# Mint a view token for the caller's workspace

Returns a short-lived token that authenticates getAttachment, which cannot read an Authorization header because a browser sends none on an <img src>. The token carries the CALLER'S own reach — their active workspace and which of its teams they may read — and is never chosen by the client. One token covers every attachment they can already reach, so a page of markdown needs one call rather than one per image.

It grants nothing beyond what the caller could open through the issues and comments those files hang on: a team-scoped team's attachments stay unreachable to someone who is not on that team.

Append it to a stored attachment URL as `t` at render time. Attachment URLs are persisted inside issue and comment markdown, so they cannot themselves carry anything that expires; that is the whole reason the token is separate from the URL.

Valid for 5 minutes. Re-mint rather than caching past `expires` — an expired token is refused as a 404, indistinguishable from a missing file. 501 when the signer is not configured, which fails closed: no unsigned URL is ever served in its place.

Canonical: https://easerix.com/docs/developers/api/tasks/attachments/getAttachmentToken

{/* This file was generated by Fumadocs. Do not edit this file directly. Any changes should be made by running the generation command again. */}

export default function Layout(props) {
  const { APIPage, OpenAPIPage } = props.components ?? {};
  // "APIPage" is the old name from v10, this allows both for backward compatibility
  const Comp = OpenAPIPage ?? APIPage;
  return (
    <>
      {props.children}
      <Comp document="tasks" operations={[{"path":"/v1/attachments/token","method":"get"}]} />
    </>
  );
}
