# List attachments

GET /{type}/{id}/attachments. Parameters, permissions, request and response schemas.

`GET /{type}/{id}/attachments`

List attachments. Requires the REST `read` token ability. The bearer token selects the Team; a supplied team\_id cannot switch tenants. Additional role, entity-policy and plan requirements vary by operation.

## Authentication

Use a team API key as `Authorization: Bearer YOUR_API_KEY`. The token ability and the user’s role must both allow this operation. See [authentication](https://conversionlab.app/docs/developer/authentication).

```json
{
  "ability": "read",
  "team": "Token-bound Team",
  "authorization": "Additional role, entity-policy and plan requirements vary by operation."
}
```

## Parameters

| Name   | Location | Required | Description |
| ------ | -------- | -------- | ----------- |
| `type` | path     | Yes      | Type.       |
| `id`   | path     | Yes      | Id.         |

### type

```json
{
  "type": "string",
  "enum": [
    "experiments",
    "ideas",
    "insights",
    "variations"
  ]
}
```

### id

```json
{
  "type": "integer",
  "minimum": 1
}
```

## Example request

```bash
curl --request GET 'https://api.example.test/api/experiments/101/attachments' \
  --header 'Authorization: Bearer YOUR_API_KEY' \
  --header 'Accept: application/json'
```

Examples use fictional data. Replace resource IDs and the API host with your environment’s values.

## Responses

### 200

Array of `AttachmentResource`

Content type: `application/json`.

```json
{
  "type": "object",
  "properties": {
    "data": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "integer"
          },
          "project_id": {
            "type": "integer"
          },
          "name": {
            "type": [
              "string",
              "null"
            ]
          },
          "file_type": {
            "type": [
              "string",
              "null"
            ]
          },
          "file_size": {
            "type": [
              "integer",
              "null"
            ]
          },
          "type": {
            "type": "string",
            "enum": [
              "image",
              "document",
              "link"
            ],
            "title": "AttachmentType"
          },
          "url": {
            "type": [
              "string",
              "null"
            ]
          },
          "attachable_type": {
            "type": "string"
          },
          "attachable_id": {
            "type": "integer"
          },
          "created_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          },
          "updated_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "project_id",
          "name",
          "file_type",
          "file_size",
          "type",
          "url",
          "attachable_type",
          "attachable_id",
          "created_at",
          "updated_at"
        ],
        "title": "AttachmentResource"
      }
    }
  },
  "required": [
    "data"
  ]
}
```

```json
{
  "data": [
    {
      "id": 101,
      "project_id": 101,
      "name": null,
      "file_type": null,
      "file_size": null,
      "type": "image",
      "url": null,
      "attachable_type": "example",
      "attachable_id": 101,
      "created_at": null,
      "updated_at": null
    }
  ]
}
```

### 401

Unauthenticated

Content type: `application/json`.

```json
{
  "type": "object",
  "properties": {
    "message": {
      "type": "string",
      "description": "Error overview."
    }
  },
  "required": [
    "message"
  ]
}
```

```json
{
  "message": "The request could not be completed."
}
```

### 403

Authorization error

Content type: `application/json`.

```json
{
  "type": "object",
  "properties": {
    "message": {
      "type": "string",
      "description": "Error overview."
    }
  },
  "required": [
    "message"
  ]
}
```

```json
{
  "message": "The request could not be completed."
}
```

### 429

Rate limit exceeded. Honor Retry-After before retrying.

Response headers:

```json
{
  "Retry-After": {
    "description": "Seconds before retrying.",
    "schema": {
      "type": "integer"
    }
  }
}
```

Content type: `application/json`.

```json
{
  "type": "object",
  "properties": {
    "message": {
      "type": "string",
      "example": "Too Many Attempts."
    }
  },
  "required": [
    "message"
  ]
}
```

```json
{
  "message": "Too Many Attempts."
}
```

See [API conventions](https://conversionlab.app/docs/developer/api-conventions) for error handling, rate limits, pagination, and uploads.
