Prerequisites
- An API key with the
transfers:readandtransfers:writescopes, exported asYUNGLE_API_KEY. Transfers work on every plan, the free one included. - For the SDK tabs:
npm install yungle-client(Node 20 or later) orpip install yungle. For the CLI tab:npm install -g yungle-cli. See SDKs and CLI.
Steps
1
Create the transfer
Register each file with its name and its exact size in bytes. The transfer starts as a draft: the link is not live and nobody is emailed until you send it in step 3. A draft you never send is deleted after 24 hours.The response is
201 with the transfer’s id, where to upload (tusEndpoint), and one upload target per file:titleappears only in your dashboard, never to recipients.expiresInDaysdefaults to 7. A longer value is clamped to your plan’s maximum, not rejected: 7 days on the free plan, a year on a paid plan.maxBytesis the most this transfer may hold: 10 GB on the free plan, your plan’s storage quota on a paid one. Registering more returns413transfer_too_largebefore any bytes move.- Add
"path": "Day 1/Card A"to a file to keep its folder in the recipient’s zip.
2
Upload the files
Stream each file to To add more files before sending, call
tusEndpoint with its uploadToken. The SDKs and the CLI handle the protocol, retries and token renewal. To write your own client, follow Upload large files.POST /transfers/{id}/files with the same files shape. To drop one, call DELETE /transfers/{id}/files/{fileId}. Both work only on a draft: once the transfer is sent its contents are fixed, and either call returns 410 not_editable.3
Send it
Finalizing makes the link live. Choose how it reaches people:Finalizing is safe to retry: a repeated call does not email anyone twice. To add people later, finalize again with just the new addresses; only they are emailed.Who may email. An API key with
- By link: omit
recipients. Nobody is emailed and no email budget is spent. Sharetransfer.urlyourself. - By email: pass up to 10 addresses in
recipients. Yungle emails each one a personal link once every file has finished uploading, so you can finalize before the upload ends.
transfers:write may email recipients. A connection made through OAuth, such as an AI assistant over MCP, may email only if you allowed “Email recipients” when you connected it; otherwise a call with recipients returns 403 insufficient_scope naming transfers:send, and the same call without recipients still works.Email limits. A transfer has at most 10 recipients across all calls, and a workspace may email 150 recipients a day. When the daily budget is spent, finalize returns 429 email_budget_exhausted and the transfer is not sent. Call finalize again without recipients to make the link live, then share it yourself. See Email limits.4
Change the expiry or the download limit
PATCH the transfer with expiresInDays, maxDownloads, or both. expiresInDays counts from now and is clamped to your plan’s maximum. On the free plan a transfer cannot outlive 7 days from its creation. maxDownloads caps how many download sessions the link allows; null lifts the cap.{ "transfer": { … } } with the new expiresAt and maxDownloads. A revoked or expired transfer returns 410 not_editable.5
Read status and receipts
GET /transfers/{id} returns the transfer, its uploaded files with their virus-scan verdict (scanResult), and each recipient’s status. GET /transfers/{id}/downloads adds the download events.- One visit is one download. A recipient who saves eight files produces eight events that share one
sessionId. Count distinct sessions, or usetotalDownloads, which is the numbermaxDownloadsis enforced against. fileNameisnullwhen the whole transfer was downloaded as a zip.recipientEmailis set when someone used their personal emailed link, andnullwhen someone used the link you shared yourself.bouncedAtis set when mail to that address permanently failed.- The list holds the 200 most recent events.
openedandipTruncatedare retired fields, alwaysfalseandnull.
transfer.downloaded with a webhook.6
Revoke it
DELETE ends the transfer immediately. Its encryption keys are destroyed before the response returns, so the files cannot be recovered and every link already sent stops working. This cannot be undone.{ "transfer": { … } } with status set to removed. The transfer stays in your list as a record of what happened.Next steps
Upload large files
Resumable uploads, part sizes and token renewal for your own client.
Webhooks
Get
transfer.ready and transfer.downloaded as they happen.Download files
Fetch your own transfer, or a link someone shared with you.
API reference
Every field of every transfer endpoint.
