filescom-bundles

SkillFiles & storage

A Bundle is the API/SDK term for the feature called Share Links in the web interface. Creating a Share Link does not send any email. To deliver the link by email, either call `bundles share` after creation, or pass `--share-after-create=true` when adding a recipient with `bundle-recipients create`.

Use filescom-bundles in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add filescom-bundles and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the filescom-bundles skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

filescom-bundlesStart free

What this skill tells your AI

The instructions your AI receives, as published by files-com/files-cli in skills/filescom-bundles/SKILL.md and read by Ahel’s review.

A Bundle is the API/SDK term for the feature called Share Links in the web interface. The API provides the full set of actions related to Share Links, including sending them via E-Mail.

Please note that we very closely monitor the E-Mailing feature and any abuse will result in disabling of your site.

All subcommands also accept the flags documented in CONTEXT.md (--api-key, --format, --workspace-id, --debug, and the pagination flags --cursor / --per-page / --max-pages on list). Those are not repeated below.

Commands

files-cli bundles list

List Share Links.

FlagTypeDescription
--user-idint64User ID. Provide a value of 0 to operate the current session's user.
--sort-byobjectIf set, sort records by the specified field in either asc or desc direction. Valid fields are expires_at.
--filterobjectIf set, return records where the specified field is equal to the supplied value. Valid fields are created_at, expires_at, code, group_id, user_id or bypasses_site_expiration_rules. Valid field combinations are [ group_id, expires_at ] and [ user_id, expires_at ].
--filter-gtobjectIf set, return records where the specified field is greater than the supplied value. Valid fields are created_at and expires_at.
--filter-gteqobjectIf set, return records where the specified field is greater than or equal the supplied value. Valid fields are created_at and expires_at.
--filter-prefixobjectIf set, return records where the specified field is prefixed by the supplied value. Valid fields are code.
--filter-ltobjectIf set, return records where the specified field is less than the supplied value. Valid fields are created_at and expires_at.
--filter-lteqobjectIf set, return records where the specified field is less than or equal the supplied value. Valid fields are created_at and expires_at.
--deletedboolIf true, only list deleted Share Links.

files-cli bundles find

Show Share Link.

FlagTypeDescription
--idint64Bundle ID. Required.
--deletedboolIf true, show a deleted Share Link.

files-cli bundles create

Create Share Link.

FlagTypeDescription
--user-idint64User ID. Provide a value of 0 to operate the current session's user.
--paths[]stringA list of paths to include in this bundle. Required.
--passwordstringPassword for this bundle.
--bypasses-site-expiration-rulesboolIf true, this Share Link bypasses site-wide expiration rules. Only site admins may set this.
--form-field-set-idint64Id of Form Field Set to use with this bundle
--create-snapshotboolIf true, create a snapshot of this bundle's contents.
--dont-separate-submissions-by-folderboolDo not create subfolders for files uploaded to this share. Note: there are subtle security pitfalls with allowing anonymous uploads from multiple users to live in the same folder. We strongly discourage use of this option unless absolutely required.
--expires-atdatetimeExplicit Bundle expiration date/time. If not set, the site-wide expiration setting may apply.
--finalize-snapshotboolIf true, finalize the snapshot of this bundle's contents. Note that create_snapshot must also be true.
--max-usesint64Maximum number of times bundle can be accessed
--group-idint64Owning group ID. If set, members of this group can view, edit, and share this Share Link.
--internal-namestringInternal name for identifying this Share Link.
--descriptionstringPublic description
--notestringBundle internal note
--codestringBundle code. This code forms the end part of the Public URL.
--path-templatestringTemplate for creating submission subfolders. Can use the uploader's name, email address, ip, company, strftime directives, and any custom form data.
--path-template-time-zonestringTimezone to use when rendering timestamps in path templates.
--permissionsenumPermissions that apply to Folders in this Share Link. One of: read, write, read_write, full, none, preview_only.
--require-registrationboolShow a registration page that captures the downloader's name and email address?
--clickwrap-idint64ID of the clickwrap to use with this bundle.
--inbox-idint64ID of the associated inbox, if available.
--require-share-recipientboolOnly allow access to recipients who have explicitly received the share via an email sent through the Files.com UI?
--send-one-time-password-to-recipient-at-registrationboolIf true, require_share_recipient bundles will send a one-time password to the recipient when they register. Cannot be enabled if the bundle has a password set.
--send-email-receipt-to-uploaderboolSend delivery receipt to the uploader. Note: For writable share only
--skip-emailboolBundleRegistrations can be saved without providing email?
--skip-nameboolBundleRegistrations can be saved without providing name?
--skip-companyboolBundleRegistrations can be saved without providing company?
--start-access-on-datedatetimeDate when share will start to be accessible. If nil access granted right after create.
--snapshot-idint64ID of the snapshot containing this bundle's contents.
--workspace-idint64Workspace ID. 0 means the default workspace.
--watermark-attachment-filefilePreview watermark image applied to all bundle items.
--watermark-valueobjectPreview watermark settings applied to all bundle items. Uses the same keys as Behavior.value

files-cli bundles share

Send email(s) with a link to bundle.

FlagTypeDescription
--idint64Bundle ID. Required.
--to[]stringA list of email addresses to share this bundle with. Required unless recipients is used.
--notestringNote to include in email.
--recipients[]objectA list of recipients to share this bundle with. Required unless to is used.

files-cli bundles update

Update Share Link.

