> ## Documentation Index
> Fetch the complete documentation index at: https://developer.mogl.online/llms.txt
> Use this file to discover all available pages before exploring further.

# iOS — Initiate direct-to-S3 multipart upload to replace an existing slot

> iOS-only. Step 1 of 2 for replacing an existing file slot. Creates an S3 multipart upload session bound to this DealFolderFile and returns presigned URLs (one per ~10 MB part) valid for 24 hours. Call POST /deal-folder/files/{file}/replace/complete with the returned session_id and per-part ETags to finalise. Only the original uploader (or the athlete's agent) may call this; voided slots cannot be replaced.



## OpenAPI

````yaml /storage/api-docs/api-docs.json post /deal-folder/files/{file}/replace/initiate
openapi: 3.0.0
info:
  title: MOGL Core API
  description: >-
    MOGL Platform Core API — powering athlete NIL deals, brand partnerships,
    agent management, payments, messaging, and more.
     *
     * ## Authentication
     * - **JWT Bearer Token**: Most endpoints require a Bearer token obtained via `/api/login`.
     * - **Server-to-Server API Key**: Internal/lambda/cron endpoints use an `X-API-KEY` header.
     *
     * ## Rate Limiting
     * - Registration & login endpoints: 4–15 requests per minute
     * - Public/influencer endpoints: 200 requests per minute
     * - Authenticated endpoints: standard Laravel throttle
  version: 1.0.0
servers:
  - url: http://localhost/mogl/mogl-backend/api
    description: Local
  - url: https://dev-api.mogl.online/api
    description: Dev
  - url: https://staging-api.mogl.online/api
    description: Staging
  - url: https://api.mogl.online/api
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Login, registration, password reset
  - name: User Registration - Common
    description: Common user registration & email check
  - name: User Registration - Athlete
    description: Athlete registration & onboarding steps
  - name: User Registration - Partner
    description: Partner/Brand registration & onboarding steps
  - name: User Registration - Agent
    description: Agent registration & onboarding steps
  - name: User Registration - Fan
    description: Fan registration & onboarding steps
  - name: User Profile
    description: User profile management, settings, social media
  - name: Athlete
    description: 'Athlete-specific endpoints: search, details, availability'
  - name: Athlete - Availability Confirmation
    description: Post-hiring availability confirmation workflow
  - name: Athlete - NIL Feed
    description: Athlete NIL feed and partner search
  - name: Athlete - AI Assistant
    description: AI-powered job assistant for athletes — chat and conversation history
  - name: Partner
    description: Partner/Brand-specific endpoints
  - name: Partner - External Job
    description: External job link & applicant management
  - name: Partner - Deliverable Report
    description: Deliverable detail reports for brands
  - name: Partner - Screening Questions
    description: Screening question reports
  - name: Partner - Contract Management
    description: Brand contract management with athletes
  - name: Partner - Content Library
    description: Brand content library for deliverable assets
  - name: Agent
    description: Agent profile, athlete management, contracts
  - name: Agent - Athletes
    description: Agent-athlete relationship management
  - name: Agent - Stripe
    description: Agent payment methods & billing via Stripe
  - name: Agent - Contracts
    description: Agent athlete contract management
  - name: Agent - Availability Confirmation
    description: Agent managing athlete job availability
  - name: Jobs
    description: Job/deal CRUD, search, invitations, hiring, deliverables
  - name: Deals
    description: Deal listing, my deals, bulk operations
  - name: Deal Folder
    description: >-
      Deal folder file workflow — uploads, replacements, approvals, revisions,
      comments. Accessible by athlete, partner/brand, agent, and iOS clients
      (per-action authorisation enforced server-side).
  - name: Deal Folder iOS API
    description: >-
      iOS-only direct-to-S3 multipart upload endpoints for deal folder files
      (initiate/complete for new uploads and replacements). Web clients should
      use the standard `Deal Folder` upload/replace endpoints instead.
  - name: Chat
    description: Messaging, chat contacts, notifications
  - name: Notifications
    description: Notification preferences, in-app notifications
  - name: Payments
    description: Stripe payments, payment history, cards, bulk pay
  - name: Subscription
    description: Brand subscription plans & management
  - name: Public Pages
    description: Public content endpoints (no auth required)
  - name: Public - Influencer/SEO
    description: Public influencer discovery, sitemaps, directories
  - name: Services
    description: Athlete service marketplace
  - name: iOS Device
    description: iOS device tokens, live activities
  - name: Onboarding Tutorial
    description: Onboarding tutorial progress
