Readable by its uploader, or, once a run has bound it to a Project, by any member of the
org. The signed URL lasts 15 minutes and is minted per request. Do not send
Authorization to the redirect target: storage refuses a request that carries both a
signature and a bearer. curl -L drops it on a cross-host redirect; Python's urllib
forwards it, so follow the Location yourself there. Images (png, jpeg, gif,
webp), audio and PDF open inline; everything else is served as a download.
Authenticate with a signed-in session token (an API key cannot call this route).
Path parameters
The org's slug or id. A caller with no role in the org gets 404.
File id from createFiles.
Query parameters
1 signs the URL as a download even for an inline-safe type.
1Responses
302Redirect to the signed object URL.
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
404No such attachment, or the caller may not read it (same answer).
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
409The upload has not finished (ATTACHMENT_NOT_UPLOADED).
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
410The stored bytes have expired (ATTACHMENT_EXPIRED).
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
500Opening the attachment failed.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.