Get a download URL for a document
curl --request GET \
--url https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": {
"downloadUrl": "https://files.example.com/d?X-Amz-Signature=abc",
"viewUrl": "https://files.example.com/v?X-Amz-Signature=def",
"fileName": "policy.pdf",
"contentType": "application/pdf",
"expiresAt": "2026-09-29T13:00:00.000Z"
},
"requestId": "dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8",
"timestamp": "2025-11-12T20:49:03.293Z"
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}File Documents
Get a Download URL for a Document
Mint short-lived links to download or view one document
GET
/
v2
/
upstream
/
file-documents
/
{fileDocumentId}
/
download-url
Get a download URL for a document
curl --request GET \
--url https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://public.api.live.turrisfi.com/v2/upstream/file-documents/{fileDocumentId}/download-url"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": {
"downloadUrl": "https://files.example.com/d?X-Amz-Signature=abc",
"viewUrl": "https://files.example.com/v?X-Amz-Signature=def",
"fileName": "policy.pdf",
"contentType": "application/pdf",
"expiresAt": "2026-09-29T13:00:00.000Z"
},
"requestId": "dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8",
"timestamp": "2025-11-12T20:49:03.293Z"
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}{
"statusCode": 123,
"requestId": "<string>",
"errorType": "validation_error",
"errorMessage": [
"<string>"
],
"timestamp": "<string>",
"details": {}
}Returns two short-lived presigned links for one document:
downloadUrl saves the file under its original name, and viewUrl opens it in a browser. Both stop working at expiresAt, one hour after the call. Fetch a fresh pair when you need one rather than storing the links.
It works for every document List Documents returns that is not deleted, and for the files on your surplus-lines filings that you can see in the filing response. The default list includes deleted documents, except Surplus Lines files, which are never listed once deleted, and asking for a deleted document returns 404. Files on checklist items Turris keeps internal are never served: they return 404, the same response as an id that does not exist.
For a file on a filing, pass the fileDocumentId the filing response shows on that file: every checklist attachment, the policy document and every completion artifact carries one. That is also how you fetch a file someone else put on the filing, such as a document Turris attached. An attachment’s _id identifies the attachment record, not the document, and returns 404 here.
Which version you get
For a compliance document you get the version your organization sees: the copy held on your relationship with the agency, otherwise the latest version. PassversionId (an S3 version id from the document’s version history) to pick a specific one.
If a compliance document has more than one relationship with your organization, the call returns 400 until you say which one with upstreamDownstreamAssociationId. The parameter is ignored for categories that have no per-relationship copies.
Limits
This endpoint is limited to 120 requests per 60 seconds per organization. Past that it returns 429 with aRetry-After header. See Rate Limiting.
Error Scenarios
Bad Request (400)
Returned whenfileDocumentId is not a valid MongoDB ObjectId, or the document has more than one relationship with your organization and upstreamDownstreamAssociationId is missing.
Document Not Found (404)
Returned when the document does not exist, is not yours, has been deleted, sits on a checklist item Turris keeps internal, orversionId is not one of its versions.
Too Many Requests (429)
Returned when the rate limit above is exceeded.Unauthorized (401)
Missing or invalid authentication token. See Authentication.Authorizations
bearerrestricted-access-token
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Unique identifier of the file document
Example:
"66a1b2c3d4e5f6a7b8c9d0e3"
Query Parameters
S3 version id of the version to download, from the document version history. Defaults to the latest version you see.
Example:
"Xo2f9mK1Qv.3a7b"
The downstream entity association whose copy to download. Needed only when a compliance document has more than one relationship with your organization; ignored for other categories.
Example:
"507f1f77bcf86cd799439011"
Was this page helpful?