FlagTypeDescription
--idint64Bundle ID. Required.
--paths[]stringA list of paths to include in this bundle.
--passwordstringPassword for this bundle.
--bypasses-site-expiration-rulesboolIf true, this Share Link bypasses site-wide expiration rules. Only site admins may set this.
--form-field-set-idint64Id of Form Field Set to use with this bundle
--clickwrap-idint64ID of the clickwrap to use with this bundle.
--codestringBundle code. This code forms the end part of the Public URL.
--create-snapshotboolIf true, create a snapshot of this bundle's contents.
--descriptionstringPublic description
--dont-separate-submissions-by-folderboolDo not create subfolders for files uploaded to this share. Note: there are subtle security pitfalls with allowing anonymous uploads from multiple users to live in the same folder. We strongly discourage use of this option unless absolutely required.
--expires-atdatetimeExplicit Bundle expiration date/time. If not set, the site-wide expiration setting may apply.
--finalize-snapshotboolIf true, finalize the snapshot of this bundle's contents. Note that create_snapshot must also be true.
--inbox-idint64ID of the associated inbox, if available.
--max-usesint64Maximum number of times bundle can be accessed
--group-idint64Owning group ID. If set, members of this group can view, edit, and share this Share Link.
--internal-namestringInternal name for identifying this Share Link.
--notestringBundle internal note
--path-templatestringTemplate for creating submission subfolders. Can use the uploader's name, email address, ip, company, strftime directives, and any custom form data.
--path-template-time-zonestringTimezone to use when rendering timestamps in path templates.
--permissionsenumPermissions that apply to Folders in this Share Link. One of: read, write, read_write, full, none, preview_only.
--require-registrationboolShow a registration page that captures the downloader's name and email address?
--require-share-recipientboolOnly allow access to recipients who have explicitly received the share via an email sent through the Files.com UI?
--send-one-time-password-to-recipient-at-registrationboolIf true, require_share_recipient bundles will send a one-time password to the recipient when they register. Cannot be enabled if the bundle has a password set.
--send-email-receipt-to-uploaderboolSend delivery receipt to the uploader. Note: For writable share only
--skip-companyboolBundleRegistrations can be saved without providing company?
--start-access-on-datedatetimeDate when share will start to be accessible. If nil access granted right after create.
--skip-emailboolBundleRegistrations can be saved without providing email?
--skip-nameboolBundleRegistrations can be saved without providing name?
--user-idint64The owning user id. Only site admins can set this.
--watermark-attachment-deleteboolIf true, will delete the file stored in watermark_attachment
--watermark-attachment-filefilePreview watermark image applied to all bundle items.
--watermark-valueobjectPreview watermark settings applied to all bundle items. Uses the same keys as Behavior.value
--workspace-idint64Workspace ID. 0 means the default workspace.

files-cli bundles delete

Delete Share Link.

FlagTypeDescription
--idint64Bundle ID. Required.

Limitations and considerations

Sending the link is a separate step from creating it. bundles create returns the URL and code but does not email anyone. Two delivery paths exist: bundles share sends to one or more addresses; bundle-recipients create --share-after-create=true adds a recipient and emails them at creation. Do not delete and recreate the bundle to trigger delivery — neither is necessary, and the per-recipient rate limit below makes recreate-and-resend ineffective anyway.

Per-recipient invitation emails are rate-limited to once every 24 hours. A bundles share call to the same address within that window will not actually re-send.

Snapshot Share Links are immutable. A Share Link created with --create-snapshot --finalize-snapshot captures the file set at creation time and cannot be edited afterward. Adding files to the source folder later does not change what a Snapshot link delivers. Live Share Links include source changes; Snapshot Share Links do not.

Password protection and one-time-password are mutually exclusive. Only one authentication type is permitted per Share Link. If both --password and --send-one-time-password-to-recipient-at-registration are set, the create will fail.

Adding access control after the fact does not revoke active sessions. Enabling access control on an existing Share Link blocks new visitors but does not remove access from visitors already in a session.

Site-wide expiration changes are retroactive. Lowering the site-wide Share Link expiration setting immediately expires any links that have been active longer than the new threshold.

--dont-separate-submissions-by-folder is a security risk. It allows anonymous uploads from multiple users to live in the same folder, which has subtle security pitfalls. Do not enable without a specific reason.

Common patterns

Create a Share Link and email it after creation

  1. Create:

    files-cli bundles create --paths=/demo/q3-report.pdf --description="Q3 report" --format=json
    

    The response includes an id. Use it in step 2.

  2. Email:

    files-cli bundles share --id=<BUNDLE_ID> --to=bob@example.com --note="Q3 report attached" --format=json
    

    bundles share can deliver to up to 50 addresses in a single call.

Create a Share Link and email it at the same time (recipient route)

files-cli bundles create --paths=/demo/q3-report.pdf --description="Q3 report" --format=json
files-cli bundle-recipients create --bundle-id=<BUNDLE_ID> --recipient=bob@example.com --share-after-create=true --format=json

This adds the recipient row and triggers the invitation email in one call.

Restrict access to named recipients only

A Share Link with --require-share-recipient is only accessible to recipients who received an emailed invitation through Files.com. Create then deliver via bundles share:

files-cli bundles create --paths=/legal/contract.pdf --require-share-recipient --format=json
files-cli bundles share --id=<BUNDLE_ID> --to=counsel@example.com --to=ceo@example.com --format=json

Audit who downloaded a Share Link

files-cli bundle-downloads list --bundle-id=<BUNDLE_ID> --format=json

Signals

GitHub stars
46
Forks
4
Last commit
Oct 2026
Advanced
Item type
skill
Key
filescom-bundles
Source
github.com/files-com/files-cli