> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Read one file a transcript row carried

> The bytes of one picture or converted document a session's transcript names, addressed by the mediaKey on an Entry.attachments record. This is the ONLY road to them: the transcript read carries what a picture IS and never any of it, so a client that wants to draw one asks here.
It serves bytes rather than a path on purpose. The client may be on another machine than the engine, where a path names nothing — and even on one machine a path would invite a client to read a directory the host owns.
The key is resolved through the TRANSCRIPT that names it, not by joining it onto a directory. So a key this session's conversation does not carry is a 404 whether or not a file of that name exists: one conversation's picture is not another's, and a home holds every session's media beside the database. The refusal says nothing else — there is no distinction to draw between "no such file" and "not yours", and drawing one would answer questions nobody may ask.
Immutable once written, so the response may be cached for as long as the client likes. narya session purge destroys a conversation's media with it, after which its own keys answer 404.



## OpenAPI

````yaml /en/openapi/v3-current/narya.yaml get /v1/sessions/{sessionId}/media/{mediaKey}
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    runs on your machine and serves this API over a Unix socket in your Narya
    home. Narya creates the socket owner-only, and file permissions are the
    whole authorization. There is no password, no token and no TLS. The terminal
    client and the one-shot command that Lerian ships drive this API, and a
    client you write drives the same one.


    Results never arrive on the response of the request that caused them.
    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title, message, and fields on 422. Codes are NRY-
    followed by four digits. A paged list answers items, limit and a nextCursor
    when more remains. Cursors are opaque.
servers: []
security: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
paths:
  /v1/sessions/{sessionId}/media/{mediaKey}:
    parameters:
      - $ref: '#/components/parameters/SessionIdParam'
      - $ref: '#/components/parameters/MediaKeyParam'
    get:
      tags:
        - sessions
      summary: Read one file a transcript row carried
      description: >-
        The bytes of one picture or converted document a session's transcript
        names, addressed by the mediaKey on an Entry.attachments record. This is
        the ONLY road to them: the transcript read carries what a picture IS and
        never any of it, so a client that wants to draw one asks here.

        It serves bytes rather than a path on purpose. The client may be on
        another machine than the engine, where a path names nothing — and even
        on one machine a path would invite a client to read a directory the host
        owns.

        The key is resolved through the TRANSCRIPT that names it, not by joining
        it onto a directory. So a key this session's conversation does not carry
        is a 404 whether or not a file of that name exists: one conversation's
        picture is not another's, and a home holds every session's media beside
        the database. The refusal says nothing else — there is no distinction to
        draw between "no such file" and "not yours", and drawing one would
        answer questions nobody may ask.

        Immutable once written, so the response may be cached for as long as the
        client likes. narya session purge destroys a conversation's media with
        it, after which its own keys answer 404.
      operationId: getSessionMedia
      responses:
        '200':
          description: The stored file, with the media type the transcript recorded for it.
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
        '400':
          $ref: '#/components/responses/BadRequest'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    SessionIdParam:
      name: sessionId
      in: path
      required: true
      description: The session's id.
      schema:
        type: string
        format: uuid
    MediaKeyParam:
      name: mediaKey
      in: path
      required: true
      description: >-
        The name EntryAttachment.mediaKey carries, addressing one stored file
        inside one session's media directory. It travels as a single path
        segment and its shape is bounded to what a path segment carries
        unchanged, for MonitorNameParam's reason: a "/" would address no route,
        and a "?" or "#" would end the segment early. The host composes these
        names itself when it stores the bytes, so no key that exists can fail to
        be addressed here — and a key outside this shape did not come from a
        transcript this host wrote.
      schema:
        type: string
        minLength: 1
        maxLength: 128
        pattern: ^[A-Za-z0-9_][A-Za-z0-9._-]*$
  responses:
    BadRequest:
      description: Malformed request — invalid parameter, cursor, or JSON body.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The addressed resource does not exist on this host.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension. fields appears only on 422 validation errors,
        mapping each offending property to its problem.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems. Present on 422 only.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.

````