Thursday, August 6, 2026

Salesforce REST API: Upload a Files to a Record Attachments | Step-by-Step Guide

Uploading a file to a Salesforce record using the REST API is a straightforward process. In this tutorial, I'll walk you through the complete process using only four cURL commands.

The entire process consists of four simple steps:

  1. Authenticate with your Salesforce org to obtain an Access Token.

  2. Upload the file from your local machine to Salesforce using the Access Token. This request returns the ContentVersion Id.

  3. Retrieve the ContentDocument Id using the ContentVersion Id.

  4. Link the file to a Salesforce record using the ContentDocument Id.

That's it! With these four REST API calls, your file will be successfully attached to the desired Salesforce record.


What is cURL?

cURL (Client URL) is a command-line tool used to send HTTP requests to web servers and REST APIs. It is one of the most widely used tools for testing and interacting with REST services, including the Salesforce REST API.

Throughout this tutorial, we'll use only 4 cURL commands to perform all the API requests.


Do You Need to Install cURL?

Whether you need to install cURL depends on your operating system.

Operating SystemIs cURL Pre-installed?
Windows 10 (Version 1803+) & Windows 11✅ Yes
Linux✅ Usually Pre-installed
macOS✅ Yes
Windows 7 / Windows 8❌ Usually Not Installed

How to Check Whether cURL is Installed

Open Command Prompt or PowerShell and execute the following command:

curl --version

If installed, you'll see output with it's version and if it is not there then you will get message like "'curl' is not recognized as an internal or external command".

Note: This tutorial assumes that cURL is already installed and available on your machine.


Let's Get Started

Now that we have a basic understanding of cURL, let's dive into the implementation.

In the following sections, we'll go through each of the four REST API calls required to upload a file and attach it to a Salesforce record, with complete request examples and explanations for each step.


Step 1: Authenticate with Your Salesforce Org and Obtain an Access Token

Open Command Prompt (Windows) and execute the following cURL command to authenticate with your Salesforce org.






Note:
The cURL command shown in the above article may be split across multiple lines for better readability. Before executing it in Command Prompt, remove the trailing backslash (\) from the end of each line and combine the entire command into a single line.


Below is the Raw Command I used for my testing,

curl -X POST https://login.salesforce.com/services/oauth2/token -d "grant_type=password" -d "client_id=AKHG9d8..z.hDcPKzY60RcaEIAGFHl9AfckqHkoY.y3AHazraPEaiwu3LbM7YVh9wi4ap" -d "client_secret=C7B12F5AKH21642AA58B29F7E540F0722E5AE83915275" -d "username=arunkumar@hazra.com" -d "password=Abc@1234bMAKHAcBHH8vZCtM6dZD"


Response I received:
{"access_token":"00D7F0000LOVEAQN_u.PIqS6AKHfR2ZTtjk8QmBOEn56A7i1tcPshZOWHi5xReHVDR73m6dUMeyiIyDF43DWsW5CY","instance_url":"https://lwcdmn-dev-ed.my.salesforce.com","id":"https://login.salesforce.com/id/00D7F000000saHDUAY/0057F000000xxXnQAI","token_type":"Bearer","issued_at":"1786011844436","signature":"tPvyF5HRbTUNv1w3rBqQe+FjkIk1/o6Q8sogmUrzboI="}


Note:
This highlighted Access Token, we will use in our next steps (Step-2)

Step 2:Upload the file from your local machine to Salesforce using the Access Token. This request returns the ContentVersion Id.

Open Command Prompt (Windows) and execute the following cURL command to upload the file in Salesforce as a ContentVersion and then as a response collect the ContenVersion Id.








Note:
The cURL command shown in the above article may be split across multiple lines for better readability. Before executing it in Command Prompt, remove the trailing backslash (\) from the end of each line and combine the entire command into a single line.

Below is the Raw Command I used for my testing,

curl --request POST "https://lwcdmn-dev-ed.my.salesforce.com/services/data/v55.0/sobjects/ContentVersion" --header "Authorization: Bearer 00D7F0000LOVEAQN_u.PIqS6AKHfR2ZTtjk8QmBOEn56A7i1tcPshZOWHi5xReHVDR73m6dUMeyiIyDF43DWsW5CY" --form "entity_content={\"Title\":\"MediAssistCard\",\"PathOnClient\":\"MediAssistCard.pdf\"};type=application/json" --form "VersionData=@C:\Arun\MediAssistCard.pdf;type=application/octet-stream"

Response I received:
Response: {"id":"068NS00000aABC7YAO","success":true,"errors":[]}


Note:

  •  This highlighted ContentVersion Id in GREEN, we will use in our next steps (Step-3).
  • VVI:  Please notice the highlighted parpel color in my raw command, this is very very important note. If you are using a quote under another quote then use this backslash (\) before each quote which are part under a parent quotes. If you did a single mistake on syntax then it will be very hard to solve. So, be carefull on this command systax.
  • VVI: Try to use  absolute path of your file location like I mentioned in ORANGE colour and keep your folder name without space.


