List files
Lists the conversation's files, oldest first: uploads and files a sandbox command left in its outbox. Read one back with artifacts.download.
Authentication
Both headers are required.
- Header:
X-Api-Key: YOUR_API_KEY - Header:
Authorization: Bearer YOUR_USER_TOKEN
Path parameters
userIdstring · uuidrequiredThe user in the path; must equal the token's own account.
Validation rules
- Format
"uuid"- Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
conversationIdstring · uuidrequiredThe conversation's id.
Validation rules
- Format
"uuid"- Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
Query parameters
cursorstringoptionalWhere the previous page ended; omit for the first page
Validation rules
- Maximum length
256
limitintegeroptionalHow many rows to answer, at most 100
Validation rules
- Default
50- Minimum
1- Maximum
100
Request example
Illustrative request. Replace the host, credentials and resource IDs with your own. If a request file is shown, create it from the schema above. Review the requested action before sending it.
curl --request GET 'https://api.example.test/v1/users/YOUR_USER_ID/conversations/YOUR_CONVERSATION_ID/artifacts' \
--header 'X-Api-Key: YOUR_API_KEY' \
--header 'Authorization: Bearer YOUR_USER_TOKEN'
Responses
200 The conversation's files.
The conversation's files.
application/json · object
dataarrayrequiredThis page's rows.
Show attributes
This page's rows.
Array items · object
One file attached to a conversation: an upload, or a file a sandbox command produced.
idstring · uuidrequiredThe artifact's id.
Validation rules
- Format
"uuid"- Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
conversationIdstring · uuidrequiredThe conversation's id.
Validation rules
- Format
"uuid"- Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
runIdanyOfrequiredThe run whose sandbox produced it; null for uploads and standalone tool calls.
Show attributes
The run whose sandbox produced it; null for uploads and standalone tool calls.
anyOf · 2 variants
Variant 1 · string · uuid
Validation rules
- Format
"uuid"- Pattern
"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
Variant 2 · null
originstringrequiredHow the file entered the conversation: upload from the caller, or sandbox from a run's sandbox command.
Validation rules
- Allowed values
["upload","sandbox"]
namestringrequiredThe file's name: one path segment of letters, digits, ., _ and -.
Validation rules
- Pattern
"^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$"
mediaTypestringrequiredAs declared by the uploader; downloads are always served as opaque bytes.
Validation rules
- Maximum length
128
bytesintegerrequiredThe file's size in bytes.
Validation rules
- Minimum
0- Maximum
9007199254740991
sha256stringrequiredThe file's SHA-256 digest, lowercase hex.
Validation rules
- Pattern
"^[0-9a-f]{64}$"
createdAtstring · date-timerequiredWhen the file was attached.
Validation rules
- Format
"date-time"- Pattern
"^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$"
nextCursorstring or nullrequiredThe cursor for the next page; null once there are no more rows.
totalintegerrequiredHow many rows the list holds in all.
Validation rules
- Minimum
0- Maximum
9007199254740991
400 The request could not be read as this operation expects.
The request could not be read as this operation expects.
invalid_input— the body or query failed validation;issuesnames each fieldinvalid_cursor— thecursoris not one this list minted
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
401 A credential is missing, invalid or expired.
A credential is missing, invalid or expired.
partner_key_required— noX-Api-Keyheader was sentpartner_key_invalid— theX-Api-Keyis unknown or revokedcredential_expired— the user token has expired; obtain a fresh one
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
403 The credentials are valid but may not do this.
The credentials are valid but may not do this.
subject_mismatch— the{userId}in the path is not the token's useraccount_disabled— an operator disabled the accountorigin_rejected— a browserOriginother than the configured web origin
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
404 The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.
The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
412 The identity is verified but has no account yet.
The identity is verified but has no account yet.
account_not_provisioned— the identity is verified but has no account yet; callusers.ensurefirst
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
429 A limiter refused the request; honour `Retry-After`.
A limiter refused the request; honour Retry-After.
rate_limited— the per-key or per-user limit is spent; honourRetry-After
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
500 A fault on our side; quote `requestId` when reporting it.
A fault on our side; quote requestId when reporting it.
internal— a fault on our side; quoterequestIdwhen reporting it
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
503 The replica is draining or a dependency did not answer; `retryable` says whether to try again.
The replica is draining or a dependency did not answer; retryable says whether to try again.
