> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gobare.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# List artifacts

> List files this session's turns published.



## OpenAPI

````yaml /openapi.json get /v1/sessions/{session_id}/artifacts
openapi: 3.1.0
info:
  title: Gobare Agent API
  version: v1
  description: >-
    Programmatic access to Gobare coding-agent sessions. Conceptually aligned
    with OpenAI's Agents API; deliberately not wire-compatible with it. See the
    divergence list in the product documentation.
servers:
  - url: https://api.{domain}
    variables:
      domain:
        default: gobare.dev
security: []
paths:
  /v1/sessions/{session_id}/artifacts:
    get:
      summary: List artifacts
      description: List files this session's turns published.
      operationId: get_sessions_session_id_artifacts
      parameters:
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 100
          description: How many to return, 1–100. Default 20.
        - name: order
          in: query
          required: false
          schema:
            type: string
            enum:
              - asc
              - desc
          description: Newest first (`desc`, the default) or oldest first (`asc`).
        - name: after
          in: query
          required: false
          schema:
            type: string
          description: >-
            The `last_id` of the previous page. A cursor this collection cannot
            place — expired, deleted, or never issued — answers with an empty
            page rather than starting over, so a paging loop ends instead of
            repeating itself.
        - name: turn_id
          in: query
          required: false
          schema:
            type: string
          description: Only what this turn published.
      responses:
        '200':
          description: List files this session's turns published.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ArtifactList'
        '400':
          description: >-
            `invalid_request`. A query parameter this endpoint does not take.
            Refused rather than ignored, because an ignored filter answers with
            everything and looks like a filter that matched.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: The access token is missing, unrecognised, expired or revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            The token is valid but may not perform this call. The message names
            the scope it wanted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            No such endpoint, or no such object under this token's organization.
            Another organization's id is indistinguishable from one that never
            existed, deliberately.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            `rate_limit_exceeded`. The token is past its allowance for this
            bucket. Honour `Retry-After`; the `x-ratelimit-*` headers on every
            response say how close you were.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: An unexpected error. Quote the request id.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - accessToken: []
components:
  schemas:
    ArtifactList:
      type: object
      required:
        - object
        - data
      properties:
        object:
          type: string
          const: list
          description: >-
            Always `list`. Names the shape, so a value can be identified without
            knowing which call returned it.
        data:
          type: array
          items:
            $ref: '#/components/schemas/Artifact'
        has_more:
          type: boolean
        last_id:
          type:
            - string
            - 'null'
    Error:
      type: object
      required:
        - error
      description: Every refusal this API makes, in one shape.
      properties:
        error:
          description: Always present on a failure, and the only thing present.
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              enum:
                - invalid_request
                - authentication_error
                - permission_denied
                - not_found
                - method_not_allowed
                - conflict
                - queue_full
                - rate_limit_exceeded
                - project_limit_exceeded
                - context_length_exceeded
                - provider_error
                - provider_unauthorized
                - sandbox_error
                - sandbox_unavailable
                - directory_unavailable
                - workspace_recovery_failed
                - bridge_incompatible
                - internal_error
            message:
              type: string
            request_id:
              type: string
              description: >-
                Also on the x-request-id header. Quote it when reporting a
                problem.
    Artifact:
      type: object
      required:
        - object
        - id
        - session_id
        - turn_id
        - path
        - size_bytes
      description: >-
        An immutable copy of a file a turn published. Survives the sandbox being
        paused or reclaimed.
      properties:
        object:
          type: string
          const: artifact
          description: >-
            Always `artifact`. Names the shape, so a value can be identified
            without knowing which call returned it.
        id:
          type: string
          description: Ours. Use it to fetch the bytes.
        session_id:
          type: string
          description: The session that produced it.
        turn_id:
          type: string
          description: The turn that published it.
        path:
          type: string
          description: Where it was in the workspace when it was published.
        size_bytes:
          type: integer
          description: Of the stored copy.
        content_type:
          type: string
          description: Guessed from the path. `application/octet-stream` when unrecognised.
        created_at:
          type: integer
          description: Unix milliseconds, when it was published.
  securitySchemes:
    accessToken:
      type: http
      scheme: bearer
      description: >-
        A `gbr_pat_` access token. Scopes are recorded on the token when it is
        minted.

````