album.downloadToken

bearer / PAT

Mint an owner album download link

Five-minute download_user token scoped to the caller, album, variant and current generation. Only currently ready private ZIPs qualify; every GET/HEAD reauthorizes. Never starts work.

Parameters

Passed by name in the params object.

Name Type Required Description
album_id string yes
variant string (enum) yes

Result

Returns downloadTokenResult:

Field Type Description
expires_at * string
url * string

Errors

Code Message When
2001 not_found No such resource owned by the caller.
2002 validation_failed Malformed request; see error.data.
2006 download_not_ready The authorized download is unavailable; see error.data.state and check download status before requesting a fresh link.

See the error reference for the full catalog, including the authentication codes.

Example

Request:

{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "album.downloadToken",
  "params": {
    "album_id": "018f3a80-1c2d-7e00-9a00-0b1c2d3e4f50",
    "variant": "screen"
  }
}

Response:

{
  "jsonrpc": "2.0",
  "id": 1,
  "result": {
    "url": "/api/v1/albums/018f3a80-1c2d-7e00-9a00-0b1c2d3e4f50/download?token=short-lived-scoped-token",
    "expires_at": "2026-10-05T12:05:00Z"
  }
}

curl

curl -s https://peinture.gumeniuk.com/rpc \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"album.downloadToken","params":{"album_id":"018f3a80-1c2d-7e00-9a00-0b1c2d3e4f50","variant":"screen"}}'

JavaScript

const res = await fetch("https://peinture.gumeniuk.com/rpc", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Authorization": `Bearer ${token}`,
  },
  body: JSON.stringify({
    jsonrpc: "2.0", id: 1, method: "album.downloadToken", params: {"album_id":"018f3a80-1c2d-7e00-9a00-0b1c2d3e4f50","variant":"screen"},
  }),
});
const { result, error } = await res.json();

Go

body := []byte(`{"jsonrpc":"2.0","id":1,"method":"album.downloadToken","params":{"album_id":"018f3a80-1c2d-7e00-9a00-0b1c2d3e4f50","variant":"screen"}}`)
req, _ := http.NewRequest("POST", "https://peinture.gumeniuk.com/rpc", bytes.NewReader(body))
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer "+token)
resp, err := http.DefaultClient.Do(req)

Try it

Sends a real request to /rpc from your browser. Paste a bearer token above — a JWT access token or a personal access token (pnt_…).