# `GET /v1/sessions/{sessionId}/files` — List published files

Part of the [Bkper Managed Agent API](https://bkper.com/docs/api/managed-agent.md). Read its guide for authentication, conventions, and examples.

Files this session published, newest first.

## Operation contract

```json
{
  "operationId": "listFiles",
  "tags": [
    "Files"
  ],
  "summary": "List published files",
  "security": [
    {
      "bearerAuth": []
    }
  ],
  "parameters": [
    {
      "name": "sessionId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "cursor",
      "in": "query",
      "schema": {
        "type": "string"
      }
    }
  ],
  "description": "Files this session published, newest first.",
  "responses": {
    "200": {
      "description": "Success",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/FileList"
          }
        }
      }
    },
    "400": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "401": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "403": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "404": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "409": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "410": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "411": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "413": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    },
    "503": {
      "description": "Rejected; never contains credentials or upstream payloads.",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Error"
          }
        }
      }
    }
  }
}
```

## Schemas

### FileList

```json
{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "origin": {
            "type": "string",
            "description": "Uploaded by the user, or published by the agent. Open: upload | publish."
          },
          "sessionId": {
            "description": "The session that published it. Absent on uploads, which belong to the user.",
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "mediaType": {
            "type": "string",
            "description": "Published: the allowlisted type for its name. Uploaded: as declared by the uploader, unverified. Downloads always use the allowlisted type for the name; anything else is application/octet-stream."
          },
          "size": {
            "type": "number",
            "description": "Bytes."
          },
          "sha256": {
            "type": "string",
            "description": "Hex SHA-256 of the content."
          },
          "createdAt": {
            "type": "string",
            "pattern": "^\\d+$",
            "description": "Milliseconds since the epoch, as a string."
          },
          "createdBy": {
            "type": "string"
          },
          "expiresAt": {
            "type": "string",
            "pattern": "^\\d+$",
            "description": "When the stored copy is deleted, 30 days after creation. Then downloads are 410 file_gone."
          }
        },
        "required": [
          "id",
          "origin",
          "name",
          "mediaType",
          "size",
          "sha256",
          "createdAt",
          "createdBy",
          "expiresAt"
        ],
        "description": "An immutable private copy of a file, kept for 30 days. Only its owner can read or download it."
      }
    },
    "cursor": {
      "type": "string"
    }
  },
  "required": [
    "items"
  ]
}
```

### Error

```json
{
  "type": "object",
  "properties": {
    "error": {
      "type": "object",
      "properties": {
        "code": {
          "type": "string",
          "description": "Stable code, e.g. not_found, idempotency_conflict, session_working, usage_limit_exceeded. Open."
        },
        "type": {
          "description": "Category, e.g. invalid_request_error, authentication_error, usage_limit_error. Open.",
          "type": "string"
        },
        "message": {
          "type": "string"
        }
      },
      "required": [
        "code"
      ]
    }
  },
  "required": [
    "error"
  ]
}
```

## Authentication

```json
{
  "bearerAuth": {
    "type": "http",
    "scheme": "bearer"
  }
}
```
