Upload one chunk
Store one raw chunk: the body is the bytes; path, index and sha256 ride as query parameters. The server verifies the digest before storing, a mismatch is 409 and nothing is stored. Idempotent: a re-PUT atomically replaces the same part, so ANY client can resume , ask GET /api/workbench/uploads/ for the received/missing chunk map and byte accounting per file.
Authorizations
Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.
Path Parameters
Query Parameters
The manifest-relative file path this chunk belongs to.
0-based chunk index within the file.
SHA-256 of this chunk's bytes (64 hex chars).
Body
The body is of type file.
Response
Chunk stored

