image.downloadToken

bearer / PAT

Mint an owner photo download link

Five-minute download_user token scoped to the caller, photo, current album membership, variant, exact screen rendition and current generation. Every GET/HEAD rechecks current ownership and availability. Never starts work.

Parameters

Passed by name in the params object.

Name Type Required Description
id string yes
variant string (enum) yes
crop string no
spec integer no

Result

Returns downloadTokenResult:

Field Type Description
expires_at * string
url * string

Errors

Code Message When
2001 not_found No such resource owned by the caller.
2002 validation_failed Malformed request; see error.data.
2006 download_not_ready The authorized download is unavailable; see error.data.state and check download status before requesting a fresh link.

See the error reference for the full catalog, including the authentication codes.

Example

Request:

{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "image.downloadToken",
  "params": {
    "id": "018f3a7d-2b8c-7f1a-a4d5-6e7f8a9b0c1d",
    "variant": "full"
  }
}

Response:

{
  "jsonrpc": "2.0",
  "id": 1,
  "result": {
    "url": "/api/v1/images/018f3a7d-2b8c-7f1a-a4d5-6e7f8a9b0c1d/download?token=short-lived-scoped-token",
    "expires_at": "2026-10-05T12:05:00Z"
  }
}

curl

curl -s https://peinture.gumeniuk.com/rpc \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"image.downloadToken","params":{"id":"018f3a7d-2b8c-7f1a-a4d5-6e7f8a9b0c1d","variant":"full"}}'

JavaScript

const res = await fetch("https://peinture.gumeniuk.com/rpc", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Authorization": `Bearer ${token}`,
  },
  body: JSON.stringify({
    jsonrpc: "2.0", id: 1, method: "image.downloadToken", params: {"id":"018f3a7d-2b8c-7f1a-a4d5-6e7f8a9b0c1d","variant":"full"},
  }),
});
const { result, error } = await res.json();

Go

body := []byte(`{"jsonrpc":"2.0","id":1,"method":"image.downloadToken","params":{"id":"018f3a7d-2b8c-7f1a-a4d5-6e7f8a9b0c1d","variant":"full"}}`)
req, _ := http.NewRequest("POST", "https://peinture.gumeniuk.com/rpc", bytes.NewReader(body))
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer "+token)
resp, err := http.DefaultClient.Do(req)

Try it

Sends a real request to /rpc from your browser. Paste a bearer token above — a JWT access token or a personal access token (pnt_…).