# Repository · Assets

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## POST /repository/find-asset/{datatype}

**Find assets**

`operationId: RepositoryController_findAsset`

Searches assets of a datatype using a body-supplied query.

#### Signature

```http
POST /repository/find-asset/{datatype} (datatype: string, body) -> Matching assets
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/search-asset/{datatype}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `datatype` | path | string | yes | The collection to act on. |

### Request body

The asset query.

```json
{
  "keyword": "hero",
  "options": {
    "page": 1,
    "pageSize": 50
  }
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Matching assets |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/update-asset/{datatype}/{id}

**Update an asset**

`operationId: RepositoryController_updateAsset`

Updates an asset's metadata.

#### Signature

```http
POST /repository/update-asset/{datatype}/{id} (datatype: string, id: string, body) -> The updated asset
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `RootUser`, `RootSystem`, `RootAdmin`, `ConfigAdmin`.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/delete-asset/{datatype}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `datatype` | path | string | yes | The collection to act on. |
| `id` | path | string | yes | Asset id. |

### Request body

Fields to change.

```json
{
  "title": "Cola hero image",
  "alt": "A chilled can of cola"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The updated asset |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/delete-asset/{datatype}

**Delete assets**

`operationId: RepositoryController_deleteAsset`

Deletes several assets at once. The body is a bare array of ids.

#### Signature

```http
POST /repository/delete-asset/{datatype} (datatype: string, body) -> Deletion result
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `RootUser`, `RootSystem`, `RootAdmin`, `ConfigAdmin`.

#### Notes

- Deletes the asset records. Whether the underlying files are removed depends on the storage driver.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/file/delete`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `datatype` | path | string | yes | The collection to act on. |

### Request body

Asset ids to delete, as a bare array.

```json
[
  "66f1a2b3c4d5e6f708192a3b"
]
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Deletion result |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/search-asset/{datatype}

**Search assets**

`operationId: RepositoryController_searchAsset`

Full-text search across assets of a datatype.

**Note this handler does not read the `orgid` header** — unlike every other asset endpoint, it is not org-scoped at the controller level.

#### Signature

```http
POST /repository/search-asset/{datatype} (datatype: string, body) -> Matching assets
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Notes

- Takes no `orgid` — verify the scoping before relying on it in a multi-tenant context.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/find-asset/{datatype}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `datatype` | path | string | yes | The collection to act on. |

### Request body

The search to run.

```json
{
  "keyword": "hero"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Matching assets |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

