Portal: Download Document
GET/api/walmart/:integrationInstance/wfs/inbound-shipments/fulfillment-portal/:token/documents/:document/download
Download one of the packet's staged documents by id. Records a 'downloaded' portal event, then streams the document as a file attachment (not JSON):
- receiving_label → the live WFS receiving label fetched from Walmart as a PDF (Content-Type: application/pdf, Content-Disposition: attachment; filename="wfs-receiving-label-<shipment_id>.pdf").
- carrier_label → the live WFS carrier / pickup label fetched from Walmart as a PDF (Content-Type: application/pdf, Content-Disposition: attachment; filename="wfs-carrier-label-<shipment_id>.pdf"). Only present when a preferred carrier is booked on the shipment.
- instructions / work_order → rendered on demand as a plain-text attachment (Content-Type: text/plain; charset=UTF-8, filename="<type>-<packet_id>.txt").
Any valid API token can call this endpoint — no specific scope required. Manage tokens.
Public, token-gated endpoint — no bearer auth. The {token} in the path gates packet access; tenant is resolved by host.
Errors:
- 404 (text 'This portal link is no longer valid.') when the token is invalid/expired/revoked or the document does not belong to this packet.
- 422 (text 'This document is not yet available.') when the document status is not downloadable.
- 422 (text 'The receiving label could not be retrieved from Walmart right now.') when the live label fetch fails.
- 422 (text 'The carrier label could not be retrieved from Walmart right now.') when the live carrier-label fetch fails.
- 422 (text 'This document is prepared elsewhere and will be attached when ready.') for a file-backed type (e.g. po/asn) with no rendered content.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.