# Complete a catalog photo upload

> Completes a photo upload after its bytes were PUT: bymundi re-encodes it and attaches it to the entry — last, or as the lead photo with `position: first`.

`POST /v1/catalog/entities/{entityId}/images/{assetId}/complete`

Completes a photo upload after its bytes were PUT: bymundi re-encodes it and attaches it to the entry — last, or as the lead photo with `position: first`. Nothing uploaded yet is a 422 `upload_missing`; bytes that are not an image a 422 `not_an_image`; a second completion a 409 `already_complete`. Undo with POST /changes/{changeId}/revert: it takes the photo off the entry while nobody has changed its photos since.

**Permissions:** `catalog:write` · **Kind:** write · **Cost:** 2 units · MCP tool [`complete_catalog_image_upload`](https://api.bymundi.com/docs/mcp/tools/complete_catalog_image_upload.md)

Undoable: the response carries `Bymundi-Change-Id`; [revert it](https://api.bymundi.com/docs/guides/undo-and-dry-run.md) with `POST /v1/changes/{changeId}/revert`.

## Path parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `entityId` | uuid | yes |  |
| `assetId` | uuid | yes |  |

## Body

| Field | Type | Required | Description |
|---|---|---|---|
| `alt` | string |  | A description of the photo for screen readers (recommended). max 300 chars |
| `position` | "first" \| "last" |  | `first` makes it the entry's lead photo; `last` (the default) appends it. default "last" |

## Response `200`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "catalog_entity" | yes |  |
| `id` | uuid | yes |  |
| `kind` | "destino" \| "punto" \| "alojamiento" \| "actividad" \| "servicio" | yes |  |
| `name` | string | yes |  |
| `placeId` | string | yes |  |
| `cityKey` | string | yes |  |
| `externalId` | string | yes |  |
| `place` | object | yes |  |
| `images` | object[] | yes |  |
| `tags` | string[] | yes |  |
| `origin` | "human" \| "ai" \| "api" \| "import" | yes |  |
| `content` | object | yes |  |
| `updatedAt` | string | yes |  |
| `deletedAt` | string \| null | yes |  |

## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached
- [`not_found`](https://api.bymundi.com/problems/not_found.md) — Not found
- [`idempotency_key_reused`](https://api.bymundi.com/problems/idempotency_key_reused.md) — Idempotency-Key reused
- [`request_in_progress`](https://api.bymundi.com/problems/request_in_progress.md) — Request in progress

## Examples

#### curl

```bash
curl -X POST https://api.bymundi.com/v1/catalog/entities/$ENTITY_ID/images/$ASSET_ID/complete \
  -H "Authorization: Bearer $BYMUNDI_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{}'
```

#### JavaScript

```javascript
const res = await fetch(`https://api.bymundi.com/v1/catalog/entities/${entityId}/images/${assetId}/complete`, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify({}),
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.post(
    f"https://api.bymundi.com/v1/catalog/entities/{entityId}/images/{assetId}/complete",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
    json={},
)
res.raise_for_status()
data = res.json()
```
