---
title: List attachments
openapi: /openapi/mailfully.yaml GET /v1/emails/receiving/{id}/attachments
---

> **For AI agents:** the complete documentation index is at [llms.txt](/docs/llms.txt). Append `.md` to any page URL for its markdown version.

`GET https://api.mailfully.com/v1/emails/receiving/{id}/attachments`

List every attachment on one received email, in the order it was stored, each with a download link. A link lasts at most one hour; `expires_at` is the exact time it stops working and can be sooner. The link saves the file under its original filename. For an email whose `virus` verdict is `FAIL`, no files were stored, so `download_url` and `expires_at` are `null`. Returns the same `403 email_above_quota` and `404` as the email itself. Not paginated. Requires the `read:inbound` scope.

## Authentication

- `apiKey` — http bearer

## Path parameters

- `id` (string, required) — The received email id (`inb_` followed by a 26-character ULID).

## Response 200

The email's attachments.
  - response (object)
    - `data` (array, required)
      - `items`
        - (allOf)
          - value (object)
            - id: … (nested further)
            - filename: … (nested further)
            - content_type: … (nested further)
            - content_disposition: … (nested further)
            - content_id: … (nested further)
            - size: … (nested further)
          - value (object)
            - download_url: … (nested further)
            - expires_at: … (nested further)

## Response 401

Authentication failed.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 403

The credential lacks the scope, or the email is locked over quota.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 404

The requested resource was not found.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.

## Response 500

An unexpected error occurred.
  - response (object)
    - `error` (object, required)
      - `type` (string, required) — Machine-readable error code.
      - `message` (string, required) — Human-readable error message.
      - `param` (string) — The offending field; present only on validation errors.


---

📦 **OpenAPI specs:** Every OpenAPI specification referenced by this documentation is available as a single download — https://mailfully.com/docs/api-specs.zip
