Stream an attachment's bytes (members)
For an attachment on a page the caller can see, streams the file itself (Content-Disposition attachment). Exports use it to bundle images, since a browser cannot read the cross-origin storage redirect.
View as MarkdownAuthorization
bearer In: header
Path Parameters
uuidResponse Body
application/octet-stream
application/json
curl -X GET "https://example.com/v1/attachments/497f6eca-6276-4993-bfeb-53cbbbba6f08/content"Fetch an attachment (capability-checked presigned redirect)
Redirects (302) to a presigned R2 URL valid for 10 minutes, for a caller holding one of: a valid exp+sig from signAttachmentUrl (how <img> tags load it), a live share token for the attachment's page (share), or a bearer that can see the page. Anything else is 404, so an attachment id alone opens nothing.
Mint a short-lived signed URL for an attachment
For an attachment on a page the caller can see, returns a URL to getAttachment carrying exp and sig, valid for 10 minutes, so an <img> (which cannot send a bearer) can load it. 404 for anything the caller cannot see.