---
title: "Get attachment metadata"
method: GET
path: "/rest/api/3/attachment/{id}"
tags: ["Issue attachments"]
---

# Get attachment metadata

`GET /rest/api/3/attachment/{id}`

Returns the metadata for an attachment. Note that the attachment itself is not returned.

This operation can be accessed anonymously.

**[Permissions](#permissions) required:**

 *  *Browse projects* [project permission](https://confluence.atlassian.com/x/yodKLg) for the project that the issue is in.
 *  If [issue-level security](https://confluence.atlassian.com/x/J4lKLg) is configured, issue-level security permission to view the issue.
 *  If attachments are added in private comments, the comment-level restriction will be applied.

## Path parameters

- `id` string, required

## Response `200`

Returned if the request is successful.

- AttachmentMetadata — Metadata for an issue attachment.
  - `author` User — A user with details as permitted by the user's Atlassian Account privacy settings. However, be aware of these exceptions: * User record deleted from Atlassian: This occurs as the result of a right to be forgotten request. In this case, `displayName` provides an indication and other parameters have default values or are blank (for example, email is blank). * User record corrupted: This occurs as a results of events such as a server import and can only happen to deleted users. In this case, `accountId` returns *unknown* and all other parameters have fallback values. * User record unavailable: This usually occurs due to an internal service outage. In this case, all parameters have fallback values.
    - `accountId` string — The account ID of the user, which uniquely identifies the user across all Atlassian products. For example, *5b10ac8d82e05b22cc7d4ef5*. Required in requests.
    - `accountType` 'atlassian' | 'app' | 'customer' | 'unknown' — The user account type. Can take the following values: * `atlassian` regular Atlassian user account * `app` system account used for Connect applications and OAuth to represent external systems * `customer` Jira Service Desk account representing an external service desk
    - `active` boolean — Whether the user is active.
    - `appType` string — The app type of the user account when accountType is 'app'. Can take the following values: * `service` Service Account * `agent` Rovo Agent Account * `unknown` Unknown app type
    - `applicationRoles` SimpleListWrapperApplicationRole
      - `callback` ListWrapperCallbackApplicationRole
      - `items` ApplicationRole[]
        - `defaultGroups` string[] — The groups that are granted default access for this application role. As a group's name can change, use of `defaultGroupsDetails` is recommended to identify a groups.
        - `defaultGroupsDetails` GroupName[] — The groups that are granted default access for this application role.
          - `groupId` string, nullable — The ID of the group, which uniquely identifies the group across all Atlassian products. For example, *952d12c3-5b5b-4d04-bb32-44d383afc4b2*.
          - `name` string — The name of group.
          - `self` string, uri — The URL for these group details.
        - `defined` boolean — Deprecated.
        - `groupDetails` GroupName[] — The groups associated with the application role.
          - `groupId` string, nullable — The ID of the group, which uniquely identifies the group across all Atlassian products. For example, *952d12c3-5b5b-4d04-bb32-44d383afc4b2*.
          - `name` string — The name of group.
          - `self` string, uri — The URL for these group details.
        - `groups` string[] — The groups associated with the application role. As a group's name can change, use of `groupDetails` is recommended to identify a groups.
        - `hasUnlimitedSeats` boolean
        - `key` string — The key of the application role.
        - `name` string — The display name of the application role.
        - `numberOfSeats` integer — The maximum count of users on your license.
        - `platform` boolean — Indicates if the application role belongs to Jira platform (`jira-core`).
        - `remainingSeats` integer — The count of users remaining on your license.
        - `selectedByDefault` boolean — Determines whether this application role should be selected by default on user creation.
        - `userCount` integer — The number of users counting against your license.
        - `userCountDescription` string — The [type of users](https://confluence.atlassian.com/x/lRW3Ng) being counted against your license.
      - `max-results` integer
      - `pagingCallback` ListWrapperCallbackApplicationRole
      - `size` integer
    - `avatarUrls` AvatarUrlsBean
      - `16x16` string, uri — The URL of the item's 16x16 pixel avatar.
      - `24x24` string, uri — The URL of the item's 24x24 pixel avatar.
      - `32x32` string, uri — The URL of the item's 32x32 pixel avatar.
      - `48x48` string, uri — The URL of the item's 48x48 pixel avatar.
    - `displayName` string — The display name of the user. Depending on the user’s privacy setting, this may return an alternative value.
    - `emailAddress` string — The email address of the user. Depending on the user’s privacy setting, this may be returned as null.
    - `expand` string — Expand options that include additional user details in the response.
    - `groups` SimpleListWrapperGroupName
      - `callback` ListWrapperCallbackGroupName
      - `items` GroupName[]
        - `groupId` string, nullable — The ID of the group, which uniquely identifies the group across all Atlassian products. For example, *952d12c3-5b5b-4d04-bb32-44d383afc4b2*.
        - `name` string — The name of group.
        - `self` string, uri — The URL for these group details.
      - `max-results` integer
      - `pagingCallback` ListWrapperCallbackGroupName
      - `size` integer
    - `guest` boolean — Whether the user is a guest.
    - `key` string — This property is no longer available and will be removed from the documentation soon. See the [deprecation notice](https://developer.atlassian.com/cloud/jira/platform/deprecation-notice-user-privacy-api-migration-guide/) for details.
    - `locale` string — The locale of the user. Depending on the user’s privacy setting, this may be returned as null.
    - `name` string — This property is no longer available and will be removed from the documentation soon. See the [deprecation notice](https://developer.atlassian.com/cloud/jira/platform/deprecation-notice-user-privacy-api-migration-guide/) for details.
    - `self` string, uri — The URL of the user.
    - `timeZone` string — The time zone specified in the user's profile. If the user's time zone is not visible to the current user (due to user's profile setting), or if a time zone has not been set, the instance's default time zone will be returned.
  - `content` string — The URL of the attachment.
  - `created` string, date-time — The datetime the attachment was created.
  - `filename` string — The name of the attachment file.
  - `id` integer — The ID of the attachment.
  - `mimeType` string — The MIME type of the attachment.
  - `properties` object — Additional properties of the attachment.
  - `self` string, uri — The URL of the attachment metadata details.
  - `size` integer — The size of the attachment.
  - `thumbnail` string — The URL of a thumbnail representing the attachment.

## Other responses

- `401` — Returned if the authentication credentials are incorrect or missing.
- `403` — Returned if the user does not have the necessary permission.
- `404` — Returned if: * the attachment is not found. * attachments are disabled in the Jira settings.

---

[API](https://skmtc.net/atlassian/apis/the-jira-cloud-platform-rest-api-2.md) · [All operations](https://skmtc.net/atlassian/apis/the-jira-cloud-platform-rest-api-2/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/atlassian/the-jira-cloud-platform-rest-api-2/versions/5a51740d7ab3/schema)
