Skip to content

Query parameters

Parameters of GET /imagepreset. Any failed rule returns 404.

ParameterRuleAllowlist / limitDescription
srcrequired string, ≤ 1000 charsLocal: no .., null byte or leading .. Remote: allowed_hosts or APP_URL hostSource image, see Image sources
presetstringKey of presetsNamed preset; its values are not checked against allowlists
winteger 1–20000allowed_widths (alone) or allowed_sizes (with h)Width, px
hinteger 1–20000allowed_heights (alone) or allowed_sizes (with w)Height, px
qintegerallowed_qualitiesQuality. Default quality
fmstringallowed_formatsOutput format. Default format
fitstring, needs w or h in the requestallowed_fitsFit method. Default default_fit_both / default_fit_one
blurinteger 0–blur_maxBlur
sharpinteger 0–sharp_maxSharpen
orstringallowed_orientationsauto (EXIF), 0, 90, 180, 270
crop^\d+,\d+,\d+,\d+$Rectangle width,height,x,y cut before resizing
bg^[0-9a-fA-F]{3,8}$Background colour, hex without #
_tstring, exactly 16 charsTrusted token, see Trusted bypass
signatureAdded by signed URLs, checked by the signed middleware
  • With a valid _t, the allowed_sizes/widths/heights/qualities/fits/formats checks are skipped.
  • ['*'] disables allowed_sizes, allowed_widths, allowed_heights, allowed_qualities.
  • Empty values (?w=) count as absent.
  • Unknown parameters are ignored by processing but are part of the cache key (_t is not).