# Download one file the session was given

`GET /o/{org}/sessions/{session}/attachments/{id}`

The bytes of a file the session was started or followed up with, streamed, with its type,
`Content-Disposition: inline` and its filename. Send the key, or open the attachment's
`url` from the session read, which needs no key until `url_expires_at`. A wrong, expired or
altered link answers `404`, as a missing file does.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `org` | path | string | yes | The org's slug or id. A caller with no role in the org gets `404`. |
| `session` | path | string | yes | The session's full id (`execution_id`). |
| `id` | path | string | yes | An `id` from the session's `attachments`. |
| `expires` | query | integer | no | Part of a file's signed `url`; send it as given, with no key. |
| `signature` | query | string | no | Part of a file's signed `url`; send it as given, with no key. |

## Example request

```bash
curl "https://api.prix.dev/o/$RUSH_ORG/sessions/$SESSION_ID/attachments/$ID" \
  -H "Authorization: Bearer $RUSH_API_KEY"
```

```typescript
const org = process.env.RUSH_ORG;
const sessionId = process.env.SESSION_ID;
const id = process.env.ID;

const res = await fetch(`https://api.prix.dev/o/${org}/sessions/${sessionId}/attachments/${id}`, {
  headers: {
    Authorization: `Bearer ${process.env.RUSH_API_KEY}`,
  },
});

console.log(res.status, await res.text());
```

```python
import os

import requests

org = os.environ["RUSH_ORG"]
session_id = os.environ["SESSION_ID"]
id = os.environ["ID"]

res = requests.get(
    f"https://api.prix.dev/o/{org}/sessions/{session_id}/attachments/{id}",
    headers={"Authorization": f"Bearer {os.environ['RUSH_API_KEY']}"},
)

print(res.status_code, res.text)
```

## Responses

### 200

The file.


### 401

No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.

### 404

No such resource for the caller, including one that exists in an org the caller cannot see.

## Example response (200)

```json
"string"
```
