Skip to content

Preview public file contents

GET
/api/v1/public/{slug}/preview
curl --request GET \
--url https://example.com/api/v1/public/example/preview
  • With the download permission, and downloads left, any file, with Range for media seeking.
  • Otherwise, with the view permission, only a note or text file up to [TEXT_PREVIEW_MAX], as text/plain. Photos get thumbnails, other files nothing: view-only never hands out original bytes.

The response is sandboxed through user_bytes (nosniff, a sandbox CSP, active types as text) because it is inline on the app’s origin: an uploaded HTML or SVG file opened directly must not run script as the app. Route: /api/v1/public/{slug}/preview. Inputs: slug, path, item, Range, If-None-Match, X-Public-Password. Safe reads can use bounded retries.

slug
required
string
path
string

A path relative to the shared folder. Refused on a link with hidden names.

item
string

An entry’s item ID from /entries, in place of path.

Range
string | null

One byte range

If-None-Match
string | null

Return 304 when this validator matches

X-Public-Password
string
Media typeapplication/octet-stream
Media typeapplication/octet-stream
Media typeapplication/json

The standard API error response: { "error": { ... } }.

object
error
required

Error details.

object
code
required

Stable machine-readable code.

string
Allowed values: bad_request unauthorized forbidden not_found conflict name_conflict_case name_too_long push_endpoint_rejected too_many_requests internal service_unavailable
details
One of:

Optional field or operation details.

object
key
additional properties
string
message
required

Safe text for logs or a user-facing error message.

string
Example
{
"error": {
"code": "bad_request"
}
}
Media typeapplication/json

The standard API error response: { "error": { ... } }.

object
error
required

Error details.

object
code
required

Stable machine-readable code.

string
Allowed values: bad_request unauthorized forbidden not_found conflict name_conflict_case name_too_long push_endpoint_rejected too_many_requests internal service_unavailable
details
One of:

Optional field or operation details.

object
key
additional properties
string
message
required

Safe text for logs or a user-facing error message.

string
Example
{
"error": {
"code": "bad_request"
}
}