# Repository · Media

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## POST /repository/media/photos

**Search stock photos**

`operationId: RepositoryController_searchPhotosFromPexel`

Searches a stock photo provider, so an editor can pick an image without leaving the product. Results are the provider's and are not stored until used.

#### Signature

```http
POST /repository/media/photos (body) -> Matching stock photos
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Notes

- Provider licensing applies to any image you use — this endpoint does not grant rights.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/media/photos/curated`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The photo search.

```json
{
  "query": "summer drinks",
  "per_page": 20,
  "orientation": "landscape"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Matching stock photos |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/media/photos/curated

**Get curated stock photos**

`operationId: RepositoryController_searchPhotosFromPexelCurated`

Returns the provider's curated photo selection, for a starting point when there is no search term.

#### Signature

```http
POST /repository/media/photos/curated (body) -> Curated photos
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/media/photos`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

Paging.

```json
{
  "per_page": 20,
  "page": 1
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Curated photos |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/media/videos

**Search stock videos**

`operationId: RepositoryController_searchVideosFromPexel`

Searches a stock video provider. The video counterpart to the photo search.

#### Signature

```http
POST /repository/media/videos (body) -> Matching stock videos
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/media/videos/popular`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The video search.

```json
{
  "query": "city timelapse",
  "per_page": 20
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Matching stock videos |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/media/videos/popular

**Get popular stock videos**

`operationId: RepositoryController_searchVideosFromPexelPopular`

Returns the provider's popular video selection.

#### Signature

```http
POST /repository/media/videos/popular (body) -> Popular videos
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/media/videos`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

Paging.

```json
{
  "per_page": 20
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | Popular videos |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

