agency-board
PATCH /v1/agency/boards/{boardId}/cards/{cardId}/attachments/{attachmentId}
Choose whether the client can see this file.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X PATCH https://api.zinndigital.com/v1/agency/boards/{boardId}/cards/{cardId}/attachments/{attachmentId} \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "visibility": <AgencyBoardVisibility> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
boardId (path) | Uuid | Yes | Project board ID (UUIDv7). |
cardId (path) | Uuid | Yes | Board card ID (UUIDv7). |
attachmentId (path) | Uuid | Yes | Board card attachment ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
visibility | AgencyBoardVisibility | Yes | Who may see this object. `internal` is always the default. A **card** reaches the client only when it is `client` **and its column is too** — an AND, not inheritance, because th… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
card_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
filename | string | Yes | — |
content_type | string | No | — |
size_bytes | integer | Yes | — |
visibility | AgencyBoardVisibility | No | Who may see this object. `internal` is always the default. A **card** reaches the client only when it is `client` **and its column is too** — an AND, not inheritance, because th… |
scan_state | AgencyBoardAttachmentScanState | Yes | Where an uploaded file is in the malware pipeline. ⛔ `clean` is the ONLY state the bytes are ever served in — `pending`, `infected` and `error` all refuse, including to the agen… |
downloadable | boolean | Yes | ⭐ Whether these bytes may be fetched right now. Computed from the scan state by the engine rather than derived by a caller — two copies of "may this leave the building" is how t… |
uploaded_by | AgencyBoardActor | No | — |
created_at | string | No | — |
Errors this endpoint can return
401 · 403 · 404 · 422