Skip to content

Files

Download a message’s file

Every message with a file has a media_url such as /api/media/<workspace>/<file>, for files you received and files you sent. Request https://whatsappx.si + media_url with Authorization: Bearer <key> to download the file; a read key is enough. The media_url of an uploaded file (upload.…) works the same way.

GET/api/media/{workspace}/{file}
  • Bearer API key
  • Scope: read, write or admin
  • or app session

Path parameters

  • workspaceuuidrequired

    Workspace id, as it appears in the media_url. It must be your key’s workspace.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30
  • filestringrequired

    Stored file name, as it appears in the media_url.

    Example
    3EB0C4D5E6F708192A3B.pdf

Headers

  • Authorizationstringrequired

    Your API key as Bearer <key>. The word Bearer and the space are case-sensitive. Browser clients signed in to the app use the session cookie instead. No X-Tenant-ID is needed: the workspace is in the path.

    Constraints
    Keys start with pk_live_ and are 56 characters long.
    Example
    Bearer pk_live_…
  • Rangestringoptional

    Optional byte range, for example bytes=0-1048575, to download part of the file. The answer is then 206 Partial Content.

Response

Status codes

  • 200OK. The file. Images (JPEG, PNG, GIF, WebP), audio and video come with their own Content-Type, to show inline. Every other file (PDFs, office documents, anything else) comes as application/octet-stream with Content-Disposition: attachment and the message’s original file_name (for an upload, its file_name).
  • 206Partial content. The requested part of the file, when you send a Range header.
  • 401Unauthorized. The API key is unknown, revoked or expired (invalid or expired API key), or there is no key and no signed-in session (unauthorized).
  • 404Not found. The file does not exist, the path is malformed, or the workspace in the path is not your key’s workspace. A file of another workspace always answers 404, so the answer never reveals whether it exists.

Where do I find the media_url?

On each message with a file: in List messages, in the response of Send files, in the webhook payload of an incoming message and in message.created live events. An uploaded file has one too (Get an uploaded file).

Is the download recorded?

Downloads made with an API key are recorded in the audit log as file.downloaded, with the resource media and the stored file name as its id.

-OJ makes cURL save the file under the name the server sends. Profile pictures (avatar_url of a conversation) use /api/avatars/<workspace>/<file> the same way.