> ## Documentation Index
> Fetch the complete documentation index at: https://developers.myhero.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate an embed URL

> Checks whether the given `url` is safe and suitable for embedding in the editor.

Blocks executable and archive file extensions, follows redirects, and inspects the Content-Type and Content-Disposition headers of the remote resource.

Returns `{ valid: true }` on success or `{ valid: false, message }` with the reason for rejection.



## OpenAPI

````yaml post /upload/validate-embed-url
openapi: 3.1.0
info:
  title: HERO API
  version: current
  description: |-
    The HERO REST API.

    See https://developers.myhero.so for the rendered docs.
servers:
  - url: https://app.myhero.so
security: []
paths:
  /upload/validate-embed-url:
    post:
      tags:
        - Upload
      summary: Validate an embed URL
      description: >-
        Checks whether the given `url` is safe and suitable for embedding in the
        editor.


        Blocks executable and archive file extensions, follows redirects, and
        inspects the Content-Type and Content-Disposition headers of the remote
        resource.


        Returns `{ valid: true }` on success or `{ valid: false, message }` with
        the reason for rejection.
      operationId: validateEmbedUrl
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  minLength: 1
              required:
                - url
      responses:
        '200':
          description: 200 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  url:
                    type: string
                  valid:
                    type: boolean
                    enum:
                      - true
                  message:
                    type: string
                required:
                  - url
                  - valid
                  - message
        '400':
          description: 400 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  url:
                    type: string
                  valid:
                    type: boolean
                    enum:
                      - false
                  message:
                    type: string
                required:
                  - valid
                  - message
        '403':
          description: 403 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: HERO personal access token

````