EaserixDocs
DevelopersAPI referenceTasksAttachments

Delete an attachment and its stored file

Authenticated and org-scoped, unlike the GET above: holding the link must not be enough to destroy the file. Removes the object from storage inline, because presigned URLs already issued stay valid for their full 60 seconds and only the object going away revokes them. Reach follows the parent — the attachment's issue, or its comment's issue — so an attachment outside the caller's workspace answers 404, never 403. So does one already deleted, which makes a repeated delete idempotent, and one whose parent is already gone: there is no workspace left to authorize it, and a background sweeper reclaims those. 200 even when storage refuses the delete: the attachment has left every view the caller can see, and the row stays marked so the sweeper finishes the file. 501 when storage is not configured, since marking the row would hide the only record of a file that could never be removed.

View as Markdown
DELETE
/v1/attachments/{id}
AuthorizationBearer <token>

In: header

Path Parameters

id*string
Formatuuid

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X DELETE "https://example.com/v1/attachments/497f6eca-6276-4993-bfeb-53cbbbba6f08"
{  "message": "string"}

Fetch an attachment (presigned redirect, token-authenticated)

302-redirects to a presigned R2 URL valid for 60 seconds. Registered outside the authenticated group because an <img src> cannot send a bearer header — but NOT open. The caller must present a `t` view token from getAttachmentToken whose scope reaches the file: the same workspace, and either an org-wide team or one the bearer belongs to. The attachment's owner is found through its parent: its issue, or the issue its comment sits on. A bearer token is NOT an alternative here, and sending one has no effect: this route runs outside the authentication middleware, so there are no verified claims for it to read. An API caller fetches a view token first and appends it — one way in, verified in one place. Everything else is a 404, never a 403 — a wrong workspace, another team's file, an expired or forged token, no credentials at all, a deleted attachment, and an orphan whose parent is gone all answer identically, so the response never confirms that an id names a real file somewhere. 501 when storage is not configured. Limited per caller IP (EAS-77): a caller that sends too many requests gets 429 with a Retry-After header. The limit is generous, sized for a page that loads every image on an issue at once. If the rate-limit store is unavailable the request is served without a limit.

List labels

Labels across the org's teams, ordered by name. Filter with team_id. Each carries issueCount, the number of non-deleted issues that still have it, so a caller can weigh a delete before making one.