curl --request GET \
--url https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"enabled": true,
"max_files_per_message": 123,
"max_bytes_per_file": 123,
"max_bytes_per_message": 123,
"max_attachments_per_conversation": 123,
"max_files_per_folder": 123,
"unwrap_archives": true,
"accepted_extensions": [
"<string>"
],
"retention_days": 123
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "unauthorized",
"message": "Missing or invalid API key"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "rate_limited",
"message": "Rate limit exceeded"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "auth_unavailable",
"message": "API key authentication is temporarily unavailable"
}{
"code": "request_timeout",
"message": "Request timed out"
}Get the attachment policy
Read the upload limits and accepted extensions the instance’s published config enforces.
curl --request GET \
--url https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.usenexio.com/api/v1/conversation-instances/{instance_slug}/conversations/{conversation_id}/attachments/policy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"enabled": true,
"max_files_per_message": 123,
"max_bytes_per_file": 123,
"max_bytes_per_message": 123,
"max_attachments_per_conversation": 123,
"max_files_per_folder": 123,
"unwrap_archives": true,
"accepted_extensions": [
"<string>"
],
"retention_days": 123
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "unauthorized",
"message": "Missing or invalid API key"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "rate_limited",
"message": "Rate limit exceeded"
}{
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}{
"code": "auth_unavailable",
"message": "API key authentication is temporarily unavailable"
}{
"code": "request_timeout",
"message": "Request timed out"
}Authorizations
Send the key as Authorization: Bearer <key>. Two kinds of key exist.
Organization keys are issued in the portal (Settings, then API keys),
each bound to one environment, shaped nx_<environment slug>_<64 hex>. They carry
no capabilities and pass every capability check, with one exception:
routes under /api/v1/records, /api/v1/engines/{id}/opportunities,
/api/v1/graph and /api/v1/catalog/documents accept an
organization key only when its environment is live, and refuse any
other with 403 scoped_key_required. Revocation takes effect within 60
seconds.
Scoped keys are issued by Nexio on request, shaped
nxsk_v1_<24 hex key id>_<43 character secret>. Each is bound to one
org, one environment, a set of engines and a set of capabilities. A
malformed, unknown or revoked nxsk_ key fails with 401 and is never
retried as an organization key. Revocation takes effect on the next
request. A scoped key without a route's capability gets 403
insufficient_capability; a scoped key not bound to the engine gets 403
engine_binding_forbidden.
Key-grantable capabilities: engines:read, runs:write, runs:read,
runs:defensibility:read, runs:test, catalog:read,
catalog:documents:read, webhooks:manage, conversations:use,
conversations:export, records:read, records:opportunities:run,
actions:write, actions:read, graph:read, records:analyze.
Routes that accept organization keys only (every scoped key gets 403
insufficient_capability): environment management, engine create,
update, configuration and publish, and conversation instance
authoring. Each operation description names the capability a scoped
key needs.
Path Parameters
Conversation instance identifier slug (e.g. platform-assistant).
Query Parameters
The asserted end-user identity the conversation must belong to.
Response
The resolved policy.
The upload policy resolved from the instance's latest published config.
Always true on a 200; a disabled instance answers attachments_not_enabled.
Attachments one message may carry. A folder, zip, or email counts as one.
Per-file limit in raw bytes. At most 39321600.
Combined limit for one message, measured on the base64-encoded size (52428800).
Live attachments one conversation may hold, container contents included (100).
Files one folder may carry (25).
Whether .zip and .eml containers are accepted and opened.
Accepted file extensions with the leading dot, sorted.
Days files are kept; null follows the conversation's retention.