Skip to main content
Files

File スキーマ

Forward API リファレンス。

File object

Upload, get, and list endpoints return this structure.
フィールド型説明
idstringfile_ プレフィックス付きの File ID
typestringAlways "file"
filenamestring保存されたファイル名
size_bytesintegerファイルサイズ(バイト)
mime_typestringMIME type supplied during upload or detected from the filename
downloadablebooleanWhether the File can be downloaded through the /content endpoint
scopeobject | nullScope when the File is attached to another resource, such as { "id": "sess_...", "type": "session" }; null when unattached
metadataobjectCustom metadata supplied during upload; defaults to {} when omitted. created_by is reserved by Forward and must not be supplied by callers
identity_idstring | nullOwning Forward identity. Returns the Identity ID when owned by an Identity, or null otherwise. See Identity ownership
icon_urlstring | nullIcon URL associated by Forward
binding_infoBinding infoBinding information, such as Template reference counts
created_atstringCreation time in RFC 3339 format
updated_atstringLast update time in RFC 3339 format

Identity ownership

An account (or Workspace) can have multiple Identities. Each Identity represents an end user of the product integrated with that account (or Workspace). A File can belong to an account (or Workspace) or to an Identity. Ownership determines who can view, download, and delete the File.

Specifying ownership

CallerOwnershipHow to specify
PATAccount / WorkspaceOmit identity_id (the default, unchanged from previous behavior)
PATSpecified IdentitySupply the query parameter identity_id=<identity_id>
SAT (administrator)WorkspaceResolved automatically; cannot be switched through parameters
SAT (bound to an Identity)That IdentityResolved automatically; cannot be switched through parameters
identity_id is optional and is used only when operating on Identity-owned resources. A PAT can explicitly supply it; omitting it uses administrator scope. SAT ownership is determined by the credential. To operate in Identity scope, issue an Identity-scoped credential and do not explicitly supply this parameter (even with an empty value); otherwise, HTTP 400 is returned. An Identity specified by a PAT must belong to the account or Workspace represented by that PAT and must be enabled. An Identity that does not exist, is disabled or deleted, or does not belong to the caller returns 404.

Ownership isolation

  • In administrator scope (a PAT without identity_id or an Admin SAT), Identity-owned Files are not visible.
  • An Identity cannot see Files owned by the account (or Workspace) itself or by other Identities under the same account.
  • In a valid Identity scope, cross-scope get, download, or delete operations always return 404, without distinguishing between "not found" and "not yours".
  • A PAT without identity_id and an Admin SAT retain existing behavior: an Owner mismatch returns 403. A downstream permission check may also return 403.
  • Creation idempotency keys are isolated by ownership. Different Identities can reuse the same Idempotency-Key without replaying each other's requests.

Supported endpoints

Uploading, searching, listing, getting, downloading, and deleting Files all support Identity scope.
GET /api/v1/forward/resources/batch does not support identity_id; its visibility rules are unchanged.

Supported upload file types

アップロードエンドポイントはテキストベースのファイルのみを受け付けます。
カテゴリ受け入れ可能な値
MIME タイプすべての text/* MIME タイプに加え、application/json、application/xml、application/javascript、application/x-yaml、application/x-toml
拡張子.txt, .md, .csv, .json, .xml, .yaml, .yml, .toml, .ini, .conf, .cfg, .env, .log, .html, .htm, .css, .scss, .less, .js, .jsx, .ts, .tsx, .vue, .svelte, .py, .go, .rs, .java, .kt, .scala, .c, .cpp, .cc, .h, .hpp, .rb, .php, .swift, .r, .lua, .pl, .sh, .bash, .zsh, .fish, .ps1, .sql, .graphql, .gql, .proto, .dockerfile, .makefile, .gitignore, .editorconfig, .eslintrc, .prettierrc, .tex, .rst, .adoc, .org, .svg
拡張子なしファイル名dockerfile, makefile, gemfile, rakefile, procfile, vagrantfile, justfile, brewfile

File download response object

The Download a File endpoint returns this structure, including a short-lived presigned URL.
フィールド型説明
urlstring署名付きダウンロード URL
expires_atstringURL expiration time in RFC 3339 format
filenamestringSuggested download filename, used for browser Content-Disposition

Binding info

Reference summary included by Forward in File responses.
フィールド型説明
agent_template_countintegerNumber of Templates currently bound to the File

List pagination fields

フィールド型説明
dataarray of File objectsRecords on the current page
has_morebooleanWhether another page is available
next_pagestring | nullForward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null
first_idstring | nullID of the first record on the current page
last_idstring | nullID of the last record on the current page
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.