# List attachments for an entity

> `GET` `/v1/attachments`

URL: https://www.agencytitan.com/docs/tag/attachments/GET/v1/attachments

Operation ID: `attachments_list`

Tag: [attachments](https://www.agencytitan.com/docs/tag/attachments.md)

## Description

Returns metadata-only file references for one readable parent entity. The parent is read through its own public get authorization path before the tenant storage registry is queried. No storage path or download credential is returned.

## Parameters

- `entity_id` (query, required, `string`) — Parent entity id. Optional filter. Omit unless the user asked for it; never guess identifiers.
- `entity_type` (query, required, `string`) — Public parent entity type. Optional filter. Omit unless the user asked for it; never guess identifiers.
- `limit` (query, optional, `integer`) — Maximum number of items to return (1-200).
- `offset` (query, optional, `integer`) — Number of items to skip before collecting the result set.
- `order` (query, optional, `string`) — Sort direction. Default `desc`.
- `search` (query, optional, `string`) — Case-insensitive match over filename or content type.
- `sort` (query, optional, `string`) — Field to sort by. Default `created_at`.

## Request body

_None_

## Responses

- `200` (`application/json`): Successful response.
  - Type: `object`
  - Properties:
    - `data` (`array<object>`, required)
    - `pagination` (`object`, required)
- `400` (`application/json`): Request validation failed (unknown or out-of-range parameters/properties are rejected).
  - Type: `object`
  - Properties:
    - `error` (`object`, required)
- `401` (`application/json`): Missing, invalid, expired, or revoked bearer token.
  - Type: `object`
  - Properties:
    - `error` (`string`, required)
    - `error_description` (`string`, required)
- `403` (`application/json`): The authenticated user does not have permission for this operation.
  - Type: `object`
  - Properties:
    - `error` (`object`, required)
- `404` (`application/json`): The requested resource was not found.
  - Type: `object`
  - Properties:
    - `error` (`object`, required)
- `429` (`application/json`): Per-tenant rate limit exceeded (600 requests/minute across all /v1 REST endpoints). The Retry-After header indicates how many seconds to wait.
  - Type: `object`
  - Properties:
    - `error` (`object`, required)
- `500` (`application/json`): An unexpected internal error occurred.
  - Type: `object`
  - Properties:
    - `error` (`object`, required)

## Authentication

- `bearerAuth` — http (bearer) — All /v1 endpoints (except `/v1/openapi.json` and `/v1/llms.txt`) require a bearer token. Two equal first-class paths: (1) an OAuth 2.0 access token from the au…

## Useful links

- Interactive page: https://www.agencytitan.com/docs/tag/attachments/GET/v1/attachments
- API reference home: https://www.agencytitan.com/docs/
- Tag page: https://www.agencytitan.com/docs/tag/attachments.md
- This operation as Markdown: https://www.agencytitan.com/docs/tag/attachments/GET/v1/attachments.md
- OpenAPI JSON: https://www.agencytitan.com/docs/openapi.json
- Full API Markdown: https://api.agencytitan.com/v1/llms.txt
- API keys: https://app.agencytitan.com/settings/api-mcp
