> ## Documentation Index
> Fetch the complete documentation index at: https://enterprise-docs.dify.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Download File

> **Available for**: Workflow, Chatflow

Serves a file's raw bytes for preview or download. The file must belong to the calling app, the environment, and the `user`.

**Standard API equivalent**: [Download File](/en/3.13.x/develop/api/files/download-file). Differences:

- A `kind` parameter selects the file source.
- `user` is required.
- Error codes differ.



## OpenAPI

````yaml /en/3.13.x/develop/api/openapi_service.json get /v2/files/{file_id}/preview
openapi: 3.0.1
info:
  title: Dify Service API
  description: >-
    REST API for Dify applications and knowledge bases. Application endpoints
    authenticate with an app API key; knowledge endpoints authenticate with a
    dataset API key.
  version: 1.0.0
servers:
  - url: https://{api_base_url}
    description: >-
      Base URL of the Dify Service API. Replace it with your deployment's API
      endpoint.
    variables:
      api_base_url:
        default: api.example.com/v1
        description: Host and path of the API base URL, without the `https://` prefix.
security:
  - ApiKeyAuth: []
tags:
  - name: Chat Messages
    description: Operations related to chat messages and interactions.
  - name: Files
    description: File upload and preview operations.
  - name: End Users
    description: Operations related to end user information.
  - name: Feedback
    description: User feedback operations.
  - name: Conversations
    description: Operations related to managing conversations.
  - name: Audio
    description: Text-to-Speech and Speech-to-Text operations.
  - name: Applications
    description: Operations to retrieve application settings and information.
  - name: Annotations
    description: Operations related to managing annotations for direct replies.
  - name: Human Input
    description: Endpoints for resuming paused workflows that require human input.
  - name: Workflow Runs
    description: Operations for executing and managing workflows.
  - name: Completion Messages
    description: Operations related to text generation and completion.
  - name: Knowledge Bases
    description: >-
      Operations for managing knowledge bases, including creation,
      configuration, and retrieval.
  - name: Documents
    description: >-
      Operations for creating, updating, and managing documents within a
      knowledge base.
  - name: Chunks
    description: Operations for managing document chunks and child chunks.
  - name: Metadata
    description: >-
      Operations for managing knowledge base metadata fields and document
      metadata values.
  - name: Tags
    description: Operations for managing knowledge base tags and tag bindings.
  - name: Models
    description: Operations for retrieving available models.
  - name: Knowledge Pipeline
    description: >-
      Operations for managing and running knowledge pipelines, including
      datasource plugins and pipeline execution.
  - name: Deployed Environments
    description: >-
      Endpoints served by deployed environments over the `v2` base URL. Deployed
      environments serve only the endpoints in this group; calling any other
      path there returns `404 not_found`. Authentication and errors differ from
      the standard Service API; each page here is authoritative for deployed
      environments.
paths:
  /v2/files/{file_id}/preview:
    get:
      tags:
        - Deployed Environments
      summary: Download File
      description: >-
        **Available for**: Workflow, Chatflow


        Serves a file's raw bytes for preview or download. The file must belong
        to the calling app, the environment, and the `user`.


        **Standard API equivalent**: [Download
        File](/en/3.13.x/develop/api/files/download-file). Differences:


        - A `kind` parameter selects the file source.

        - `user` is required.

        - Error codes differ.
      operationId: downloadDeployedFile
      parameters:
        - name: file_id
          in: path
          required: true
          description: >-
            ID of the file to download. Two sources: the `id` returned by
            [Upload
            File](/en/3.13.x/develop/api/deployed-environments/upload-file), and
            the `upload_file_id` of an entry in a message's `message_files` from
            [List Conversation
            Messages](/en/3.13.x/develop/api/deployed-environments/list-conversation-messages).
            Tool-produced files need `kind=tool`.
          schema:
            type: string
            format: uuid
        - name: user
          in: query
          required: true
          description: >-
            End-user identifier, defined by your app and unique within it. Must
            match the `user` that owns the file. See [End User
            Identity](/en/3.13.x/develop/api/guides/end-user-identity).
          schema:
            type: string
            minLength: 1
            maxLength: 255
        - name: as_attachment
          in: query
          required: false
          description: >-
            When `true`, the file downloads as an attachment instead of
            rendering inline in the browser.
          schema:
            type: boolean
            default: false
        - name: kind
          in: query
          required: false
          description: >-
            File source. URLs returned in message payloads already carry the