internal— a fault on our side; quoterequestIdwhen reporting it
application/problem+json · object
RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack.
typestringrequiredThe kind of problem as a URN, urn:fin:error:<kind>; stable, compare against it
titlestringrequiredThe kind's human title, for logs; never parse it
statusintegerrequiredThe HTTP status, repeated in the body
Validation rules
- Minimum
400- Maximum
599
reasonstringoptionalThe machine-readable why. One of:
run_active(409) — a run already holds this conversationbudget_exhausted(409) — the user's spend headroom is gone, or an operator froze itapproval_not_pending(409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversationexecution_capacity(409) — no execution capacity is free right now;retryablesays whether to try againexecution_unavailable(409) — the execution engine could not take the workstop_pending(409) — a stop is already in progress and its cleanup is not yet confirmedautomation_changed(409) — therevisionsent is stale; reload the automationautomation_held(409) — an operator holds the automation; it fires again when releasedautomation_invalid(409) — the automation's definition cannot run as writtenautomation_completed(409) — the automation has finished for good and cannot fire againautomation_limit(409) — the user already has as many automations as the deployment allowsprofile_unknown_tool(409) — the run profile names a tool this deployment does not havedeployment_paused(409) — an operator paused a deployment control; nothing was admitted or firedrun_not_active(409) — the run named in the path is not the conversation's live runwithdrawal_changed(409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progresscredential_expired(401) — the user token has expired; obtain a fresh oneaccount_disabled(403) — an operator disabled the accountaccount_not_provisioned(412) — the identity is verified but has no account yet; callusers.ensurefirstprovider_unavailable(503) — an external provider the call depends on did not answerengine_unavailable(503) — the execution engine did not answerinvalid_input(400) — the body or query failed validation;issuesnames each fieldinternal(500) — a fault on our side; quoterequestIdwhen reporting itpartner_key_required(401) — noX-Api-Keyheader was sentpartner_key_invalid(401) — theX-Api-Keyis unknown or revokedsubject_mismatch(403) — the{userId}in the path is not the token's userorigin_rejected(403) — a browserOriginother than the configured web originpermission_required(403) — the operator credential lacks the scope this call needsrate_limited(429) — the per-key or per-user limit is spent; honourRetry-Afterstream_capacity(429) — no stream socket is free on this replica or for this user; honourRetry-Afterinvalid_cursor(400) — thecursoris not one this list minted
Validation rules
- Allowed values
["run_active","budget_exhausted","approval_not_pending","execution_capacity","execution_unavailable","stop_pending","automation_changed","automation_held","automation_invalid","automation_completed","automation_limit","profile_unknown_tool","deployment_paused","run_not_active","withdrawal_changed","credential_expired","account_disabled","account_not_provisioned","provider_unavailable","engine_unavailable","invalid_input","internal","partner_key_required","partner_key_invalid","subject_mismatch","origin_rejected","permission_required","rate_limited","stream_capacity","invalid_cursor"]
requestIdstringrequiredThe id Fin used for this request; quote it when reporting a problem
retryablebooleanrequiredWhether repeating the same request later can succeed without changing it
detailstringoptionalOnly on invalid_input: which part of the request failed validation
issuesarrayoptionalOnly on invalid_input: one entry per failing field
Show attributes
Only on invalid_input: one entry per failing field
Array items · object
pathstringrequiredThe JSON pointer of the failing field; empty for the root object
messagestringrequiredWhy the field failed
Complete OpenAPI definition
The exact operation and all referenced components, including recursive schemas.
{
"operation": {
"operationId": "artifacts.list",
"summary": "List files",
"tags": [
"artifacts"
],
"description": "Lists the conversation's files, oldest first: uploads and files a sandbox command left in its outbox. Read one back with `artifacts.download`.",
"parameters": [
{
"schema": {
"type": "string",
"maxLength": 256
},
"in": "query",
"name": "cursor",
"required": false,
"description": "Where the previous page ended; omit for the first page"
},
{
"schema": {
"default": 50,
"type": "integer",
"minimum": 1,
"maximum": 100
},
"in": "query",
"name": "limit",
"required": false,
"description": "How many rows to answer, at most 100"
},
{
"schema": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
},
"in": "path",
"name": "userId",
"required": true,
"description": "The user in the path; must equal the token's own account."
},
{
"schema": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
},
"in": "path",
"name": "conversationId",
"required": true,
"description": "The conversation's id."
