# File uploads

> Accept attachments on any form. Turn on uploads, add a file input and multipart encoding, and set size and type limits.

Source: https://sitebackend.com/docs/forms/file-uploads · Updated: 2026-10-11

SiteBackend can store files people attach to your forms: CVs, screenshots, briefs. Files are private: only members of your workspace can download them.

### Turn on uploads for the form

Open **Form → Settings → File uploads** and switch on **Accept file uploads**. Until you do, file fields are ignored.

### Add a file input and multipart encoding

A form that sends files must use `enctype="multipart/form-data"`:

```html title="apply.html" {1,5}
<form action="https://api.sitebackend.com/forms/YOUR_FORM_ID" method="POST" enctype="multipart/form-data">
  <input type="email" name="email" required />
  <label>
    CV (PDF)
    <input type="file" name="cv" accept=".pdf" required />
  </label>
  <button type="submit">Apply</button>
</form>
```

Add `multiple` to an input to let people attach several files at once.

### Check the inbox

Submitted files appear under **Attachments** on the submission, with a preview for images and a download button.

## What are the limits?

|                                              | Free   | Pro    |
| -------------------------------------------- | ------ | ------ |
| Max size per file                            | 10 MB  | 100 MB |
| Max size per submission (all files together) | 25 MB  | 150 MB |
| Storage per workspace                        | 500 MB | 5 GB   |
| Files per submission                         | 10     | 10     |

You can set a lower size limit per form under **Max file size**. Photos attached to testimonials don't count toward your storage.

## How do I restrict file types?

List the types you accept in **Allowed file types**, separated by commas. Use MIME types, wildcards or extensions:

```txt
image/*, application/pdf, .docx
```

Leave it empty to accept any type. Also set the input's `accept` attribute so the browser's file picker matches.

## What happens when a file isn't accepted?

The whole submission is rejected and nothing is stored:

| Status | `error`                                        |
| ------ | ---------------------------------------------- |
| `413`  | `<file> is too large (max 10 MB per file)`     |
| `415`  | `<file>: this file type isn't accepted`        |
| `400`  | `Too many files (max 10 per submission)`       |
| `413`  | `This form's workspace is out of file storage` |
| `413`  | `Submission is too large (max 25 MB)`          |

HTML forms show the error on the SiteBackend thank-you page; `fetch` requests get it as JSON.

## How do I upload with JavaScript?

Send a `FormData` object; the browser sets the multipart encoding for you. Don't set `Content-Type` yourself.

```js
const res = await fetch(form.action, {
  method: "POST",
  body: new FormData(form), // includes <input type="file"> fields
  headers: { Accept: "application/json" },
});
```

## Where do the files show up?

- **Inbox:** under **Attachments** on each submission.
- **Notifications:** each file's name, size and a link to download it (login required).
- **CSV export:** one column per file field, with download links.

Deleting a submission, form, site or workspace also deletes its files. Spam submissions never store files.