            right value; set it manually only when constructing URLs yourself.
          schema:
            type: string
            enum:
              - upload
              - tool
            default: upload
      responses:
        '200':
          description: >-
            The raw file content. `Content-Type` is the file's own MIME type.
            When `as_attachment` is `true`, the response is sent as
            `application/octet-stream` with `Content-Disposition: attachment`.
            HTML files always download, whatever `as_attachment` says.
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
        '400':
          description: >-
            - `invalid_param`: `user`, `kind`, or `as_attachment` is not valid.
            The message is `invalid argument`.

            - `invalid_param`: `file_id` is not a UUID. The message is `invalid
            id`.

            - `app_unavailable`: the app can't serve API requests in this
            environment right now.
                - API access is turned off.
                - The app is not deployed here.
                - A deployment is still rolling out.
                - The environment is being deleted.

                Ask the app's owner to check its **Access Point** tab, or an administrator to check the environment in the Enterprise Dashboard, and retry once it serves again.
          content:
            application/json:
              examples:
                invalid_param:
                  summary: invalid_param
                  value:
                    code: invalid_param
                    message: invalid argument
                    status: 400
                invalid_param_id:
                  summary: invalid_param (invalid id)
                  value:
                    code: invalid_param
                    message: invalid id
                    status: 400
                app_unavailable:
                  summary: app_unavailable
                  value:
                    status: 400
                    code: app_unavailable
                    message: App unavailable, please check your app configurations.
        '401':
          description: >-
            `unauthorized`: the API key is missing, malformed, unknown, or
            revoked.
          content:
            application/json:
              examples:
                unauthorized:
                  summary: unauthorized
                  value:
                    code: unauthorized
                    message: Access token is invalid
                    status: 401
        '404':
          description: >-
            - `file_not_found`: the file does not exist, or it does not belong
            to the calling app, environment, `user`, and `kind`.

            - `APPDEPLOY_APP_NOT_FOUND`: Dify has no record of the app this API
            key belongs to. Check that the app still exists. Message `app not
            found`.
          content:
            application/json:
              examples:
                file_not_found:
                  summary: file_not_found
                  value:
                    status: 404
                    code: file_not_found
                    message: The requested file was not found.
                app_not_found:
                  summary: APPDEPLOY_APP_NOT_FOUND
                  value:
                    code: APPDEPLOY_APP_NOT_FOUND
                    message: app not found
                    status: 404
        '500':
          description: >-
            `internal_server_error`: the platform could not complete the
            request; retry, and contact your administrator if it persists.
          content:
            application/json:
              examples:
                internal_server_error:
                  summary: internal_server_error
                  value:
                    code: internal_server_error
                    message: internal error
                    status: 500
        '503':
          description: >-
            `internal_server_error`: the file service is temporarily
            unavailable; retry, and contact your administrator if it persists.
          content:
            application/json:
              examples:
                internal_server_error:
                  summary: internal_server_error
                  value:
                    code: internal_server_error
                    message: file service unavailable
                    status: 503
      servers:
        - url: https://{deployed_api_base_url}
          description: >-
            Base URL shared by every deployed environment: the standard Service
            API address, with `/v2` in place of `/v1`.
          variables:
            deployed_api_base_url:
              default: api.example.com
              description: >-
                On the app's **Access Point** tab, copy the full URL from any
                deployed environment's **Backend Service API** card, then remove
                the `https://` prefix and the trailing `/v2`.
components:
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API_KEY
      description: >-
        Every request authenticates with an API key: `Authorization: Bearer
        {API_KEY}`. App endpoints take an app API key; knowledge endpoints take
        a knowledge base API key ([Get
        Started](/en/3.13.x/develop/api/guides/get-started)).


        Keep keys server-side; never embed them in client code. Requests with a
        missing or invalid key fail with HTTP `401` (`unauthorized`).

````