---
title: Retrieve an attachment
openapi: /openapi/mailfully.yaml GET /v1/emails/receiving/{id}/attachments/{attachment_id}
---

> **For AI agents:** the complete documentation index is at [llms.txt](/docs/llms.txt). Append `.md` to any page URL for its markdown version.

`GET https://api.mailfully.com/v1/emails/receiving/{id}/attachments/{attachment_id}`

Retrieve one attachment on a received email, with a download link that lasts at most one hour (`expires_at` is exact). An unknown attachment id returns `404`. Requires the `read:inbound` scope.

## Authentication

- `apiKey` — http bearer

## Path parameters

- `id` (string, required) — The received email id (`inb_` followed by a 26-character ULID).
- `attachment_id` (string, required) — The attachment id (`att_` followed by a 26-character ULID).

## Response 200

The attachment.
  - response
    - (allOf)
      - value (object)
        - `id` (string, required) — The attachment id (`att_…`).
        - `filename` (string, required)
        - `content_type` (string, required)
        - `content_disposition` (string, required) — Usually `attachment` or `inline`.
        - `content_id` (string, required) — The `Content-ID` that `cid:` links in `html` refer to.
        - `size` (integer, required) — Size in bytes.
      - value (object)
        - `download_url` (string, required) — A link to the file, valid until `expires_at`. `null` when the email's `virus` verdict is `FAIL`.
        - `expires_at` (string, date-time, required) — When `download_url` stops working, at most one hour after the request.

## Response 401

Authentication failed.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 403

The credential lacks the scope, or the email is locked over quota.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 404

The requested resource was not found.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 500

An unexpected error occurred.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.


---

📦 **OpenAPI specs:** Every OpenAPI specification referenced by this documentation is available as a single download — https://mailfully.com/docs/api-specs.zip
