> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a download link for a file

> Returns a short-lived link to the file rather than the bytes, so your own code decides what to do next and the expiry is visible.

**Treat the link as a credential.** Request a new one rather than storing one or retrying an expired one.



## OpenAPI

````yaml /openapi/kira-api.2026-06-01.json get /v1/rfis/{rfi_id}/items/{item_id}/documents/{document_id}
openapi: 3.1.0
info:
  title: Kira API
  version: '2026-06-01'
  description: >-
    REST API for users, KYC/KYB verification, virtual accounts, payouts,
    recipients, and webhooks. Every request requires an `x-api-key` header and a
    bearer access token (see Authentication). Pin your account to version
    `2026-04-14` before integrating.
  contact:
    name: Kira API Support
    email: support@kirafin.ai
servers:
  - url: https://api.balampay.com
    description: Production
  - url: https://api.balampay.com/sandbox
    description: Sandbox
security:
  - bearerAuth: []
    apiKeyAuth: []
tags:
  - name: Authentication
  - name: Versioning
  - name: Users
  - name: Virtual Accounts
  - name: Recipients
  - name: Quotations
  - name: Payouts
  - name: Reference
  - name: RFIs
paths:
  /v1/rfis/{rfi_id}/items/{item_id}/documents/{document_id}:
    get:
      tags:
        - RFIs
      summary: Get a download link for a file
      description: >-
        Returns a short-lived link to the file rather than the bytes, so your
        own code decides what to do next and the expiry is visible.


        **Treat the link as a credential.** Request a new one rather than
        storing one or retrying an expired one.
      operationId: get_v1-rfis-rfi-id-items-item-id-documents-document-id
      parameters:
        - in: path
          name: rfi_id
          required: true
          schema:
            type: string
            format: uuid
          description: RFI UUID.
        - in: path
          name: item_id
          required: true
          schema:
            type: string
            format: uuid
          description: Item UUID. The item must be a `document` item of this RFI.
        - in: path
          name: document_id
          required: true
          schema:
            type: string
            format: uuid
          description: The file's own id, as returned in `documents[]`.
        - in: header
          name: X-Api-Version
          required: false
          description: >-
            Version applied to this request. It wins over your account's pinned
            version — see [Versioning](/using-the-api/versioning).
          schema:
            type: string
            example: '2026-06-01'
      responses:
        '200':
          description: The link, and when it stops working.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RfiDocumentDownloadResponse'
              example:
                download_url: https://files.balampay.com/rfi/…?expires=1789...&signature=…
                expires_at: '2026-09-04T10:15:00.000Z'
        '400':
          description: Malformed `rfi_id`, `item_id`, or `document_id`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
              example:
                code: validation_error
                message: Invalid request body
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: invalid_request
                message: >-
                  The request could not be authenticated. Check the x-api-key
                  and Authorization headers.
        '404':
          description: >-
            The RFI belongs to another client or is `withdrawn`, the item does
            not belong to this RFI, or the RFI has no such file.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: not_found
                message: RFI not found
      security:
        - bearerAuth: []
          apiKeyAuth: []
      servers:
        - url: https://api.balampay.com/sandbox
          description: Sandbox
        - url: https://api.balampay.com
          description: Production
components:
  schemas:
    RfiDocumentDownloadResponse:
      type: object
      properties:
        download_url:
          type: string
          format: uri
          description: Pre-signed URL. Downloads under the file's own `file_name`.
        expires_at:
          type: string
          format: date-time
          description: When the link stops working. Minutes away, deliberately.
    ValidationErrorResponse:
      type: object
      description: >-
        Validation / request error. The body shape is **not uniform** across the
        API — it varies by endpoint and by which validation layer rejects the
        request. The fields below are the union of what may appear; treat them
        all as optional. Observed shapes include `{ code, message }`, `{ code,
        message, errors[] }`, `{ code, error, details[] }`, `{ error, details[]
        }`, and a nested `{ error: { code, message, details } }`. Always branch
        on the HTTP status, not on a fixed body shape.
      properties:
        code:
          type: string
        message:
          type: string
        error:
          type:
            - string
            - object
          description: >-
            A short error label (e.g. `"Invalid data"`), or on some endpoints a
            nested `{ code, message, details }` object.
        errors:
          type: array
          items:
            type: object
            properties:
              field:
                type: string
              message:
                type: string
            required:
              - field
              - message
        details:
          type:
            - array
            - object
          description: >-
            Per-issue detail. Shape varies by endpoint — typically an array of
            `{ message }` or `{ path, message, code }`, occasionally an object.
    ErrorResponse:
      type: object
      properties:
        message:
          type: string
        code:
          type: string
        statusCode:
          type: number
        error:
          type: string
        timestamp:
          type: string
        path:
          type: string
        details: {}
      required:
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The `data.access_token` value from [Get access
        token](/api-reference/authentication/get-access-token).
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key issued by Kira.

````