> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Zulässige Dateitypen auflisten

> GET /media/allowed-files/

Listet die Erweiterungen, MIME-Typen und Größenlimits auf, die beim Datei-Upload akzeptiert werden, auf dem **Management-API**-Host (`api.scanova.io`).

```
GET https://api.scanova.io/media/allowed-files/
```

<Note>
  Keine Authentifizierung erforderlich.
</Note>

<ParamField query="file_type" type="string">
  Kommagetrennte Kategorien (`image`, `video`, `audio`, `pdf`, `doc`, `script`), auf die gefiltert wird. Weglassen für alle Kategorien.
</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl "https://api.scanova.io/media/allowed-files/?file_type=image"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  [
    {
      "file_type": "image",
      "extensions": ["png", "jpg", "jpeg", "gif", "svg"],
      "mime_types": ["image/png", "image/jpeg", "image/gif", "image/svg+xml"],
      "file_size": 5242880
    }
  ]
  ```
</ResponseExample>

Nutzen Sie dies, um eine Datei clientseitig zu validieren, bevor Sie [Datei hochladen](/de/api-reference/management-api/user-media/upload) aufrufen — `file_size` ist in Bytes angegeben. Beachten Sie, dass das tatsächlich durchgesetzte Limit der Kategorien `pdf`/`doc` höher oder niedriger sein kann als hier aufgeführt, falls das Konto eine benutzerdefinierte Plan-Quota `DOCUMENT_FILE_SIZE` hat; dieser Endpunkt meldet den statischen Standardwert.

## Verwandte Themen

* [Datei hochladen](/de/api-reference/management-api/user-media/upload) — der Endpunkt, für den diese Einschränkungen gelten.
* [Übersicht über die Management API](/de/api-reference/management-api/overview) — das Authentifizierungsschema und die Quota-Regeln für diesen Endpunkt.


## OpenAPI

````yaml api-reference/openapi/management-api.json GET /media/allowed-files/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /media/allowed-files/:
    get:
      summary: List allowed file types
      description: >-
        Reference data describing which extensions, MIME types, and size limits
        are accepted by file upload — use it to validate client-side before
        uploading. No authentication required.
      operationId: listAllowedMediaTypes
      parameters:
        - name: file_type
          in: query
          required: false
          schema:
            type: string
          description: >-
            Comma-separated categories (image, video, audio, pdf, doc, script)
            to filter to; omit for all.
      responses:
        '200':
          description: Array of allowed-type definitions.
          content:
            application/json:
              example:
                - file_type: image
                  extensions:
                    - png
                    - jpg
                    - jpeg
                    - gif
                    - svg
                  mime_types:
                    - image/png
                    - image/jpeg
                    - image/gif
                    - image/svg+xml
                  file_size: 5242880
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````