Skip to content

Serve the authorized indexed renderer with access-checked, private no-store thumbnail bytes.

GET
/api/v1/files/thumb/{hash}
curl --request GET \
--url 'https://example.com/api/v1/files/thumb/example?s=1&kind=media&v=2' \
--header 'Authorization: Bearer <token>'

Route: /api/v1/files/thumb/{hash}. Inputs: hash, s, kind, v. Safe reads can use bounded retries.

hash
required
string
s
required
integer format: int32
kind

Public names for the renderer families carried by Files thumbnail URLs.

string
Allowed values: media pdf text-card

Renderer family. Omission keeps existing media URLs valid.

v
integer format: int32
>= 1 <= 2

Legacy v=1 and current v=2 URL identities are accepted; private thumbnail bytes are never cached.

Example
2
Media typeimage/webp
Media typeapplication/json

The standard API error response: { "error": { ... } }.

object
error
required

Error details.

object
code
required

Stable machine-readable code.

string
Allowed values: bad_request unauthorized forbidden not_found conflict name_conflict_case name_too_long push_endpoint_rejected too_many_requests internal service_unavailable
details
One of:

Optional field or operation details.

object
key
additional properties
string
message
required

Safe text for logs or a user-facing error message.

string
Example
{
"error": {
"code": "bad_request"
}
}