Download an attachment
Not under /v1 — a tenant-scoped convenience endpoint, not a public CDN. Requires an API key whose tenant matches the object key's {tenant_id}/... prefix; a mismatched or missing key returns 404 (never 403), so a leaked/guessed key can't be used to even confirm another tenant's attachment exists. The response is forced to download (Content-Disposition: attachment, X-Content-Type-Options: nosniff) and privately cached (5 minutes).
bearerAuthAuthorizationBearer <token>API key sent as Authorization: Bearer <key>. Looked up by SHA-256
hash (email_core::sha256_hex) against api_keys.hash; revoked
keys and keys belonging to a suspended tenant are rejected. See the
top-level Authentication section for permission levels.
key*stringThe full R2 object key, {tenant_id}/{message_id}/{filename} (as returned by POST /v1/attachments).
The attachment file.
response?fileapplication/octet-streambinarycurl -X GET "https://example.com/attachments/string""string"