Skip to main content

Get Approval Card File

GET 

/api/support/agent/approvals/:approval/files/:attachment

Streams one of the files attached to an approval card — a root-cause report, an HTML mockup, a screenshot, a PDF. Use the download_url on the card's evidence entry, or build the path from the card id and the entry's attachment_id.

Required scope: support:read

Grant this scope to your token under Settings → Developer → Personal Access Tokens.

The file is returned as raw bytes with its stored content type (one of the types allowed when the card was opened), not wrapped in JSON. Every response carries Content-Security-Policy: sandbox and X-Content-Type-Options: nosniff, so an HTML file can never run script with this site's privileges, and Content-Disposition: inline; filename="...". To preview HTML, load the text into a sandboxed frame; to show an image or PDF, read the response as a blob.

404 unless the attachment is named in this card's evidence — a card never gives access to any other file. Card files are internal: no customer endpoint serves them.

Path parameters

  • approval (integer) — the card id.
  • attachment (integer) — the file's attachment id.

Authentication: Bearer token with the support:read scope, or an authenticated session, from a caller with an active support role (any role, including viewer). No tenant context — this endpoint is central.

Request​

Responses​

OK

Response Headers
    Content-Type
    Content-Disposition
    Content-Security-Policy
    X-Content-Type-Options
    Cache-Control