> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentscope.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For AgentScope Python, use https://docs.agentscope.io/stable/en/index for new projects. For existing projects, check the installed agentscope version and use matching versioned documentation.
> The /latest/ alias points to development documentation. Use it only with the matching development source. Do not mix AgentScope 1.x and 2.x APIs.
> State the AgentScope version when providing installation commands or code examples. ReMe uses its own continuously updated /reme/latest/ documentation.

# Mint a short-lived token for a browser-native fetch

> Mint a token so a browser can fetch the raw file directly.

``<iframe>`` PDF previews, ``<img>`` tags and click-to-download
navigations carry no custom headers, so they cannot present
``X-User-ID``; the token rides in the URL instead and is bound to
exactly this document.

Args:
    knowledge_base_id (`str`):
        The parent knowledge base.
    document_id (`str`):
        The document the token authorizes.
    user_id (`str`):
        Injected authenticated user ID.
    service (`KnowledgeBaseService`):
        Injected knowledge base service — resolved here only to
        fail early with a proper 404 instead of a raw error page
        on the browser navigation.
    download_secret (`str`):
        Injected app-wide signing secret.

Returns:
    `DocumentDownloadTokenResponse`:
        The token and its expiry.



## OpenAPI

````yaml /en/versions/2.0.9/deploy/openapi.json post /knowledge_bases/{knowledge_base_id}/documents/{document_id}/download_token
openapi: 3.1.0
info:
  title: AgentScope
  version: 2.0.9
servers: []
security: []
paths:
  /knowledge_bases/{knowledge_base_id}/documents/{document_id}/download_token:
    post:
      tags:
        - knowledge_bases
      summary: Mint a short-lived token for a browser-native fetch
      description: |-
        Mint a token so a browser can fetch the raw file directly.

        ``<iframe>`` PDF previews, ``<img>`` tags and click-to-download
        navigations carry no custom headers, so they cannot present
        ``X-User-ID``; the token rides in the URL instead and is bound to
        exactly this document.

        Args:
            knowledge_base_id (`str`):
                The parent knowledge base.
            document_id (`str`):
                The document the token authorizes.
            user_id (`str`):
                Injected authenticated user ID.
            service (`KnowledgeBaseService`):
                Injected knowledge base service — resolved here only to
                fail early with a proper 404 instead of a raw error page
                on the browser navigation.
            download_secret (`str`):
                Injected app-wide signing secret.

        Returns:
            `DocumentDownloadTokenResponse`:
                The token and its expiry.
      operationId: >-
        create_document_download_token_knowledge_bases__knowledge_base_id__documents__document_id__download_token_post
      parameters:
        - name: knowledge_base_id
          in: path
          required: true
          schema:
            type: string
            description: The knowledge base id.
            title: Knowledge Base Id
          description: The knowledge base id.
        - name: document_id
          in: path
          required: true
          schema:
            type: string
            description: The document id.
            title: Document Id
          description: The document id.
        - name: x-user-id
          in: header
          required: true
          schema:
            type: string
            description: >-
              Caller's user ID. Temporary header-based identity; will be
              replaced by JWT auth.
            title: X-User-Id
          description: >-
            Caller's user ID. Temporary header-based identity; will be replaced
            by JWT auth.
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DocumentDownloadTokenResponse'
        '404':
          description: Not found
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    DocumentDownloadTokenResponse:
      properties:
        token:
          type: string
          title: Token
          description: >-
            Pass as the ``token`` query parameter of ``GET
            /knowledge_bases/{kb_id}/documents/{document_id}``, in place of the
            ``X-User-ID`` header. Valid for this document only.
        expires_at:
          type: number
          title: Expires At
          description: Unix timestamp after which the token is refused.
      type: object
      required:
        - token
        - expires_at
      title: DocumentDownloadTokenResponse
      description: A capability authorizing one fetch of one document's raw file.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````