Cognite Files API
A file stores a sequence of bytes connected to one or more assets. Forexample, a file can contain a piping and instrumentation diagram (P&IDs)showing how multiple assets are connected.Each file is identified by the 'id' field, which is generated internallyfor each new file. Each file's 'id' field is unique within a project.The 'externalId' field is optional, but can also be used to identify a file.The 'externalId' (if used) must be unique within a project.Files are created in two steps; First the metadata is stored in a fileobject, and then the file contents are uploaded. This means that files canexist in a non-uploaded state. The upload state is reflected in the 'uploaded'field in responses.Asset references obtained from a file - through asset ids - may beinvalid, simply by the non-transactional nature of HTTP.They are maintained in an eventual consistent manner.## Rate and concurrency limitsBoth the rate of requests (denoted as request per second, or â**rps**â) and the number of concurrent (parallel) requests are governed by limits,for all CDF API endpoints. If a request exceeds one of the limits,it will be throttled with a `429: Too Many Requests` response. More on limit typesand how to avoid being throttled is described[here](https://docs.cognite.com/dev/concepts/resource_throttling).Limits are defined at both the overall API service level, and on the API endpoints belonging to the service.Some types of requests consume more resources (compute, storage IO) than others, and where a service handlesmultiple concurrent requests with varying resource consumption.For example, âCRUDâ type requests (**C**reate, **R**etrieve, **R**equest ByIDs, **U**pdate and **D**elete and similar) are far less resourceintensive than âAnalyticalâ type requests (List, Search and Filter) and in addition, the most resourceintensive Analytical endpoint of all, Aggregates, receives its own request budget within the overall Analytical request budget.The version 1.0 limits for the overall API service and its constituent endpoints are illustrated in the diagram below.These limits are subject to change, pending review of changing consumption patterns and resource availability over time:### Translating RPS into data speedA single request may retrieve up to 1000 items. In the context of Files, 1 item = 1 file recordTherefore, the maximum theoretical data speed at the top API service level is 160,000 items per second for all consumers,and 120,000 for a single identity or client in a project.### Use of Partitions / Parallel RetrievalAs a general guidance, Parallel Retrieval is a technique that should be used where due to query complexity, retrieval of data in asingle request session turns out to be slow. By parallelizing such requests, data retrieval performance can be tuned to meet theclient application needs. Parallel retrieval may also be used where retrieval of large sets of data is required, up to thecapacity limits defined for a given API service. For example (using the Files API request budget):* A single request may retrieve up to 1000 items* Up to 23 requests per second may be issued for an analytical query (per identity), such as when using /list or /filter API endpoints* This provides a theoretical maximum of 23,000 items read per second per identity* The query complexity may result in it taking longer than 1s to read or write 1000 items in a single request* Therefore, it is appropriate to specify the query to retrieve a lower number of items per request, and retrieve more items in parallel, up to the theoretical maximum performance of 23,000 items per second.**Important Note:**Parallel retrieval should be only used in situations where, due to query complexity,a single request flow provides data retrieval speeds that are significantly less than the theoretical maximum.Parallel retrieval does not act as a speed multiplier on optimally running queries. Regardless of the numberof concurrent requests issued, the overall requests per second limit still applies.So for example, a single request returning data at approximately 18,000 items per second will onlybenefit from adding a second parallel request, the capacity of which goes somewhat wastedas only an additional 5,000 items per second will return before the request rate budget limit is reached.
Cognite Files API is one of 90 APIs that Cognite publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include File. The published artifact set on APIs.io includes an OpenAPI specification.
This API exposes 15 operations across 14 paths, and defines 104 schemas. It is described by OpenAPI 3.2.0, at version v1.
Requests are made against a single base URL, https://{cluster}.cognitedata.com/api/v1/projects/{project}.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 5
Cognite Files API declares
5 security schemes
for authenticating requests.
It accepts HTTP bearer tokens (OpenID Connect or OAuth2 token) (oidc-token).
It supports OAuth 2.0 (oauth2-client-credentials) using the clientCredentials flow, exposing 1 scope.
It supports OAuth 2.0 (oauth2-auth-code) using the authorizationCode flow, exposing 1 scope.
It supports OAuth 2.0 (oauth2-open-industrial-data) using the clientCredentials flow, exposing 1 scope.
It supports OpenID Connect (org-oidc-token) discovered at https://auth.cognite.com/.well-known/openid-configuration.
By default, every request must be authenticated.
oidc-token— Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to acce…oauth2-client-credentials— Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to acce…oauth2-auth-code— Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to acce…oauth2-open-industrial-data— Auth flow for Open Industrial Data. Get your client secret from https://hub.cognite.com/open-industrial-data-211.org-oidc-token— Access token issued by the Cognite authorization server, and valid for the target organization. The token must be an OpenID Connect token, and it can be obtain…
Paths & Operations 15
Across 14 paths, the API surfaces 15 operations — 3 GET, 12 POST. Each is listed below with its method, path, parameters, and response codes.
A file stores a sequence of bytes connected to one or more assets. For example, a file can contain a piping and instrumentation diagram (P&IDs) showing how multiple assets are con…
Schemas 104
The contract defines 104 schemas that model the data the API accepts and returns. The most detailed are ExternalFilesMetadata (13 properties), Error (4 properties), GeoLocation (3 properties), DataWithCursor (2 properties). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
More from Cognite 12
Other APIs Cognite publishes across the network.
This is an independent, third-party profile of Cognite Files API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.