Nothing here yet
Drop images anywhere on this page, or use Upload.
Users
| User | Contact | URL id | Status | Files | Storage | API keys | Last sign-in |
|---|
No users yet
Create one — they get their own media library and a public / secret key pair.
API keys
The public key identifies the account in client-side uploads and may appear in web pages. The secret key signs those uploads and calls the API — keep it on servers only. Secrets are shown once, when created; revoke a key and generate a new one if it leaks.
| Label | Public key | Secret | Created | Last used | Status |
|---|
Developer
Credentials
You have no API key yet. Generate a key pair to call the API from your code.
The secret key uploads, deletes and signs client uploads. Use it only from server code (e.g. the Ramrogaadi API) — never in a web page visitors load. Delivery URLs are public and need no key.
URL transformations
Add ?tr= to any image URL, or put tr:… as the first path segment. Results are cached.
| Param | Meaning | Example |
|---|---|---|
w | Width in px (below 1 = fraction of original) | w-400, w-0.5 |
h | Height in px | h-300 |
ar | Aspect ratio, with only w or h | w-800,ar-16-9 |
c | Crop strategy: maintain_ratio (fill & crop, default), at_max (fit inside), at_least (cover), force (stretch) | c-at_max |
cm | pad_resize: fit inside, pad to exact size with bg | cm-pad_resize,bg-FFFFFF |
fo | Crop focus: center, top, bottom, left, right, top_left… | fo-top |
q | Quality 1–100 (default 80) | q-70 |
f | Format: auto (WebP when the browser supports it), webp, jpg, png, orig | f-auto |
bl | Blur 1–100 | bl-10 |
rt | Rotate 90 / 180 / 270 | rt-90 |
e | Effect: grayscale | e-grayscale |
Upload API
POST /api/v1/files/upload — multipart form. Fields: file (required), folder, fileName, useUniqueFileName (default true), overwriteFile.
Response:
{ "name": "logo_k3j9a2xq.png", "filePath": "/Image/Dealers/logo_k3j9a2xq.png",
"url": "…/Image/Dealers/logo_k3j9a2xq.png", "size": 48213, "fileType": "image",
"mimeType": "image/png", "width": 512, "height": 512, "modified": "…" }
From C# (e.g. the Ramrogaadi API)
Client-side upload (from a browser)
Same as ImageKit: your back end signs each upload with the secret key; the page sends the file with the public key and that signature, so the secret never reaches the browser. A token can be used once; expire is a Unix time at most 1 hour ahead.
Signature: HMAC-SHA1(secretKey, token + expire) as lower-case hex. Or let this server make one: GET /api/v1/upload-auth with your secret key returns { token, expire, signature, publicKey }.
Management endpoints
| Method | Path | Purpose |
|---|---|---|
| GET | /api/v1/files?path=&search=&skip=&limit=&sort= | List a folder (or search below it) |
| GET | /api/v1/files/details?filePath= | One file, with width/height |
| POST | /api/v1/files/upload | Upload |
| POST | /api/v1/files/move | Rename / move { filePath, destinationPath, newFileName } |
| DELETE | /api/v1/files?filePath= | Delete a file |
| POST | /api/v1/files/purge | Drop a file's cached transforms { filePath } |
| POST | /api/v1/folder | Create { folderName, parentFolderPath } |
| DELETE | /api/v1/folder?folderPath= | Delete a folder and everything in it |
| GET | /api/v1/stats | Usage totals |
| GET | /api/v1/upload-auth | A one-time signature for a client-side upload |
| GET / POST | /api/v1/keys | List your key pairs / generate a new one { label } |
| DELETE | /api/v1/keys/{id} | Revoke a key pair |
Authenticate with X-Api-Key: <secret>, Authorization: Bearer <secret>, or ImageKit-style Authorization: Basic base64(secret + ":").
Admin (admin key only)
| GET / POST | /api/v1/admin/users | List users / create one { name, email, urlId } — returns its first key pair |
| PATCH / DELETE | /api/v1/admin/users/{id} | Rename, enable / disable { isActive } / delete (?deleteFiles=true) |
| GET / POST / DELETE | /api/v1/admin/users/{id}/keys[/{keyId}] | A user's key pairs |
With the admin key, library endpoints act on the account named in an X-Account: <urlId> header.
Monitor
Health
Bandwidth by day
By account
| Account | Last 24 h | Last 7 days | Period | Requests | Transforms | Not found |
|---|
Storage
Drives
By account
| Account | Owner | Files | Size | Cache | Trash |
|---|
Custom domains
Serve your images from your own domain
- At your DNS provider, add a CNAME record:
images.yourdomain.com→— or an A record →. - Add domain saves the assignment and checks the connection automatically. If it is pending, finish the DNS and server setup, then press Verify again.
- Route this hostname to ImageServer on your web server. On IIS, add an HTTP binding for the domain. For HTTPS, also add an HTTPS binding and a certificate covering the domain.
- Nothing else to set up — this server routes every verified domain automatically and issues its HTTPS certificate (Let's Encrypt) on the first visit.
- Once verified, files are served at
https://images.yourdomain.com/cars/x.jpg, and the API returns URLs on your primary domain.
DNS records are managed at your DNS provider. Adding a domain here does not change DNS, web server bindings, or certificates.
| Domain | Status | Last check |
|---|
Trash
| Item | Size | Why | When | By |
|---|
Security & backups
⚠ Possible ransomware / mass damage
While this alert is open, no snapshot is ever deleted. To recover: isolate the machine, find the last snapshot from before the damage below, and restore from it. Acknowledge only once the library is clean.
Backups
Every file version is kept once by its content hash; a file encrypted by ransomware becomes a new version and the good one stays restorable. Also copy this folder off the server (another machine, a NAS with snapshots, or cloud storage with object lock) — ransomware that controls the server can reach its local disks.
| Snapshot | Files | Size | New versions | Changed | Removed | Health |
|---|
Activity log
| When | Who | Account | Action | Target | Detail | IP |
|---|
Settings
Your account
Server
These come from appsettings.json → ImageServer. Set PublicBaseUrl to the public address (e.g. https://img.ramrogaadi.com) so returned URLs use it.
Transform cache
Each transformed variant is rendered once and kept. Clearing it is safe; variants are re-rendered on next request.