Get Approval Card File
GET/api/support/agent/approvals/:approval/files/:attachment
Streams one of the files attached to an approval card — a root-cause report, an HTML mockup, a screenshot, a PDF. Use the download_url on the card's evidence entry, or build the path from the card id and the entry's attachment_id.
support:readGrant this scope to your token under Settings → Developer → Personal Access Tokens.
The file is returned as raw bytes with its stored content type (one of the types allowed when the card was opened), not wrapped in JSON. Every response carries Content-Security-Policy: sandbox and X-Content-Type-Options: nosniff, so an HTML file can never run script with this site's privileges, and Content-Disposition: inline; filename="...". To preview HTML, load the text into a sandboxed frame; to show an image or PDF, read the response as a blob.
404 unless the attachment is named in this card's evidence — a card never gives access to any other file. Card files are internal: no customer endpoint serves them.
Path parameters
approval(integer) — the card id.attachment(integer) — the file's attachment id.
Authentication: Bearer token with the support:read scope, or an authenticated session, from a caller with an active support role (any role, including viewer). No tenant context — this endpoint is central.
Request
Responses
- 200
- 401
- 403
- 404
- 429
OK
Response Headers
Unauthorized
Response Headers
Forbidden
Response Headers
Not Found
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.