> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firedrill.run/llms.txt
> Use this file to discover all available pages before exploring further.

# Download one verified artifact from an authorized run

> Only an exact path from this run's verified manifest (or manifest.json) can be read. Delivery is attachment-only and private/no-store. Current user authentication, exact-run or project read authority, grant expiry and evidence deletion are rechecked during transfer. A three-second authority lease with a 250 ms watchdog fails closed even if a recheck stalls; streams have a thirty-second deadline. Already delivered bytes cannot be recalled. Credentials are never forwarded to artifact storage origins.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/run-links/{hostedRunId}/artifacts
openapi: 3.1.0
info:
  title: Firedrill Control API
  version: 1.0.0
  description: >-
    The control plane for drills, drill runs, and the worlds they run in. Errors
    always carry the canonical envelope; unsafe operations require an
    Idempotency-Key; long work returns an operation resource.
servers:
  - url: https://api.firedrill.run
security:
  - controlCredential: []
paths:
  /v1/run-links/{hostedRunId}/artifacts:
    get:
      summary: Download one verified artifact from an authorized run
      description: >-
        Only an exact path from this run's verified manifest (or manifest.json)
        can be read. Delivery is attachment-only and private/no-store. Current
        user authentication, exact-run or project read authority, grant expiry
        and evidence deletion are rechecked during transfer. A three-second
        authority lease with a 250 ms watchdog fails closed even if a recheck
        stalls; streams have a thirty-second deadline. Already delivered bytes
        cannot be recalled. Credentials are never forwarded to artifact storage
        origins.
      operationId: runLinks.downloadArtifact
      parameters:
        - name: hostedRunId
          in: path
          required: true
          schema:
            type: string
            pattern: ^hrun_[0-9a-z]{12,32}$
        - name: path
          in: query
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 1024
      responses:
        '200':
          description: Verified artifact bytes
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
        default:
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    ErrorEnvelope:
      type: object
      properties:
        code:
          type: string
          pattern: ^(control|world)\.[A-Z][A-Z0-9]*(_[A-Z0-9]+)*$
        message:
          type: string
          minLength: 1
        correlationId:
          type: string
          minLength: 1
        retryable:
          type: boolean
        retryAfterMs:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
        operationId:
          type: string
        source:
          type: string
          enum:
            - platform
            - simulated_provider
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              code:
                type: string
              message:
                type: string
            required:
              - path
              - code
              - message
            additionalProperties: false
        details:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        evidence:
          type: object
          properties:
            sessionId:
              type: string
            runId:
              type: string
            journalSeq:
              type: integer
              minimum: 0
              maximum: 9007199254740991
            buildHash:
              type: string
          additionalProperties: false
      required:
        - code
        - message
        - correlationId
        - retryable
        - source
      additionalProperties: true
  securitySchemes:
    controlCredential:
      type: http
      scheme: bearer
      description: Opaque control credential

````