Skip to main content
Version: 1.28 (Current)

Download File

Audience: Low-code Engineers

Skill Prerequisites: APIs, Actions, Tokens

Returns a file as the response of an API endpoint. The caller receives the file's content, with a content type based on its extension and a file name. Browsers either download the file or show it, depending on Force Download.

It's only available in APIs. It ends the action list, so actions after it don't run.

By default, the action checks that the user calling the API can view the file's folder. The override options skip these checks. Use them with care.

Typical Use Cases​

  • Give users a secure download link for a file in a protected folder, for example /api/invoice?id=123
  • Return a file created earlier in the same API, for example with Generate PDF or Create Excel from List
  • Send a file with a friendlier name than the one on disk, for example Invoice-1024.pdf
  • Show a PDF or image in the browser instead of downloading it

Don't use it to​

Action NameDescription
File ResponseServes a file by its ID through the site's normal file handling, and supports response caching.
Raw ResponseReturns any text content, with your own status code and headers.
Generate PDFCreates a PDF and stores its file ID or path in tokens.
Create Excel from ListCreates an Excel file and stores its path in tokens.
Send File for DownloadSends a portal file for download from a form.

Which response action should I use?​

You want to returnUse
Plain text, HTML, XML or JSON you write yourselfRaw Response
A JSON object built from name/value pairsNew Object as JSON
One item of a list as JSONExisting Object as JSON
The items of a list as a JSON arrayExisting List as JSON
A file, with a file name, permission checks and a download or preview optionDownload File
A file by its ID, with response cachingFile Response

If no action returns a response, the API returns the text Success.

Input Parameter Reference​

The parameters unique to this action are listed below. Review the common parameters for all actions here.

ParameterDescriptionSupports TokensDefaultRequired
File IdentifierThe file to return. It can be a file ID, for example [FileId], or a path relative to the portal's home folder, for example Invoices/INV-1024.pdf. See File Identifier formats.Yesempty stringYes
New File Name (optional)The file name the caller receives, without the extension, for example Invoice-[InvoiceNumber]. The original file's extension is added automatically. If it's empty after tokens are replaced, the original file name is used.Yesempty stringNo
Override User Security ChecksSkips the folder permission check, so anyone who can call the API gets the file, even if they aren't logged in. The file must still be in the current portal.NofalseNo
Override Portal Security ChecksShown when Override User Security Checks is on. Meant to allow files from any portal's folder, using a path that starts with ~/Portals/. Not recommended. See Considerations.NofalseNo
Override Server Security ChecksShown when Override Portal Security Checks is on. Allows any file the web server can read, using a full disk path, for example C:\Files\report.pdf. Not recommended.NofalseNo
Force DownloadOn: the browser downloads the file. Off: the browser can show the file, for example a PDF or image, if it knows how.NotrueNo

File Identifier formats​

With the default security checks, or with only Override User Security Checks on, the file must be in the portal's file system. These formats work:

FormatExample
File ID1024
Path relative to the portal's home folderInvoices/INV-1024.pdf
Path that includes the portal's home folder/Portals/0/Invoices/INV-1024.pdf
Full URL of a file in the portalhttps://example.com/Portals/0/Invoices/INV-1024.pdf
LinkClick URLhttps://example.com/LinkClick.aspx?fileticket=...

When Override Server Security Checks is on too, and the file isn't found in the portal's file system, a full disk path is also accepted.

What the caller receives​

Part of the responseValue
Status code200
Content-TypeBased on the file extension, for example application/pdf. Unknown extensions get application/octet-stream.
Content-Dispositionattachment;filename="<name>" when Force Download is on, inline;filename="<name>" when it's off.
Content-LengthThe file size.
BodyThe file's content, sent in chunks.

Large files are streamed, and the request isn't stopped by the server's script timeout while the file is sent.

If something goes wrong, the file isn't sent and the API's error handling runs instead. This happens when:

  • File Identifier is empty after tokens are replaced
  • The file isn't found
  • The user doesn't have permission to view the file's folder. The message is Permissions are not met. The file cannot be downloaded.

Without On error actions, the caller gets an error response. See API overview.

Considerations​

  • Permissions. By default, the user calling the API needs View or Edit permission on the file's folder, and must not be denied View. For an anonymous API, that means the folder must allow the right roles, or you need Override User Security Checks.
  • Validate the input. If File Identifier comes from the request, for example [FileId], and you turn on an override, any caller can download any file you allow. Check the value first, for example with a Run SQL Query that confirms the file belongs to the user, and a condition on this action.
  • Portal and server overrides. These give access to files outside the portal, limited only by the web server's own permissions. Avoid them. In 1.28, paths that start with ~/ aren't resolved correctly, so use a full disk path if you must use Override Server Security Checks.
  • File name. Don't include the extension in New File Name. It's taken from the original file. For example, Report with data.xlsx gives Report.xlsx.
  • No caching. This response isn't cached, even when the API has Cache Response turned on. The actions run on every call.
  • Final action. Only the first final action that runs returns the response. Use conditions to choose between several responses.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Download an invoice by its file ID​

This action returns the file whose ID is in the FileId input parameter. It's saved as Invoice-<InvoiceNumber> with the original extension. The folder permissions of the calling user are checked.

{
"Title": "Download File",
"ActionType": "DownloadFileResponse",
"Description": "Return the invoice file",
"Condition": "[FileId] != \"\"",
"Parameters": {
"FileIdentifier": "[FileId]",
"NewFileName": "Invoice-[InvoiceNumber]",
"OverrideUserSecurity": false,
"OverridePortalSecurity": false,
"OverrideServerSecurity": false,
"ForceDownload": true
}
}

2. Show a PDF in the browser​

This action returns Documents/Terms.pdf from the portal's home folder. Force Download is off, so the browser can open the PDF in a tab. Override User Security Checks is on, so anonymous callers get the file too.

{
"Title": "Download File",
"ActionType": "DownloadFileResponse",
"Description": "Show the terms PDF",
"Parameters": {
"FileIdentifier": "Documents/Terms.pdf",
"NewFileName": "",
"OverrideUserSecurity": true,
"OverridePortalSecurity": false,
"OverrideServerSecurity": false,
"ForceDownload": false
}
}

Revised 09/27/2026