JSON
| Field | Type | Description |
|---|---|---|
| success | Bool | Request result. |
| error | Object | Present on failure: message, code. |
| account.settings.preferred_domain | String | Default link domain. |
| account.settings.return_file_extension | Bool | Whether to include file extensions in URLs. |
| account.settings.return_typed_links | Bool | Whether uploads return /image/, /video/, /audio/ and /text/ links where the file qualifies. |
| account.settings.continuous_uploading | Bool | Continuous uploading (favorites excluded from deletion). |
| account.settings.preferred_filename_length | Integer | Desired filename length (characters). |
| account.settings.inactivity_auto_delete_days | Integer | Auto-delete inactive files after X days (favorites excluded). |
| account.settings.timezone_auto | Bool | Auto-detect timezone from browser. |
| account.settings.timezone | String | Explicit IANA timezone. Always returned, used when timezone_auto is false. |
| account.settings_options.preferred_domain_options[] | Array<String> | Selectable domains (UI only). |
| account.settings_options.return_file_extension_options[] | Array<Bool> | Allowed values for "include extensions". |
| account.settings_options.return_typed_links_options[] | Array<Bool> | Allowed values for typed links. |
| account.settings_options.continuous_uploading_options[] | Array<Bool> | Allowed values for continuous uploading. |
| account.settings_options.preferred_filename_length_options | Array<Integer> | Min/max filename length, e.g. [4, 32]. |
| account.settings_options.inactivity_auto_delete_days_options | Array<Integer> | Range of valid days, e.g. [0, 90]. |
| account.settings_options.timezone_auto_options[] | Array<Bool> | Allowed values for auto timezone. |
| account.settings_options.timezone_options[] | Array<String> | IANA timezone choices (filtered list; UI only). |
Note: account.settings_options is only present when authenticated via session (web UI).
Fetch account settings:
curl -sS -X GET "https://lobfile.com/api/v3/rest/get-account-settings" \ -H "X-API-Key: YOUR_API_KEY"
Example (truncated) success JSON:
{
"success": true,
"account": {
"settings": {
"preferred_domain": "lobfile.com",
"return_file_extension": true,
"return_typed_links": true,
"continuous_uploading": false,
"preferred_filename_length": 12,
"inactivity_auto_delete_days": 30,
"timezone_auto": true,
"timezone": "America/Los_Angeles"
}
}
}