List files
List the files visible to the caller in the current space. Requires the files:read permission (the family gate — mirrors runs:read); on top of it, each row is filtered by its own container ACL, so a member sees the files of the runs it may read (the whole space with runs:read-all, otherwise the runs it launched) plus its own chat and container-less files, and end-users see only their own. Filter by purpose, runId, packageId, chat_session_id, or a chat session's complete context; paginate with startingAfter + limit. An unknown query parameter or an invalid purpose is rejected with 400.
/api/filesCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Query Parameters
Filter by file purpose.
"user_upload" | "agent_output"Filter to files anchored to this run.
Filter to files produced by this agent package.
Filter to files anchored to this chat session.
Filter to the private conversation context: direct attachments plus files produced or consumed by runs launched from the session.
Keyset cursor — file id to page after (newest-first order).
Page size (1–100, default 20).
201 <= value <= 100Header Parameters
Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).
uuidSpace ID. Required for space-scoped routes (agents, runs, schedules, and space-scoped module routes). Not needed for API key auth (space resolved from key).
curl -X GET "https://your-instance/api/files"{
"object": "list",
"data": [
{
"object": "file",
"id": "string",
"uri": "string",
"purpose": "user_upload",
"spaceId": "string",
"runId": "string",
"chat_session_id": "string",
"packageId": "string",
"name": "string",
"mime": "string",
"size": 0,
"sha256": "string",
"downloadable": true,
"capabilities": {
"visible": true,
"metadata": true,
"download": true,
"preview": true,
"keep": true,
"delete": true
},
"previewable": true,
"preview_kind": "html",
"expiresAt": "2019-08-24T14:15:22Z",
"createdAt": "2019-08-24T14:15:22Z"
}
],
"hasMore": true,
"limit": 0
}{
"type": "https://docs.appstrate.dev/errors/validation-failed",
"title": "Validation Failed",
"status": 400,
"detail": "name: Invalid input: expected string, received undefined (+2 more)",
"code": "validation_failed",
"request_id": "req_abc123",
"errors": [
{
"field": "name",
"code": "required",
"message": "Invalid input: expected string, received undefined"
},
{
"field": "email",
"code": "invalid_format",
"message": "Invalid email address"
},
{
"field": "age",
"code": "invalid_type",
"message": "Invalid input: expected number, received string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/rate-limited",
"title": "Rate Limited",
"status": 429,
"detail": "Too many requests. Please try again shortly.",
"code": "rate_limited",
"request_id": "req_abc123",
"retry_after": 30
}