cherami.
API referenceReceived messages

Download a received attachment

GET /v1/messages/{message_id}/attachments/{attachment_id}

Read as Markdown ↗

GET /v1/messages/{message_id}/attachments/{attachment_id}

Requires a Claim-issued API key: Authorization: Bearer YOUR_CREDENTIAL.

Returns 200 with file bytes, Content-Type: application/octet-stream, and attachment disposition. Use the ID returned in ready content, not a guessed filename. An unavailable attachment or a message that is not ready returns 404; missing stored content can return 503.

Downloads use no-store, nosniff, and a sandbox content security policy. Reported filenames and MIME metadata do not establish that files are safe to execute or render.

Parameters

ParameterLocationRequiredTypeMeaning
message_idpathYesstringOwned Cherami resource ID returned by the API.
attachment_idpathYesstringID from received attachment metadata, not a filename.

curl example

Replace resource-ID placeholders with returned IDs. Supply CHERAMI_API_KEY through your private shell environment.

curl --silent --show-error --dump-header response-headers.txt --request GET \
  "https://cherami.to/v1/messages/MESSAGE_ID/attachments/ATTACHMENT_ID" \
  --header "Authorization: Bearer $CHERAMI_API_KEY" \
  --output download.bin

Responses

HTTP 200

Original bytes, served as a download.

  • X-Request-ID: Support correlation ID, not an idempotency key.
  • Content-Disposition: Attachment disposition with a safely encoded suggested filename.
  • Content-Length: Original byte count.
  • Cache-Control: Includes no-store.
  • X-Content-Type-Options: "nosniff"
  • Content-Security-Policy: Sandbox with default-src 'none'.

Content type: application/octet-stream.

Binary response body, not a JSON string. Save the original bytes.

HTTP 401

unauthorized: Provide a valid bearer credential. Use human-approved recovery if access is lost.

  • X-Request-ID: Support correlation ID, not an idempotency key.
  • WWW-Authenticate: "Bearer"

Content type: application/json.

Error

HTTP 404

not_found: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

HTTP 500

internal_error: Operation failed; a write may already have happened. Follow the operation-specific recovery below.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

HTTP 503

content_unavailable: Expected stored content is unavailable. Retry the read later.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

Schema: Error

FieldRequiredTypeMeaning and constraints
errorYesobject

error fields

FieldRequiredTypeMeaning and constraints
codeYesstringProgrammatic error code. Handle unrecognized codes by status and operation-specific recovery.
messageYesstringHuman-readable context, not a stable string to match.

HTTP conventions, errors and pagination · Download OpenAPI 3.1

On this page