> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sparkles.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Download a sandbox file

> Streams the raw bytes of one working-tree file from a running sandbox as an attachment. The bytes are read over the sandbox ACP connection, so the sandbox must be running with a live agent connection. Files above 100 MiB, protected files such as .env and opencode.json, and .git contents are refused.



## OpenAPI

````yaml /openapi.json get /api/public/v1/sandboxes/{sandboxId}/files/download
openapi: 3.1.0
info:
  title: Sparkles Sandbox API
  version: 1.0.0
  description: Create coding sandboxes, stream their work, and control their lifecycle.
servers:
  - url: https://sparkles.dev
security: []
paths:
  /api/public/v1/sandboxes/{sandboxId}/files/download:
    get:
      tags:
        - sandbox files
      summary: Download a sandbox file
      description: >-
        Streams the raw bytes of one working-tree file from a running sandbox as
        an attachment. The bytes are read over the sandbox ACP connection, so
        the sandbox must be running with a live agent connection. Files above
        100 MiB, protected files such as .env and opencode.json, and .git
        contents are refused.
      operationId: downloadSandboxFile
      parameters:
        - in: path
          name: sandboxId
          schema:
            type: string
            pattern: ^c_[a-z2-9]{12}$
          required: true
        - in: query
          name: path
          schema:
            type: string
            minLength: 1
            maxLength: 1000
          required: true
        - in: query
          name: repo
          schema:
            type: string
            maxLength: 201
            pattern: ^[A-Za-z0-9._-]+\/[A-Za-z0-9._-]+$
      responses:
        '200':
          description: The file bytes, delivered as an attachment
          headers:
            Content-Disposition:
              required: true
              description: attachment with the file basename, RFC 5987 encoded when needed
              schema:
                type: string
                description: >-
                  attachment with the file basename, RFC 5987 encoded when
                  needed
            Content-Length:
              required: true
              description: File size in bytes
              schema:
                type: string
                description: File size in bytes
            Content-Type:
              required: true
              description: >-
                Media type reported by the sandbox, else
                application/octet-stream
              schema:
                type: string
                description: >-
                  Media type reported by the sandbox, else
                  application/octet-stream
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
        '400':
          description: The file path or repository selector failed validation
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '401':
          description: Missing, malformed, revoked, or otherwise invalid API key
          headers:
            WWW-Authenticate:
              required: true
              description: Bearer authentication challenge for the Sparkles Sandbox API
              schema:
                type: string
                description: Bearer authentication challenge for the Sparkles Sandbox API
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '403':
          description: >-
            The API key lacks the sandboxes scope or its user is no longer an
            active organization member
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '404':
          description: Sandbox, repository, or file not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '409':
          description: Sandbox files or the agent connection are not available yet
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '413':
          description: The file exceeds the 100 MiB download limit
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '429':
          description: The API key exceeded its distributed per-minute request limit
          headers:
            Retry-After:
              required: true
              description: Seconds until another request may be made
              schema:
                type: string
                pattern: ^\d+$
                description: Seconds until another request may be made
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '500':
          description: The request could not be completed because of an internal error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '501':
          description: The sandbox daemon does not support file downloads
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '502':
          description: The sandbox command runtime is unavailable
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
      security:
        - apiKey: []
components:
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: spk_live_…
      description: >-
        Long-lived opaque API key minted by an approved user at /api. The secret
        is shown once, stored only as a SHA-256 digest, and disabled immediately
        when either the key or its API access grant is revoked.

````