An enterprise-grade media ingestion pipeline supporting single and bulk multipart/form-data submissions, binary magic bytes integrity validation, Cloudinary CDN delivery with auto-generated metadata, and real-time SSE broadcasts.
Select or drop real files to test the live upload pipeline against your isolated visitor sandbox.
Drag & drop an image, document, or PDF here
Or click to browse from your device. Max file size: 5 MB.
Live items persisted in your visitor overlay sandbox. Queryable via GET /api/v1/uploads.
No uploaded files in this category
Use the live upload sandbox above to upload an image, document, or PDF to see it appear here instantly.
Query, inspect, and delete media files directly against the running API endpoint:
How Playground API protects sandboxes from disguised malware, webshells, and arbitrary code execution.
Playground API does not rely solely on user-supplied Content-Type headers or file extensions. Before saving, the backend inspects the binary buffer's leading bytes to verify authentic file signatures:
| Type | Magic Signature (Hex / ASCII) |
|---|---|
| JPEG / JPG | FF D8 FF |
| PNG | 89 50 4E 47 |
| GIF | 47 49 46 38 |
| 25 50 44 46 (%PDF) | |
| WebP | RIFF .... WEBP |
Files containing executable headers (Windows PE 4D5A, Linux ELF 7F454C46, or macOS Mach-O FEEDFACE) disguised as images or documents are rejected immediately with HTTP 415 PROHIBITED_FILE_TYPE.
exe, bat, cmd, sh, bash, php, phtml, js, mjs, ts, py, pyc, rb, pl, jsp, asp, aspx, vbs, dll, so, wasm, jar, html, htm, msi
Triggered if single file payload exceeds 5 MB.
Disguised executable or banned script extension.
Session sandbox limit reached (15 active files max).
Bulk batch payload exceeded 10 items limit.
Drop-in examples for browser FormData, Axios progress listeners, Python scripts, and cURL: