Building a File Upload Feature Without Backend Code
File uploads are one of those features that seem simple until you start building them. The user picks a file, you send it somewhere, you get a URL. Three steps. But the "somewhere" part traditionally means running a backend server that handles multipart form data, writes files to disk or cloud storage, manages cleanup, and serves those files back to users. That's a lot of infrastructure for what should be a straightforward feature.
If you're building a static site, a single-page app, or working inside a no-code platform, you may not have a backend at all. And even if you do, dedicating server resources to handling file uploads is often overkill for what your app actually needs.
This guide walks through three practical methods for adding file uploads to your project without writing a single line of backend code.
The Backend Problem with File Uploads
Handling file uploads on your own server introduces several responsibilities that have nothing to do with your app's core features:
- Storage management. Where do files go? Your server's disk fills up. Cloud storage requires SDK integration, credentials, and configuration. You need to generate unique filenames and organize files into paths.
- Security. You need to validate file types, enforce size limits, scan for malicious content, and prevent path traversal attacks. Improperly handled file uploads are one of the most common web security vulnerabilities.
- CDN delivery. Files uploaded to your server are served from your server. If a file goes viral or you have users worldwide, your server becomes a bottleneck. Adding a CDN means configuring another service.
- Scaling. Handling large file uploads ties up server threads. Under load, your application can become unresponsive if upload handling isn't properly isolated. This is especially painful with synchronous web frameworks.
A file upload API offloads every one of these problems to a dedicated service. You send the file over HTTP, and the API handles storage, security, CDN delivery, and scaling. You get back a URL.
How File Upload APIs Eliminate Backend Code
A file upload API like FilePost exposes a single HTTP endpoint. Your server sends a multipart POST request with the file, and the API returns a JSON response containing a CDN-backed URL. For uploads that should start in the browser without exposing a secret, use a public intake link instead. The flow is:
- User selects a file in your UI
- Your server or a public intake link sends the file to the API
- The API stores the file, distributes it to a CDN, and returns the URL
- You use that URL however you need, display it, store it in a database, email it
A public intake link lets a browser send a file without an API key. For authenticated API uploads, keep the API key on your server and proxy the request through it; never put the key in browser code.
Method 1: Use a Hosted Intake Link
Create an intake link in your FilePost account and send users to its hosted upload page. The hosted form accepts files without exposing an API key or requiring you to build an upload server:
<a href="https://filepost.dev/u/YOUR_INTAKE_TOKEN">
Upload a file
</a>
Replace the placeholder with the token from an intake link in your account. You can put this link on a static site, email, or form confirmation page. The hosted intake page handles file selection and submission; for a custom uploader, send the upload through a server-side proxy.
The key parts:
- The link opens FilePost's hosted intake page, where the visitor selects and submits a file.
- The intake link can be configured with file type, size, upload count, and expiry limits.
- The account owner must verify their email before the intake link can accept uploads. Files have no automatic expiry by default unless an expiry is requested; the separate first unverified trial upload expires after 24 hours unless the account verifies.
Method 2: Upload from No-Code Platforms
If you're using a no-code or low-code automation platform, you can add file uploads without writing any code at all. These platforms can send HTTP requests to FilePost's API as part of automated workflows.
Zapier
In Zapier, use the "Webhooks by Zapier" action to send a POST request to https://upload.filepost.dev/v1/upload. Set the X-API-Key header and attach the file from a previous trigger step (like a Gmail attachment or form submission). The response URL can be used in subsequent actions. See our complete Zapier file upload guide for step-by-step instructions.
Make (formerly Integromat)
In Make, use the HTTP module's "Make a request" action. Set the method to POST, the URL to https://upload.filepost.dev/v1/upload, add the X-API-Key header, and set the body type to Multipart/form-data. Map the file from your trigger module to the file field.
n8n
n8n has a dedicated FilePost community node (n8n-nodes-filepost) that makes this even simpler. Install it from the community nodes menu, add your API key as a credential, and use the Upload File operation. No HTTP configuration needed. Alternatively, you can use the HTTP Request node with binary data. Our n8n file upload guide walks through both approaches.
Upload Files Without a Backend
Get a file upload API running in under a minute. Free plan starts with one provisional upload before verification and unlocks 15/month after email verification, with 2GB storage and CDN delivery.
Get Your API KeyMethod 3: Add an Intake Link to a Static Site
Static sites built with Hugo, Jekyll, Eleventy, or plain HTML can link to a hosted intake page. This keeps the upload form and account API key off the static site.
Add a link styled to match your page:
<a class="upload-button" href="https://filepost.dev/u/YOUR_INTAKE_TOKEN">
Send us a file
</a>
This works on Netlify, Vercel, GitHub Pages, Cloudflare Pages, or another static host. Visitors upload on FilePost's hosted intake page. A custom JavaScript uploader needs a server-side proxy or another supported secure upload path; never place an account API key in a public page.
Security Considerations
Public pages are visible to every visitor. Do not put an account API key in browser code; use an intake link or keep the key on a server that proxies uploads.
API Key Exposure
If an API key is in client-side JavaScript, visitors can copy and use it. Avoid that exposure in production:
- Use an intake link for public-facing uploads. It avoids exposing your API key and supports file, size, count, and expiry limits.
- Use a thin proxy. If you have even a minimal backend (a serverless function on Vercel, Netlify Functions, or Cloudflare Workers), you can proxy the upload through it. The function holds the API key server-side and forwards the file to FilePost. This is 10-15 lines of code and keeps your key private.
- Use rate limits and validation. These controls complement key protection; they do not make a public API key safe to expose.
File Validation
Always validate files on the client side before uploading. Check file types (using the type property on the File object), enforce size limits, and provide clear error messages. While server-side validation on FilePost's end protects against actual attacks, client-side checks prevent wasted uploads and improve the user experience.
CORS
Browser requests to the API are subject to origin rules. The upload API does not allow arbitrary website origins for authenticated browser uploads. Use the hosted intake page or configure a server-side proxy for a custom interface.
Getting Started
To add uploads without exposing an API key:
- Create an intake link. In your FilePost account, set its accepted file types, size, count, and expiry.
- Verify the account email. Intake links only accept uploads after the owner verifies their email.
- Add the hosted link. Put
https://filepost.dev/u/YOUR_INTAKE_TOKENon your static site or send it to uploaders. - Use a server-side proxy for custom upload interfaces. Keep the API key in server-side configuration.
The free plan starts with one provisional upload before verification and unlocks 15 per month after email verification. It includes 50MB max file size, 2GB storage, unlimited bandwidth, and CDN delivery. The Lite plan ($4/month) gives you 300 uploads with 100MB file size and 10GB storage. If you need more, the Starter plan ($9/month) gives you 1,500 uploads with 200MB file size and unlimited storage, and the Pro plan ($29/month) gives you 7,500 uploads with 500MB file size.
No upload backend is required when you use FilePost's hosted intake page.