Download File
A signed download URL for the file’s bytes — the internal download endpoint’s exact path.
Same access rule and response shape as the app’s GET /files/{id}/download
(FileService.get_file access check, then a presigned storage URL): no
bytes traverse this API. The URL is time-limited (typically valid for at
least 24 hours) — re-request rather than persisting it. Requires the
files:read scope: file bytes are content, not workspace enumeration,
so canvases:read alone deliberately does not grant them.
Authorizations
API key from Settings > Developer > REST API
Headers
Calendar-dated API version pin. New integrations should pin 2026-05-01 to opt into the newest response shapes. For back-compat the server also accepts requests with no header and resolves them to the current default (today: 2026-04-12); that default advances on each sunset date. Any unsupported value returns 400 unsupported_version.
2026-04-12, 2026-05-01 "2026-05-01"
Path Parameters
Prefixed file_ wire ID (Crockford base32 body) — the canonical, recommended form. For back-compat, a bare UUID string is also accepted in both path parameters and JSON request bodies (older integrations that stored raw UUIDs keep working). Both are permanent, supported inputs.
^file_[0-9A-HJKMNP-TV-Za-hjkmnp-tv-z]{26}$"file_01HT9WK8N3M2J4A5Z6P7Q8R9TV"
Response
Successful Response
The response is of type Response Drivedownloadfile · object.