Preview public file contents
GET
/api/v1/public/{slug}/preview
const url = 'https://example.com/api/v1/public/example/preview';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/public/example/preview- With the download permission, and downloads left, any file, with
Rangefor media seeking. - Otherwise, with the view permission, only a note or text file up to
[
TEXT_PREVIEW_MAX], astext/plain. Photos get thumbnails, other files nothing: view-only never hands out original bytes.
The response is sandboxed through user_bytes (nosniff, a sandbox CSP,
active types as text) because it is inline on the app’s origin: an
uploaded HTML or SVG file opened directly must not run script as the app.
Route: /api/v1/public/{slug}/preview. Inputs: slug, path, item, Range, If-None-Match, X-Public-Password. Safe reads can use bounded retries.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”slug
required
string
Query Parameters
Section titled “Query Parameters”path
string
A path relative to the shared folder. Refused on a link with hidden names.
item
string
An entry’s item ID from /entries, in place of path.
Header Parameters
Section titled “Header Parameters”Range
string | null
One byte range
If-None-Match
string | null
Return 304 when this validator matches
X-Public-Password
string
Responses
Section titled “Responses”Media typeapplication/octet-stream
Media typeapplication/octet-stream
Media typeapplication/json
The standard API error response: { "error": { ... } }.
object
Example
{ "error": { "code": "bad_request" }}Media typeapplication/json
The standard API error response: { "error": { ... } }.
object
Example
{ "error": { "code": "bad_request" }}