Create a document link
HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("http://localhost:8080/v2/documents/example/links")) .header("Authorization", "Bearer <token>") .header("Content-Type", "application/json") .method("POST", HttpRequest.BodyPublishers.ofString("{ \"timeToLive\": 600000 }")) .build();HttpResponse<String> response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());System.out.println(response.body());const url = 'http://localhost:8080/v2/documents/example/links';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"timeToLive":600000}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:8080/v2/documents/example/links \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "timeToLive": 600000 }'Answers a URL that downloads the document without a credential until
expiresAt. timeToLive is in milliseconds (default one hour, at
most seven days). With the S3 store the URL is a pre-signed URL of the
bucket. With the memory and local stores it is an engine URL under
/document-links/, signed with a key of the engine; it names the
tenant, the document and the expiry, and any change to it is refused.
The same rules as for a download decide 404.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”The document’s id, from its reference.
Query Parameters
Section titled “Query Parameters”The store id from the reference (in-memory, local or s3). Another value answers 404 (400 on an upload).
The content hash from the reference. A different hash answers 404.
Header Parameters
Section titled “Header Parameters”Tenant selection. A principal bound to one tenant may omit it; if
sent, it must equal that tenant (403 otherwise). A principal that
may act in several tenants must send it on every request:
without it the request is refused with 400, and a tenant it may
not act in is refused with 403.
Request Body
Section titled “Request Body”object
How long the link works, in milliseconds.
Example
{ "timeToLive": 600000}Responses
Section titled “ Responses ”The link.
object
Examplegenerated
{ "url": "example", "expiresAt": "2026-04-15T12:00:00Z"}The request is malformed, or it uses a property or filter this release does not support.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:invalid-argument", "title": "Bad Request", "status": 400, "detail": "entity key must be a positive int64 string", "instance": "/v2/process-instances/0"}No valid credential was presented.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:unauthorized", "title": "Unauthorized", "status": 401, "detail": "A valid bearer credential is required", "instance": "/v2/documents/2251799813685262/links"}Headers
Section titled “Headers”The caller lacks the required permission, a tenant named in the request is not the caller’s tenant, or a cookie write has no valid CSRF token.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:forbidden", "title": "Forbidden", "status": 403, "detail": "The principal lacks the action this route requires", "instance": "/v2/documents/2251799813685262/links"}The entity does not exist in the caller’s tenant.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:not-found", "title": "Not Found", "status": 404, "detail": "The requested resource does not exist", "instance": "/v2/documents/2251799813685262/links"}The body exceeds the configured request-size bound.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:payload-too-large", "title": "Payload Too Large", "status": 413, "detail": "The request exceeds the configured size limit", "instance": "/v2/documents/2251799813685262/links"}An internal failure. The details are never exposed.
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:internal", "title": "Internal Server Error", "status": 500, "detail": "The request could not be completed", "instance": "/v2/documents/2251799813685262/links"}No document store is configured on this engine (problem type urn:bpm:error:document-store-not-configured).
An RFC 9457 problem document. type is a stable TinyConductor URN.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:mode-not-supported", "title": "Mode Not Supported", "status": 501, "detail": "POST /v2/documents/{documentId}/links is not supported in embedded mode", "instance": "/v2/documents/2251799813685262/links", "mode": "embedded"}