# get_storage_file_url

Source: https://modulify.ai/docs/api/storage/get-storage-file-url

Returns a link to one stored file so it can be opened or downloaded.

- Title: Get a link to a stored file
- Scope: `data:read`
- Access: Read only
- Endpoint: `POST /v1/get_storage_file_url`

For a public file it returns the permanent public CDN address by default, or, with `download` set to true, a signed link that forces a save-as. That signed link needs no login and stays valid for 7 days, so treat it as a shareable secret.

A private file never has a public address: both modes return a signed link that expires after 15 minutes, for opening the file now rather than embedding it in a page. On a site whose CDN has not finished being provisioned, a public file also comes back as a signed link valid for 7 days.

Pass the full key exactly as `list_storage_files` returned it, not just the filename, since a key with no file behind it is refused with a `404`. Files in the `CMS` folder at the top level, which the CMS manages, get a link like any other, and the tool keeps working while a storage backup is being restored. See [Public and private](https://modulify.ai/docs/data/storage#public-and-private).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/get_storage_file_url`, sending the inputs below as a JSON object. The token needs the `data:read` scope.

It only reads and changes nothing, so retrying it is safe.

```bash
curl -X POST https://api.modulify.ai/v1/get_storage_file_url \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","key":"KEY"}'
```

Over MCP, the same method is the [get_storage_file_url tool](https://modulify.ai/docs/mcp/storage/get-storage-file-url).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `key` | string | Yes | The full key of the file, from `list_storage_files`. |
| `download` | boolean | No | True for a temporary signed download link instead of the public CDN address. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.