Step 3: Retrieve the ContentDocument Id using the ContentVersion Id.

Open Command Prompt (Windows) and execute the following cURL command to get the ContentDocument Id by using the Content Version Id (068NS00000aABC7YAO) that we have received from Step-2 response.






Note:
The cURL command shown in the above article may be split across multiple lines for better readability. Before executing it in Command Prompt, remove the trailing backslash (\) from the end of each line and combine the entire command into a single line.

Below is the Raw Command I used for my testing,

curl -X GET https://lwcdmn-dev-ed.my.salesforce.com/services/data/v55.0/sobjects/ContentVersion/068NS00000aABC7YAO -H "Authorization: Bearer 00D7F0000LOVEAQN_u.PIqS6AKHfR2ZTtjk8QmBOEn56A7i1tcPshZOWHi5xReHVDR73m6dUMeyiIyDF43DWsW5CY" -H "Content-Type: application/json"

Response I received:
{"attributes":{"type":"ContentVersion","url":"/services/data/v55.0/sobjects/ContentVersion/068NS00000aECJ7YAO"},"Id":"068NS00000aABC7YAO","ContentDocumentId":"069NS00000czFmRYAU","IsLatest":true,"ContentUrl":null,"ContentBodyId":"05TNS000066DRgK2AW","VersionNumber":"1","Title":"MediAssistCard","Description":null,"ReasonForChange":null,"SharingOption":"A","SharingPrivacy":"N","PathOnClient":"MediAssistCard.pdf","RatingCount":0,"IsDeleted":false,"ContentModifiedDate":"2026-08-06T10:26:01.000+0000","ContentModifiedById":"0057F087800xxXnQAI","PositiveRatingCount":0,"NegativeRatingCount":0,"FeaturedContentBoost":null,"FeaturedContentDate":null,"OwnerId":"0057F000000xxXnQAI","CreatedById":"0057F009870xxXnQAI","CreatedDate":"2026-08-06T10:26:01.000+0000","LastModifiedById":"0057F008780xxXnQAI","LastModifiedDate":"2026-08-06T10:26:01.000+0000","SystemModstamp":"2026-08-06T10:26:03.000+0000","TagCsv":null,"FileType":"PDF","PublishStatus":"R","VersionData":"/services/data/v55.0/sobjects/ContentVersion/068NS00999aECJ7YAO/VersionData","ContentSize":527093,"FileExtension":"pdf","FirstPublishLocationId":"0057F009990xxXnQAI","Origin":"C","ContentLocation":"S","TextPreview":null,"ExternalDocumentInfo1":null,"ExternalDocumentInfo2":null,"ExternalDataSourceId":null,"Checksum":"97ee0e4c74d7be1drtet45b0c693b0ae","IsMajorVersion":true,"IsAssetEnabled":false}


Note:

  •  This highlighted ContentDocumentId in GREEN, we will use in our next steps (Step-4).

Step 4: Link the file to a Salesforce record using the ContentDocument Id.

Now this is the final steps where we will atach the file to a Salesfroce Record. For my example I am going to load this file under one Account Record. So, before execute this commnad, lets check the Salesforce Account Record and we could see no file attached at this moment.


 

 




Open Command Prompt (Windows) and execute the following cURL command to attache the file to the Account Record (0017F000007A2eZQAS) by using the ContentDocumentId (069NS00000czFmRYAU) that we have received from Step-3 response.







Below is the Raw Command I used for my testing,

curl -X POST https://lwcdmn-dev-ed.my.salesforce.com/services/data/v55.0/sobjects/ContentDocumentLink -H "Authorization: Bearer 00D7F000000saHD!AQEAQN_u.PIqS6kPhfinZG49wp3AYsp7IBfR2ZTtjk8QmBOEn56A7i1tcPshZOWHi5xReHVDR73m6dUMeyiIyDF43DWsW5CY" -H "Content-Type: application/json" -d "{\"ContentDocumentId\" : \"069NS00000czFmRYAU\",\"LinkedEntityId\" : \"0017F000007A2eZQAS\",\"ShareType\" : \"V\",\"Visibility\" : \"AllUsers\"}"

Response I received:

{"id":"06ANS00000XYZUb2AL","success":true,"errors":[]}


After successfull completion of above step-4, if we check our Salesfroce record then we will file the respective file will be attached under the mentioned record (for our case Account Record),










Final Note:

1. Use the above 4 raw commnads I have used and just change the parameters value as per user setup.
2. You can load a large file. FYI I have tested for a video file with size of 85 MB and it has attached successfully.
3. In Step-4 we use 2 things, "ShareType" and "Visibility", so you can check the below details for this 2 parameters and set it as per your need.



Salesforce REST API: Upload a Files to a Record Attachments | Step-by-Step Guide

Uploading a file to a Salesforce record using the REST API is a straightforward process. In this tutorial, I'll walk you through the com...