# GET /v1/orders/{orderId}/attachments

**Service:** Orders  
**Operation:** `OrderService_ListAttachments`

Returns every file on the order's conversation as a flat list, oldest first: files your team attached and documents the Factory app generated (`isGenerated` distinguishes them). Each attachment carries a presigned download URL. Signature captures collected in the app are not returned.

## Parameters

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orderId` | path | string | yes | The id of the order whose attachments to list. Required. |
| `pageSize` | query | integer | no | Maximum number of attachments to return per page. 0 uses the server default; the server may cap the value. |
| `pageToken` | query | string | no | Opaque page token from a previous response, used to fetch the next page. |
| `fields` | query | string | no | Comma-separated response fields to include, using camelCase JSON names (e.g. `orderId,total.amountMicros`). Dot paths reach into nested objects and map transparently across arrays. Paths are relative to the resource, not the response envelope; envelope keys like `nextPageToken` are always preserved. Only 2xx JSON responses are filtered; error bodies pass through unmodified. Unknown names are silently ignored. Takes precedence over `excludeFields` when both are provided. |
| `excludeFields` | query | string | no | Comma-separated response fields to exclude, using camelCase JSON names. Dot paths and array-transparency work the same as `fields`. Paths are relative to the resource, not the response envelope. Only 2xx JSON responses are filtered; error bodies pass through unmodified. Ignored when `fields` is also provided. |

## Responses

| Status | Schema | Description |
| --- | --- | --- |
| 200 | `salesordersListAttachmentsResponse` | A successful response. |
| 400 | `Error` | The request was rejected because it failed validation. The body is a validation-failure envelope: an overall type and message and one entry per field-level problem (each with a stable code, a message, and a param pointing at the offending field). |
| 401 | `Error` | The request is missing a valid bearer token, or the token is invalid or expired. |
| 403 | `Error` | The token is valid but does not permit this action, or the resource belongs to a company the token cannot act for. The error type is permission_denied. |
| 404 | `Error` | No order with the given id exists for the authenticated company, or the document is still a quote — read its conversation with the QuoteService endpoint, swapping the id's order_ prefix for quote_ (the 26-character suffix stays the same). |
| 429 | `Error` | The request was throttled (rate_limited) or exceeded a size limit (resource_exhausted). When throttled, the Retry-After header says how many seconds to wait before retrying; a resource_exhausted request will fail the same way if retried unchanged. |
| default | `Error` | Any other error. The body is the same error envelope every error uses: a short stable type identifying the kind of failure (for example "rate_limited" or "internal"), a human-readable message, and the request's idempotency key echoed back when one was supplied. |

## Returns

`salesordersListAttachmentsResponse`

| Field | Type | Description |
| --- | --- | --- |
| `attachments` | Attachment[] | The attachments in this page, oldest first. |
| `attachments.id` | string | The id of this attachment. Use it to retrieve or delete the attachment. |
| `attachments.messageId` | string | The id of the conversation message this attachment belongs to. |
| `attachments.filename` | string | The file's name, as uploaded. |
| `attachments.contentType` | string | The file's media type (for example `image/png` or `application/pdf`). |
| `attachments.sizeBytes` | string | The file's size in bytes, rounded to kilobyte precision. Files smaller than one kilobyte read as 0. |
| `attachments.url` | string | A presigned URL to download the file. The URL expires; re-read the attachment for a fresh one rather than storing it. |
| `attachments.thumbnailUrl` | string | A presigned URL to a small preview image, for image attachments. Empty when no preview exists. Expires like `url`. |
| `attachments.isGenerated` | boolean | True when this file is a document the Factory app generated (for example a quote or invoice PDF) rather than a file somebody uploaded. Generated documents cannot be deleted through this API. |
| `attachments.generatedType` | string | For generated documents, the kind of document (for example `quote` or `invoice`). Not a fixed list; new kinds may appear. Empty for uploaded files. |
| `nextPageToken` | string | Token to pass as `pageToken` to fetch the next page; empty when there are no more results. |

---

Source: https://developer.factory.app/reference/orders/list-attachments · Factory Sales API v1
