> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# 列出允许的文件类型

> GET /media/allowed-files/

在**管理 API** 主机 (`api.scanova.io`) 上列出文件上传时可接受的扩展名、MIME 类型和大小限制。

```
GET https://api.scanova.io/media/allowed-files/
```

<Note>
  无需身份验证。
</Note>

<ParamField query="file_type" type="string">
  要筛选的以逗号分隔的类别（`image`、`video`、`audio`、`pdf`、`doc`、`script`）。省略则返回所有类别。
</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl "https://api.scanova.io/media/allowed-files/?file_type=image"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  [
    {
      "file_type": "image",
      "extensions": ["png", "jpg", "jpeg", "gif", "svg"],
      "mime_types": ["image/png", "image/jpeg", "image/gif", "image/svg+xml"],
      "file_size": 5242880
    }
  ]
  ```
</ResponseExample>

在调用[上传文件](/zh/api-reference/management-api/user-media/upload)之前，使用此接口在客户端验证文件 —— `file_size` 以字节为单位。请注意，如果账户拥有自定义的计划配额 `DOCUMENT_FILE_SIZE`，`pdf`/`doc` 类别实际生效的限制可能高于或低于此处列出的值；此端点报告的是静态默认值。

## 相关内容

* [上传文件](/zh/api-reference/management-api/user-media/upload) —— 这些限制所适用的端点。
* [管理 API 概述](/zh/api-reference/management-api/overview) —— 适用于此端点的身份验证方案和配额规则。


## OpenAPI

````yaml api-reference/openapi/management-api.json GET /media/allowed-files/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /media/allowed-files/:
    get:
      summary: List allowed file types
      description: >-
        Reference data describing which extensions, MIME types, and size limits
        are accepted by file upload — use it to validate client-side before
        uploading. No authentication required.
      operationId: listAllowedMediaTypes
      parameters:
        - name: file_type
          in: query
          required: false
          schema:
            type: string
          description: >-
            Comma-separated categories (image, video, audio, pdf, doc, script)
            to filter to; omit for all.
      responses:
        '200':
          description: Array of allowed-type definitions.
          content:
            application/json:
              example:
                - file_type: image
                  extensions:
                    - png
                    - jpg
                    - jpeg
                    - gif
                    - svg
                  mime_types:
                    - image/png
                    - image/jpeg
                    - image/gif
                    - image/svg+xml
                  file_size: 5242880
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````