# Open a file by redirecting to a freshly signed download URL.

`GET /o/{org}/files/{id}`

Readable by its uploader, or, once a run has bound it to a Project, by any member of the
org. The signed URL lasts 15 minutes and is minted per request. Do not send
`Authorization` to the redirect target: storage refuses a request that carries both a
signature and a bearer. `curl -L` drops it on a cross-host redirect; Python's `urllib`
forwards it, so follow the `Location` yourself there. Images (png, jpeg, gif,
webp), audio and PDF open inline; everything else is served as a download.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `org` | path | string | yes | The org's slug or id. A caller with no role in the org gets `404`. |
| `id` | path | string | yes | File id from `createFiles`. |
| `download` | query | string | no | `1` signs the URL as a download even for an inline-safe type. |

## Example request

```bash
curl "https://api.prix.dev/o/$RUSH_ORG/files/$ID" \
  -H "Authorization: Bearer $RUSH_TOKEN"
```

```typescript
const org = process.env.RUSH_ORG;
const id = process.env.ID;

const res = await fetch(`https://api.prix.dev/o/${org}/files/${id}`, {
  headers: {
    Authorization: `Bearer ${process.env.RUSH_TOKEN}`,
  },
});

console.log(res.status, await res.text());
```

```python
import os

import requests

org = os.environ["RUSH_ORG"]
id = os.environ["ID"]

res = requests.get(
    f"https://api.prix.dev/o/{org}/files/{id}",
    headers={"Authorization": f"Bearer {os.environ['RUSH_TOKEN']}"},
)

print(res.status_code, res.text)
```

## Responses

### 302

Redirect to the signed object URL.

### 401

No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.

### 404

No such attachment, or the caller may not read it (same answer).

### 409

The upload has not finished (`ATTACHMENT_NOT_UPLOADED`).

### 410

The stored bytes have expired (`ATTACHMENT_EXPIRED`).

### 500

Opening the attachment failed.

## Example response (302)

```http
HTTP 302 Redirect to the signed object URL.
```
