file_type_not_allowed 🔌 API

Upload error: File type not allowed / unsupported file type

The upload was rejected because the file’s type — extension, MIME type or actual content — isn’t on the allowed list.

Seen on: REST API

Meaning

Upload endpoints check the extension, the declared Content-Type of the file part, and often the file’s real signature (magic bytes). A HEIC photo renamed .jpg, a PDF uploaded as application/octet-stream, or an SVG on an image-only endpoint all fail.

Laravel says “The file must be a file of type: jpg, png”, WordPress “Sorry, you are not allowed to upload this file type”, Multer-based APIs “Unsupported file type”. This is different from 415, which is about the request’s overall Content-Type.

Common causes

  • Format not supported (HEIC, WEBP, SVG, DOCX…)
  • Wrong MIME type on the file part (application/octet-stream)
  • Extension doesn’t match the real content
  • Endpoint allow-list stricter than expected

⚡ Quick fix

  1. Convert to an allowed format (JPEG/PNG/PDF)
  2. Set the correct MIME type on the file part
  3. Check the endpoint’s allowed types in the docs

Detailed fix by platform

Node.js

  1. javascript
    const form = new FormData();
    form.append('file', new Blob([buf], { type: 'image/png' }), 'photo.png');
    await fetch(url, { method: 'POST', body: form });   // let fetch set the multipart boundary

curl

  1. curl -F 'file=@photo.png;type=image/png' https://api.example.com/v1/uploads

How to diagnose

  1. Real type — file --mime-type photo.png
  2. Declared type — Content-Type of the multipart part
  3. Allowed — Endpoint allow-list

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.