}
],
"security": [
{
"apiKey": [],
"userToken": []
}
],
"responses": {
"200": {
"description": "The conversation's files.",
"content": {
"application/json": {
"schema": {
"type": "object",
"properties": {
"data": {
"type": "array",
"items": {
"$ref": "#/components/schemas/Artifact"
},
"description": "This page's rows."
},
"nextCursor": {
"description": "The cursor for the next page; null once there are no more rows.",
"type": [
"string",
"null"
]
},
"total": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991,
"description": "How many rows the list holds in all."
}
},
"required": [
"data",
"nextCursor",
"total"
]
}
}
}
},
"400": {
"$ref": "#/components/responses/InvalidInput"
},
"401": {
"$ref": "#/components/responses/Unauthorized"
},
"403": {
"$ref": "#/components/responses/Forbidden"
},
"404": {
"$ref": "#/components/responses/NotFound"
},
"412": {
"$ref": "#/components/responses/AccountNotProvisioned"
},
"429": {
"$ref": "#/components/responses/TooManyRequests"
},
"500": {
"$ref": "#/components/responses/Internal"
},
"503": {
"$ref": "#/components/responses/Unavailable"
}
}
},
"components": {
"schemas": {
"Artifact": {
"type": "object",
"properties": {
"id": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "The artifact's id."
},
"conversationId": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "The conversation's id."
},
"runId": {
"anyOf": [
{
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
},
{
"type": "null"
}
],
"description": "The run whose sandbox produced it; null for uploads and standalone tool calls."
},
"origin": {
"type": "string",
"enum": [
"upload",
"sandbox"
],
"description": "How the file entered the conversation: `upload` from the caller, or `sandbox` from a run's sandbox command."
},
"name": {
"type": "string",
"pattern": "^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$",
"description": "The file's name: one path segment of letters, digits, `.`, `_` and `-`."
},
"mediaType": {
"type": "string",
"maxLength": 128,
"description": "As declared by the uploader; downloads are always served as opaque bytes."
},
"bytes": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991,
"description": "The file's size in bytes."
},
"sha256": {
"type": "string",
"pattern": "^[0-9a-f]{64}$",
"description": "The file's SHA-256 digest, lowercase hex."
},
"createdAt": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$",
"description": "When the file was attached."
}
},
"required": [
"id",
"conversationId",
"runId",
"origin",
"name",
"mediaType",
"bytes",
"sha256",
"createdAt"
],
"description": "One file attached to a conversation: an upload, or a file a sandbox command produced."
},
"ProblemDetails": {
"type": "object",
"properties": {
"type": {
"type": "string",
"description": "The kind of problem as a URN, `urn:fin:error:<kind>`; stable, compare against it"
},
"title": {
"type": "string",
"description": "The kind's human title, for logs; never parse it"
},
"status": {
"type": "integer",
"minimum": 400,
"maximum": 599,
"description": "The HTTP status, repeated in the body"
},
"reason": {
"description": "The machine-readable why. One of:\n\n- `run_active` (409) — a run already holds this conversation\n- `budget_exhausted` (409) — the user's spend headroom is gone, or an operator froze it\n- `approval_not_pending` (409) — the approval was already decided or has expired, or its id does not exist or belongs to a different conversation\n- `execution_capacity` (409) — no execution capacity is free right now; `retryable` says whether to try again\n- `execution_unavailable` (409) — the execution engine could not take the work\n- `stop_pending` (409) — a stop is already in progress and its cleanup is not yet confirmed\n- `automation_changed` (409) — the `revision` sent is stale; reload the automation\n- `automation_held` (409) — an operator holds the automation; it fires again when released\n- `automation_invalid` (409) — the automation's definition cannot run as written\n- `automation_completed` (409) — the automation has finished for good and cannot fire again\n- `automation_limit` (409) — the user already has as many automations as the deployment allows\n- `profile_unknown_tool` (409) — the run profile names a tool this deployment does not have\n- `deployment_paused` (409) — an operator paused a deployment control; nothing was admitted or fired\n- `run_not_active` (409) — the run named in the path is not the conversation's live run\n- `withdrawal_changed` (409) — the withdrawal cannot be prepared or confirmed as asked: the balance no longer covers it, its terms changed or expired, or it is already in progress\n- `credential_expired` (401) — the user token has expired; obtain a fresh one\n- `account_disabled` (403) — an operator disabled the account\n- `account_not_provisioned` (412) — the identity is verified but has no account yet; call `users.ensure` first\n- `provider_unavailable` (503) — an