/api/public/v1/vault-documents/{documentId}/downloadGet a download URL
A short-lived signed URL for a stored file. **The URL is the capability** — anyone holding it can fetch the file until it expires, so treat it as a secret and keep it out of logs. Ordinary files get five minutes; audio and video get an hour, because five minutes is not enough to watch a recording in one sitting. Downloading writes a DOWNLOAD audit event. That trail is the reason files live in the Vault rather than a bucket, so there is no way to fetch one without leaving a record.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
documentId | string | Required | Document ID. |
curl -X GET "https://www.pxb.app/api/public/v1/vault-documents/{documentId}/download" \
-H "Authorization: Bearer your_access_token"{
"message": "Download URL generated successfully!",
"content": {
"url": "https://storage.example/priv/…?token=…",
"expiresInSeconds": 300,
"fileName": "Q3 board pack.pdf",
"mimeType": "application/pdf",
"fileSize": 2418123
}
}{
"message": "File not found in storage."
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.