  - name: MOGL Rosters
    description: Roster management & display
  - name: Internal / Cron
    description: Server-to-server and cron job endpoints
  - name: Affiliate
    description: Athlete affiliate links & tracking
paths:
  /deal-folder/files/{file}/replace/initiate:
    post:
      tags:
        - Deal Folder iOS API
      summary: iOS — Initiate direct-to-S3 multipart upload to replace an existing slot
      description: >-
        iOS-only. Step 1 of 2 for replacing an existing file slot. Creates an S3
        multipart upload session bound to this DealFolderFile and returns
        presigned URLs (one per ~10 MB part) valid for 24 hours. Call POST
        /deal-folder/files/{file}/replace/complete with the returned session_id
        and per-part ETags to finalise. Only the original uploader (or the
        athlete's agent) may call this; voided slots cannot be replaced.
      operationId: initiateDealFolderReplaceUpload
      parameters:
        - name: file
          in: path
          description: DealFolderFile ID (slot ID).
          required: true
          schema:
            type: integer
            example: 5
      requestBody:
        required: true
        content:
          application/json:
            schema:
              required:
                - file_name
                - file_size
                - file_mime_type
              properties:
                file_name:
                  description: Original file name (max 500 chars).
                  type: string
                  example: reel-v2.mp4
                file_size:
                  description: File size in bytes. Max 250 MB (262144000 bytes).
                  type: integer
                  example: 10215040
                file_mime_type:
                  description: MIME type of the file (max 255 chars).
                  type: string
                  example: video/mp4
              type: object
      responses:
        '200':
          description: Replace-upload session created with presigned part URLs
          content:
            application/json:
              schema:
                properties:
                  status:
                    type: string
                    example: success
                  data:
                    properties:
                      session_id:
                        description: >-
                          DealFolderUploadSession ID — pass this to
                          /replace/complete.
                        type: integer
                        example: 512
                      upload_id:
                        description: S3 multipart Upload ID.
                        type: string
                        example: 2~xyzABC987defGHI654jklMNO321pqrSTU0
                      s3_key:
                        description: The destination S3 object key for the new version.
                        type: string
                        example: deal-folders/12/slot-1/v2/reel-v2.mp4
                      parts:
                        description: >-
                          One entry per ~10 MB chunk. The iOS client must PUT
                          each chunk to its `presigned_url` and capture the
                          response ETag for the /replace/complete call.
                        type: array
                        items:
                          properties:
                            part_number:
                              type: integer
                              example: 1
                            presigned_url:
                              type: string
                              example: >-
                                https://mogl-prod.s3.amazonaws.com/deal-folders/12/slot-1/v2/reel-v2.mp4?partNumber=1&uploadId=2~xyz...&X-Amz-Signature=...
                          type: object
                    type: object
                type: object
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
        '404':
          description: Deal folder file not found
          content:
            application/json:
              schema:
                properties:
                  status:
                    type: string
                    example: error
                  message:
                    type: string
                    example: Deal folder file not found.
                type: object
        '422':
          description: Validation error / not authorised / voided slot / file-size limit
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    UnauthorizedResponse:
      properties:
        message:
          type: string
          example: Unauthenticated.
      type: object
    ValidationErrorResponse:
      properties:
        message:
          type: string
          example: The given data was invalid.
        errors:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
      type: object
  securitySchemes:
    bearerAuth:
      type: http
      description: >-
        JWT Bearer token authentication. Use the /api/login endpoint to obtain a
        token.
      scheme: bearer
      bearerFormat: JWT

````