external provider the call depends on did not answer\n- `engine_unavailable` (503) — the execution engine did not answer\n- `invalid_input` (400) — the body or query failed validation; `issues` names each field\n- `internal` (500) — a fault on our side; quote `requestId` when reporting it\n- `partner_key_required` (401) — no `X-Api-Key` header was sent\n- `partner_key_invalid` (401) — the `X-Api-Key` is unknown or revoked\n- `subject_mismatch` (403) — the `{userId}` in the path is not the token's user\n- `origin_rejected` (403) — a browser `Origin` other than the configured web origin\n- `permission_required` (403) — the operator credential lacks the scope this call needs\n- `rate_limited` (429) — the per-key or per-user limit is spent; honour `Retry-After`\n- `stream_capacity` (429) — no stream socket is free on this replica or for this user; honour `Retry-After`\n- `invalid_cursor` (400) — the `cursor` is not one this list minted",
"type": "string",
"enum": [
"run_active",
"budget_exhausted",
"approval_not_pending",
"execution_capacity",
"execution_unavailable",
"stop_pending",
"automation_changed",
"automation_held",
"automation_invalid",
"automation_completed",
"automation_limit",
"profile_unknown_tool",
"deployment_paused",
"run_not_active",
"withdrawal_changed",
"credential_expired",
"account_disabled",
"account_not_provisioned",
"provider_unavailable",
"engine_unavailable",
"invalid_input",
"internal",
"partner_key_required",
"partner_key_invalid",
"subject_mismatch",
"origin_rejected",
"permission_required",
"rate_limited",
"stream_capacity",
"invalid_cursor"
]
},
"requestId": {
"type": "string",
"description": "The id Fin used for this request; quote it when reporting a problem"
},
"retryable": {
"type": "boolean",
"description": "Whether repeating the same request later can succeed without changing it"
},
"detail": {
"description": "Only on `invalid_input`: which part of the request failed validation",
"type": "string"
},
"issues": {
"description": "Only on `invalid_input`: one entry per failing field",
"type": "array",
"items": {
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "The JSON pointer of the failing field; empty for the root object"
},
"message": {
"type": "string",
"description": "Why the field failed"
}
},
"required": [
"path",
"message"
]
}
}
},
"required": [
"type",
"title",
"status",
"requestId",
"retryable"
],
"description": "RFC 9457 problem details: what every error response carries. Never a provider's message, a query or a stack."
}
},
"responses": {
"InvalidInput": {
"description": "The request could not be read as this operation expects.\n\n- `invalid_input` — the body or query failed validation; `issues` names each field\n- `invalid_cursor` — the `cursor` is not one this list minted",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"Unauthorized": {
"description": "A credential is missing, invalid or expired.\n\n- `partner_key_required` — no `X-Api-Key` header was sent\n- `partner_key_invalid` — the `X-Api-Key` is unknown or revoked\n- `credential_expired` — the user token has expired; obtain a fresh one",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"Forbidden": {
"description": "The credentials are valid but may not do this.\n\n- `subject_mismatch` — the `{userId}` in the path is not the token's user\n- `account_disabled` — an operator disabled the account\n- `origin_rejected` — a browser `Origin` other than the configured web origin",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"NotFound": {
"description": "The resource is missing, belongs to someone else, or its id is malformed: all three answer alike.",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"AccountNotProvisioned": {
"description": "The identity is verified but has no account yet.\n\n- `account_not_provisioned` — the identity is verified but has no account yet; call `users.ensure` first",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"TooManyRequests": {
"description": "A limiter refused the request; honour `Retry-After`.\n\n- `rate_limited` — the per-key or per-user limit is spent; honour `Retry-After`",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"Internal": {
"description": "A fault on our side; quote `requestId` when reporting it.\n\n- `internal` — a fault on our side; quote `requestId` when reporting it",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"Unavailable": {
"description": "The replica is draining or a dependency did not answer; `retryable` says whether to try again.\n\n- `internal` — a fault on our side; quote `requestId` when reporting it",
"content": {
"application/problem+json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
}
},
"securitySchemes": {
"apiKey": {
"type": "apiKey",
"in": "header",
"name": "X-Api-Key"
},
"userToken": {
"type": "http",
"scheme": "bearer",
"bearerFormat": "JWT"
}
}
}
}