Download a received attachment
GET /v1/messages/{message_id}/attachments/{attachment_id}
Read as Markdown ↗GET /v1/messages/{message_id}/attachments/{attachment_id}
Requires a Claim-issued API key: Authorization: Bearer YOUR_CREDENTIAL.
Returns 200 with file bytes, Content-Type: application/octet-stream, and attachment disposition. Use the ID returned in ready content, not a guessed filename. An unavailable attachment or a message that is not ready returns 404; missing stored content can return 503.
Downloads use no-store, nosniff, and a sandbox content security policy. Reported filenames and MIME metadata do not establish that files are safe to execute or render.
Parameters
| Parameter | Location | Required | Type | Meaning |
|---|---|---|---|---|
message_id | path | Yes | string | Owned Cherami resource ID returned by the API. |
attachment_id | path | Yes | string | ID from received attachment metadata, not a filename. |
curl example
Replace resource-ID placeholders with returned IDs. Supply CHERAMI_API_KEY through your private shell environment.
curl --silent --show-error --dump-header response-headers.txt --request GET \
"https://cherami.to/v1/messages/MESSAGE_ID/attachments/ATTACHMENT_ID" \
--header "Authorization: Bearer $CHERAMI_API_KEY" \
--output download.binResponses
HTTP 200
Original bytes, served as a download.
X-Request-ID: Support correlation ID, not an idempotency key.Content-Disposition: Attachment disposition with a safely encoded suggested filename.Content-Length: Original byte count.Cache-Control: Includes no-store.X-Content-Type-Options:"nosniff"Content-Security-Policy: Sandbox with default-src 'none'.
Content type: application/octet-stream.
Binary response body, not a JSON string. Save the original bytes.
HTTP 401
unauthorized: Provide a valid bearer credential. Use human-approved recovery if access is lost.
X-Request-ID: Support correlation ID, not an idempotency key.WWW-Authenticate:"Bearer"
Content type: application/json.
HTTP 404
not_found: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
HTTP 500
internal_error: Operation failed; a write may already have happened. Follow the operation-specific recovery below.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
HTTP 503
content_unavailable: Expected stored content is unavailable. Retry the read later.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
Schema: Error
| Field | Required | Type | Meaning and constraints |
|---|---|---|---|
error | Yes | object |
error fields
| Field | Required | Type | Meaning and constraints |
|---|---|---|---|
code | Yes | string | Programmatic error code. Handle unrecognized codes by status and operation-specific recovery. |
message | Yes | string | Human-readable context, not a stable string to match. |
HTTP conventions, errors and pagination · Download OpenAPI 3.1