API REFERENCE
Beta
Download an Attachment
Returns the document’s raw bytes, not JSON — the one response on this surface that isn’t a JSON envelope. Reached by following links.download.src on an Attachment, never by constructing the URL yourself.
Genuinely read-only: authorizes the caller on every request, the same as every other endpoint on this surface, and has no side effects. Not a signed or expiring URL — it’s an ordinary authenticated endpoint, so it’s safe to store, but useless without your own bearer token.
Sample
url="https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/attachments/attchmnt_0000000000006099213/content"
curl -X GET "${url}" \
-H "Authorization: Bearer your_access_token_here" \
-o paystub-august.pdf
Header Properties
| Property | Value | Required? |
|---|---|---|
| Authorization | Bearer your token | true |
Path Parameters
| Property | Description | Type |
|---|---|---|
| workflowId | The opaque handle identifying the workflow. | string |
| findingId | The opaque finding identifier (fndg_…). | string |
| attachmentId | The opaque attachment identifier (attchmnt_…). Resolves only within the finding named in the path. | string |
workflowId is accepted with or without its wfpop_ prefix — a bare GUID resolves. findingId and attachmentId are not interchangeable this way: either must carry its exact prefix, or the request 404s as if that finding or attachment did not exist. There is no bare form of either that has ever been valid.
Responses
200
The document’s raw bytes.
| Header | Description |
|---|---|
| Content-Type | The document’s media type, as stored (or detected) from the upload — the same value published as Attachment.contentType. |
| Content-Disposition | attachment, naming the file — your HTTP client’s default download behavior applies. |
There is no JSON envelope on this response. Do not attempt to parse it as JSON, even on an error — see below.
403
You are not authorized to read this workflow.
Zero-length body, no Content-Type. Do not attempt to parse a body from this response — there is none. Branch on the status code alone.
This surface uses a bodyless 403 for every authorization failure, which is different from a problem+json 404 on the same operation. Do not assume every non-2xx on this API carries JSON — check the status first.
A 403 is also produced at the edge, before this service is reached, when a request value resembles SQL injection or cross-site scripting, and separately from the per-address rate limit (429). Both of those are also bodyless and carry no Content-Type.
404
Unknown workflowId, unknown findingId, unknown attachmentId, or an attachmentId that belongs to a different finding than the one named in the path.
An RFC 9457 problem document, served as application/problem+json.
| Property | Description | Type |
|---|---|---|
| type | An absolute URI identifying the problem type. https://pointservices.com/problems/not-found is the only type this surface emits. This is the stable value to match on. | string |
| title | A short summary, written for a person. | string |
| status | The HTTP status code, repeated in the body. | number |
| detail | An explanation of this occurrence, written for your logs — never a stable code. | string |
| instance | A URI identifying this occurrence, written as urn:pps:request:<id>. Quote it when you raise a support ticket. | string |
{
"type": "https://pointservices.com/problems/not-found",
"title": "No such resource",
"status": 404,
"detail": "No attachment attchmnt_0000000000006099213 is available to this request.",
"instance": "urn:pps:request:8d3a1f56-6c94-4e20-b7f8-0a5e9c2d4b73"
}
Branch on type, never on the text of detail.