# List the attachments a session was dispatched with.

`GET /o/{org}/p/{project}/sessions/{session}/attachments`

Authorized through the session, like its other sub-resources. Expired files are listed with `expired_at` set.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `org` | path | string | yes | The org's slug or id. A caller with no role in the org gets `404`. |
| `project` | path | string | yes | A Project's handle (name) or id, resolved inside `{org}` — OR the reserved sentinel `_` meaning "no Project" (a direct-repo / repo-less dispatch on `POST`; "no Project constraint, resolve by session id alone" everywhere else). A real handle that doesn't match the session's actual Project is `404`.  |
| `session` | path | string | yes | The session's full id (`execution_id`). |

## Example request

```bash
curl "https://api.prix.dev/o/$RUSH_ORG/p/_/sessions/$SESSION_ID/attachments" \
  -H "Authorization: Bearer $RUSH_API_KEY"
```

```typescript
const org = process.env.RUSH_ORG;
const sessionId = process.env.SESSION_ID;

const res = await fetch(`https://api.prix.dev/o/${org}/p/_/sessions/${sessionId}/attachments`, {
  headers: {
    Authorization: `Bearer ${process.env.RUSH_API_KEY}`,
  },
});

console.log(res.status, await res.json());
```

```python
import os

import requests

org = os.environ["RUSH_ORG"]
session_id = os.environ["SESSION_ID"]

res = requests.get(
    f"https://api.prix.dev/o/{org}/p/_/sessions/{session_id}/attachments",
    headers={"Authorization": f"Bearer {os.environ['RUSH_API_KEY']}"},
)

print(res.status_code, res.json())
```

## Responses

### 200

The session's attachments.

- `attachments` (array of Attachment, required)
  - `id` (string, required)
  - `name` (string, required)
  - `mime` (string, required): Media type essence (`type/subtype`).
  - `size` (integer, required): Bytes.
  - `created_at` (string, required)
  - `run_id` (string | null, required): The session it was dispatched with; null until bound.
  - `expired_at` (string | null, required): Non-null means the bytes are gone.

### 401

No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.

### 404

No such resource for the caller, including one that exists in an org the caller cannot see.

### 500

Listing failed.

## Example response (200)

```json
{
  "attachments": [
    {
      "id": "3f6c1e2a-8b4d-4c1e-9a7f-2d5b6e8c0a14",
      "name": "string",
      "mime": "string",
      "size": 0,
      "created_at": "2026-10-06T12:00:00Z",
      "run_id": "string",
      "expired_at": "2026-10-06T12:00:00Z"
    }
  ]
}
```
