API referenceAttachments

Download an attachment

GET
/attachments/{key}

Not under /v1 — a tenant-scoped convenience endpoint, not a public CDN. Requires an API key whose tenant matches the object key's {tenant_id}/... prefix; a mismatched or missing key returns 404 (never 403), so a leaked/guessed key can't be used to even confirm another tenant's attachment exists. The response is forced to download (Content-Disposition: attachment, X-Content-Type-Options: nosniff) and privately cached (5 minutes).

Authorization

bearerAuth
headerAuthorizationBearer <token>

API key sent as Authorization: Bearer <key>. Looked up by SHA-256 hash (email_core::sha256_hex) against api_keys.hash; revoked keys and keys belonging to a suspended tenant are rejected. See the top-level Authentication section for permission levels.

Path Parameters

key*string

The full R2 object key, {tenant_id}/{message_id}/{filename} (as returned by POST /v1/attachments).

Response Body

The attachment file.

response?fileapplication/octet-stream
Formatbinary
curl -X GET "https://example.com/attachments/string"
"string"