> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Listar tipos de archivo permitidos

> GET /media/allowed-files/

Lista las extensiones, tipos MIME y límites de tamaño aceptados al subir archivos, en el host de la **API de gestión** (`api.scanova.io`).

```
GET https://api.scanova.io/media/allowed-files/
```

<Note>
  No se requiere autenticación.
</Note>

<ParamField query="file_type" type="string">
  Categorías separadas por comas (`image`, `video`, `audio`, `pdf`, `doc`, `script`) por las que filtrar. Omita para todas las categorías.
</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl "https://api.scanova.io/media/allowed-files/?file_type=image"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  [
    {
      "file_type": "image",
      "extensions": ["png", "jpg", "jpeg", "gif", "svg"],
      "mime_types": ["image/png", "image/jpeg", "image/gif", "image/svg+xml"],
      "file_size": 5242880
    }
  ]
  ```
</ResponseExample>

Use esto para validar un archivo en el cliente antes de llamar a [Subir un archivo](/es/api-reference/management-api/user-media/upload) — `file_size` se da en bytes. Tenga en cuenta que el límite realmente aplicado para las categorías `pdf`/`doc` puede ser mayor o menor que el aquí indicado si la cuenta tiene una cuota de plan `DOCUMENT_FILE_SIZE` personalizada; este endpoint reporta el valor predeterminado estático.

## Relacionado

* [Subir un archivo](/es/api-reference/management-api/user-media/upload) — el endpoint al que se aplican estas restricciones.
* [Resumen de la API de gestión](/es/api-reference/management-api/overview) — el esquema de autenticación y las reglas de cuota que se aplican a este endpoint.


## OpenAPI

````yaml api-reference/openapi/management-api.json GET /media/allowed-files/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /media/allowed-files/:
    get:
      summary: List allowed file types
      description: >-
        Reference data describing which extensions, MIME types, and size limits
        are accepted by file upload — use it to validate client-side before
        uploading. No authentication required.
      operationId: listAllowedMediaTypes
      parameters:
        - name: file_type
          in: query
          required: false
          schema:
            type: string
          description: >-
            Comma-separated categories (image, video, audio, pdf, doc, script)
            to filter to; omit for all.
      responses:
        '200':
          description: Array of allowed-type definitions.
          content:
            application/json:
              example:
                - file_type: image
                  extensions:
                    - png
                    - jpg
                    - jpeg
                    - gif
                    - svg
                  mime_types:
                    - image/png
                    - image/jpeg
                    - image/gif
                    - image/svg+xml
                  file_size: 5242880
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````