# List media

`GET https://app.pozyskajpacjenta.pl/api/v1/media` · operationId `listMedia` · since 1.2.0 · tag Media

The clinic's media library, newest first, up to 200 items.

## Request

Authorization: `Bearer <the clinic's key>`.

### cURL

```bash
curl "https://app.pozyskajpacjenta.pl/api/v1/media" \
  -H "Authorization: Bearer $PP_API_KEY"
```

### TypeScript

```ts
import { PozyskajPacjentaClient } from "@pozyskajpacjenta/sdk";

const client = new PozyskajPacjentaClient({
  apiKey: process.env.PP_API_KEY ?? "",
  baseUrl: "https://app.pozyskajpacjenta.pl",
});

const { items } = await client.listMedia();
```

### PHP

```php
<?php
$response = wp_remote_get(
    'https://app.pozyskajpacjenta.pl/api/v1/media',
    array(
        'headers' => array( 'Authorization' => 'Bearer ' . getenv( 'PP_API_KEY' ) ),
        'timeout' => 10,
    )
);
if ( is_wp_error( $response ) ) {
    error_log( $response->get_error_message() );
    return;
}
$status = wp_remote_retrieve_response_code( $response );
$data   = json_decode( wp_remote_retrieve_body( $response ), true );
```

## Response

### 200: The media library.

- `items` (`MediaItem[]`, required): The files.
  - `id` (`string`, required): Media id.
  - `r2Key` (`string`, required, deprecated): Internal storage key. Deprecated: do not use it or build addresses from it; use `url`.
  - `url` (`string`, required): Path of the file, e.g. /api/media-file/…
  - `filename` (`string`, required): Original file name.
  - `contentType` (`string`): MIME type, e.g. image/webp. Listed by GET /media.
  - `size` (`integer`): Size in bytes. Listed by GET /media.
  - `alt` (`string | null`): Alternative text; null when empty.
  - `width` (`integer | null`, since 1.4.0): Width in px; null when it could not be read from the file.
  - `height` (`integer | null`, since 1.4.0): Height in px; null when it could not be read.
  - `aiGenerated` (`boolean`, since 1.4.0): The image was generated by AI.
  - `caption` (`string | null`, since 1.4.0): Caption; null when empty.
  - `createdAt` (`string (date-time)`, since 1.9.1): Upload time, ISO 8601. Sent by GET /media (since 1.2.0), not by POST /media.

Example (The media library):

```json
{
  "items": [
    {
      "id": "G4DBcqheiu_BMwt3Y_c_L",
      "r2Key": "KdYaXquTXB/Hp7X9uzN-gabinet-zabiegowy.webp",
      "filename": "gabinet-zabiegowy.webp",
      "contentType": "image/webp",
      "size": 27044,
      "alt": "Gabinet zabiegowy z fotelem stomatologicznym",
      "width": 960,
      "height": 600,
      "aiGenerated": false,
      "caption": "Gabinet zabiegowy, parter",
      "createdAt": "2026-09-30T14:25:12.000Z",
      "url": "/api/media-file/KdYaXquTXB/Hp7X9uzN-gabinet-zabiegowy.webp"
    }
  ]
}
```

## Errors

| Status | code | When |
| --- | --- | --- |
| 401 |  | No Authorization header |
| 401 |  | Unknown or rotated key |
| 429 |  | Over 120 requests in this minute |

401 (No Authorization header):

```json
{
  "error": "missing Authorization: Bearer <klucz z panelu Ustawienia>"
}
```

401 (Unknown or rotated key):

```json
{
  "error": "invalid key"
}
```

429 (Over 120 requests in this minute):

```json
{
  "error": "przekroczono limit 120 zapytań/min"
}
```

## Rate limit

- 120 requests per minute per key, shared by every endpoint.

## SDK method

`client.listMedia(): Promise<{ items: MediaItem[] }>`
