# Download a received attachment

GET /v1/messages/{message_id}/attachments/{attachment_id}

Source: https://cherami.to/docs/api/messages/download-attachment



{/* Generated from apps/web/openapi. Edit the contract, not this file. */}

`GET /v1/messages/{message_id}/attachments/{attachment_id}`

Requires a [Claim-issued API key](https://cherami.to/docs/api#authentication): `Authorization: Bearer YOUR_CREDENTIAL`.

Returns `200` with file bytes, `Content-Type: application/octet-stream`, and attachment disposition. Use the ID returned in ready content, not a guessed filename. An unavailable attachment or a message that is not ready returns `404`; missing stored content can return `503`.

Downloads use `no-store`, `nosniff`, and a sandbox content security policy. Reported filenames and MIME metadata do not establish that files are safe to execute or render.

## Parameters [#parameters]

| Parameter       | Location | Required | Type   | Meaning                                               |
| --------------- | -------- | -------- | ------ | ----------------------------------------------------- |
| `message_id`    | path     | Yes      | string | Owned Cherami resource ID returned by the API.        |
| `attachment_id` | path     | Yes      | string | ID from received attachment metadata, not a filename. |

## curl example [#curl-example]

Replace resource-ID placeholders with returned IDs. Supply `CHERAMI_API_KEY` through your private shell environment.

```sh
curl --silent --show-error --dump-header response-headers.txt --request GET \
  "https://cherami.to/v1/messages/MESSAGE_ID/attachments/ATTACHMENT_ID" \
  --header "Authorization: Bearer $CHERAMI_API_KEY" \
  --output download.bin
```

## Responses [#responses]

### HTTP 200 [#http-200]

Original bytes, served as a download.

* `X-Request-ID`: Support correlation ID, not an idempotency key.
* `Content-Disposition`: Attachment disposition with a safely encoded suggested filename.
* `Content-Length`: Original byte count.
* `Cache-Control`: Includes no-store.
* `X-Content-Type-Options`: `"nosniff"`
* `Content-Security-Policy`: Sandbox with default-src 'none'.

Content type: `application/octet-stream`.

Binary response body, not a JSON string. Save the original bytes.

### HTTP 401 [#http-401]

`unauthorized`: Provide a valid bearer credential. Use [human-approved recovery](https://cherami.to/docs/guides/recovery) if access is lost.

* `X-Request-ID`: Support correlation ID, not an idempotency key.
* `WWW-Authenticate`: `"Bearer"`

Content type: `application/json`.

[Error](#schema-error)

### HTTP 404 [#http-404]

`not_found`: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.

* `X-Request-ID`: Support correlation ID, not an idempotency key.

Content type: `application/json`.

[Error](#schema-error)

### HTTP 500 [#http-500]

`internal_error`: Operation failed; a write may already have happened. Follow the operation-specific recovery below.

* `X-Request-ID`: Support correlation ID, not an idempotency key.

Content type: `application/json`.

[Error](#schema-error)

### HTTP 503 [#http-503]

`content_unavailable`: Expected stored content is unavailable. Retry the read later.

* `X-Request-ID`: Support correlation ID, not an idempotency key.

Content type: `application/json`.

[Error](#schema-error)

## Schema: Error [#schema-error]

| Field   | Required | Type   | Meaning and constraints |
| ------- | -------- | ------ | ----------------------- |
| `error` | Yes      | object |                         |

### `error` fields [#error-fields]

| Field     | Required | Type   | Meaning and constraints                                                                       |
| --------- | -------- | ------ | --------------------------------------------------------------------------------------------- |
| `code`    | Yes      | string | Programmatic error code. Handle unrecognized codes by status and operation-specific recovery. |
| `message` | Yes      | string | Human-readable context, not a stable string to match.                                         |

[HTTP conventions, errors and pagination](https://cherami.to/docs/api/errors) · [Download OpenAPI 3.1](https://cherami.to/openapi.json)
