Skip to main content
GET
Download a tenant-authorized private attachment

Authorizations

Authorization
string
header
required

A Contact Button scoped bearer key. Send Authorization: Bearer <token>. Token abilities are enforced independently of workspace membership; both checks must pass. Interactive MCP clients use registered OAuth applications, Authorization Code + PKCE, audience-bound tokens, and explicit workspace grants. Personal Sanctum tokens remain supported.

Path Parameters

workspace
string<uuid>
required
attachment
string<uuid>
required

Query Parameters

inline
boolean
default:false

Response

200 - application/octet-stream

Attachment content.

The response is of type file.