Begin download
Authorizes one direct read of a file’s content object and returns a short-lived presigned GET capability, the resolved revision, and the content reference the client checks the arriving bytes against. Range is outside the signature, so one grant serves ranged, resumed, and parallel reads. Deployments that cannot presign answer 501 not_supported; the proxied GET /filesystem/content route stays available and is capped by download.max_content_bytes.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”Namespace id
Request Body required
Section titled “Request Body required ”What a client names when it asks to read a file directly.
A path and, optionally, the revision it wants — the same two things the proxied content read takes, so a caller switching transports changes nothing about what it is asking for.
Responses
Section titled “ Responses ”Download authorized
A short-lived capability to read one file’s content object, plus everything the reader needs to check what arrives.
The raw object key is deliberately not here, exactly as it is not in a
direct_put grant: a client learns a URL that expires, not an address it
can revisit.
The grant names one immutable content object, so it does not go stale when the path moves on. A commit that replaces the file writes a new object and leaves this one alone; what the capability reads is what the requested revision held when the grant was issued, and the reference says which bytes those are.
object
Absolute path as rendered from stored display names.
Short-lived URL plus required headers for one object-store write.
object
Expiration timestamp in Unix milliseconds.
Headers that are covered by the signature and must be sent.
object
HTTP method the client must use.
Full presigned URL.
Identity, byte length, and checksum evidence for the object the
capability reads. A reader checks the bytes it receives against
size_bytes, and against whole_file_sha256 when the reference
carries one — a direct-multipart object never will, because nobody
ever hashed it with SHA-256.
object
Immutable identity of the referenced object.
Content strategy used by the referenced object.
Complete byte length of the referenced content.
Mandatory checksum over the complete object, used to verify the stored bytes against this reference without downloading them.
object
Algorithm that produced value.
Lowercase hex of the raw checksum bytes.
The algorithm is its own field, so the value carries no prefix. Provider APIs that report base64 are converted at the adapter.
SHA-256 over the complete payload, lowercase hex, when a trusted party computed it.
Present means the LoonFS write path hashed the whole stream itself, or a provider validated a signed whole-object SHA-256 on the write. There are no client-claimed digests: absent means nobody trustworthy hashed these bytes, never “the client did not tell us”.
Namespace that was read.
Revision the capability reads, resolved from the request.
Invalid path or revision
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Unauthorized
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Namespace, path, or revision not found
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Namespace deleted
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.
Direct download is unsupported
HTTP error body used by LoonFS APIs.
object
Stable machine-readable reason from the ErrorCode
registry.
Carried as a string so clients keep working when a newer server
introduces a code they do not know; use
ErrorCode::parse for typed access.
Structured context for the code, present when the failure carries machine-usable identity (API spec, “Standard error contract”). Boxed so the rare detailed error does not widen every error-carrying result.
object
Unix milliseconds at which the current epoch’s acquirer took it, when the head recorded one. Writer ids are process labels, so two runs on one machine can share one; the stamp is what tells them apart.
Writer id recorded by the current epoch’s acquirer, when the head recorded one.
Sequence at which that commit id already landed. Present when the failure was decided against a durable commit receipt, which is what holds the sequence; absent when nothing has committed under the id yet and two live requests are simply claiming it at once.
Position, in the request’s operation list, of the operation that failed. A commit applies all of its operations or none of them, so this names the one that stopped the whole request.
For not_supported errors, the capability-document feature key the
client should reconcile against.
Human-readable error message.
Correlation id the server assigned to the failed request; the same
value is sent as the x-request-id response header.