> ## Documentation Index
> Fetch the complete documentation index at: https://www.rootset.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Download artifact bytes

> Stream verified artifact bytes under current artifact-purpose and target authority.



## OpenAPI

````yaml api-reference/openapi.json GET /v1/orgs/{orgId}/artifacts/{id}/download
openapi: 3.1.2
info:
  title: Rootset public API
  version: 0.1.0
  description: >-
    Typed MDM storage. Temporal values are UTC only; IDs are opaque ULIDs.
    Runtime table definitions are discovered through the schema endpoint.
servers:
  - url: http://localhost:4310
security: []
paths:
  /v1/orgs/{orgId}/artifacts/{id}/download:
    get:
      tags:
        - artifacts
      summary: >-
        Stream verified artifact bytes under current artifact-purpose and target
        authority.
      description: >-
        Use the authenticated download URL returned by getArtifact. An API key
        or API-audience OAuth bearer token is accepted; the MCP-audience OAuth
        grant used for artifact retrieval is also accepted only at this bound
        binary handoff. The server rechecks the artifact's organisation,
        original purpose scopes, requester and current role, verifies
        encrypted-object integrity, then streams the bytes with their exact
        declared size and checksum. Artifact-bound downloads are the only
        MCP-audience exception among /v1 routes; ordinary JSON API routes remain
        API-audience only. The ordinary JSON response budget does not apply to
        the binary stream. MCP artifact resources return bounded metadata with
        this authenticated download URL.
      operationId: downloadArtifactBytes
      parameters:
        - name: orgId
          in: path
          required: true
          schema:
            type: string
            pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
        - name: id
          in: path
          required: true
          schema:
            type: string
            pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
      responses:
        '200':
          description: Verified artifact stream with its exact byte length and checksum.
          headers:
            Content-Length:
              schema:
                type: string
                pattern: ^[0-9]+$
            Content-Disposition:
              schema:
                type: string
            Cache-Control:
              schema:
                type: string
                const: no-store
            Digest:
              schema:
                type: string
              description: sha-256= followed by the base64 checksum.
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
            text/csv:
              schema:
                type: string
                format: binary
            application/x-ndjson:
              schema:
                type: string
                format: binary
        '401':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '410':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '500':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '503':
          description: >-
            Redacted artifact authentication, current authority, availability,
            expiry or integrity failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
      security:
        - apiKey: []
        - oauth: []
components:
  schemas:
    ErrorEnvelope:
      type: object
      required:
        - error
      additionalProperties: false
      properties:
        error:
          type: object
          required:
            - code
            - message
            - requestId
          additionalProperties: false
          properties:
            code:
              type: string
              description: >-
                Known domain codes are published in ErrorCode; unknown future
                codes remain valid.
              x-rootset-known-error-codes:
                - VALIDATION_FAILED
                - UNAUTHENTICATED
                - ACCESS_DENIED
                - FORBIDDEN
                - LAST_ADMIN
                - INSUFFICIENT_SCOPE
                - PERSONAL_IDENTITY_REQUIRED
                - DELEGATION_EXCEEDS_AUTHORITY
                - RESOURCE_NOT_FOUND
                - ROW_VERSION_CONFLICT
                - SCHEMA_VERSION_CONFLICT
                - UNIQUE_CONFLICT
                - ROW_SIZE_LIMIT
                - ROW_LIMIT_REACHED
                - PAYLOAD_TOO_LARGE
                - REQUEST_TIMEOUT
                - QUERY_TIMEOUT
                - CURSOR_INVALID
                - STEP_UP_REQUIRED
                - IDEMPOTENCY_CONFLICT
                - JOB_FAILED
                - RATE_LIMITED
                - CAPACITY_LIMIT
                - SCHEMA_MAINTENANCE
                - ARTIFACT_UNVERIFIED
                - ARTIFACT_EXPIRED
                - CONFIGURATION_INVALID
                - DEPENDENCY_UNAVAILABLE
                - INTERNAL_ERROR
            message:
              type: string
            requestId:
              type: string
            details: {}
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: Rootset personal API key
    oauth:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: http://localhost:4310/oauth/authorize
          tokenUrl: http://localhost:4310/oauth/token
          scopes:
            profile:manage: >-
              Current profile:manage authority; the live role ceiling still
              applies.
            account:security: >-
              Current account:security authority; the live role ceiling still
              applies.
            org:read: Current org:read authority; the live role ceiling still applies.
            org:manage: Current org:manage authority; the live role ceiling still applies.
            members:read: >-
              Current members:read authority; the live role ceiling still
              applies.
            members:manage: >-
              Current members:manage authority; the live role ceiling still
              applies.
            keys:manage: >-
              Current keys:manage authority; the live role ceiling still
              applies.
            team-keys:manage: >-
              Current team-keys:manage authority; the live role ceiling still
              applies.
            databases:read: >-
              Current databases:read authority; the live role ceiling still
              applies.
            databases:manage: >-
              Current databases:manage authority; the live role ceiling still
              applies.
            tables:read: >-
              Current tables:read authority; the live role ceiling still
              applies.
            tables:manage: >-
              Current tables:manage authority; the live role ceiling still
              applies.
            schema:manage: >-
              Current schema:manage authority; the live role ceiling still
              applies.
            rows:read: Current rows:read authority; the live role ceiling still applies.
            rows:write: Current rows:write authority; the live role ceiling still applies.
            history:read: >-
              Current history:read authority; the live role ceiling still
              applies.
            exports:read: >-
              Current exports:read authority; the live role ceiling still
              applies.
            jobs:read: Current jobs:read authority; the live role ceiling still applies.
            jobs:cancel: >-
              Current jobs:cancel authority; the live role ceiling still
              applies.
            jobs:retry: Current jobs:retry authority; the live role ceiling still applies.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.