Skip to main content

Download attachment content

GET 

/openapi/v1/credentials/:credentialId/attachments/:attachmentId/content

Returns the raw file bytes with the original Content-Type and a Content-Disposition set to the original filename. The URL is a short-lived signed link scoped to the requesting caller — obtain a fresh contentUrl (with exp and sig query parameters) from the attachment metadata endpoints. Per-credential authorization is still enforced independently of the signature.

S3-backed attachments normally answer with a 302 to a presigned S3 URL. Pass redirect=false to receive that URL as JSON instead. This exists for HTTP clients that replay request headers across a redirect: S3 rejects a presigned GET that also carries an Authorization header, so such a client cannot follow the 302. Fetching the URL as data lets the caller issue the S3 request unauthenticated. The flag is ignored for legacy inline attachments, which have no presigned URL and always stream their bytes.

Request​

Responses​

OK