## Enable or disable a document public link

`POST /v1/documents/:id/public-url`

Enables or disables a public link that opens an app document in a browser without an API key and without signing in to Bitrix24.

## Parameters

| Parameter | Type | Required | Description |
|----------|-----|:-----:|---------|
| `id` (path) | number | yes | Document ID, a positive integer. List: [`GET /v1/documents`](/docs/entities/documents/list) |

## Request fields (body)

| Field | Type | Required | Description |
|------|-----|:-----:|---------|
| `enabled` | boolean | yes | `true` enables the link, `false` disables it. The string `"true"` is rejected |

## Examples

### curl — personal key

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/documents/2001/public-url" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"enabled": true}'
```

### curl — OAuth application

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/documents/2001/public-url" \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"enabled": true}'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/documents/2001/public-url', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ enabled: true }),
})

const { success, data } = await res.json()
console.log('Link:', data.publicUrl)
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/documents/2001/public-url', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ enabled: true }),
})

const { success, data } = await res.json()
```

## Response fields

| Field | Type | Description |
|------|-----|---------|
| `success` | boolean | Always `true` on success |
| `data.publicUrl` | string \| null | Public link to the document after `enabled: true`. `null` after `enabled: false` |

## Response example

Link enabled:

```json
{
  "success": true,
  "data": {
    "publicUrl": "https://example.bitrix24.com/~FbdN8"
  }
}
```

Link disabled:

```json
{
  "success": true,
  "data": {
    "publicUrl": null
  }
}
```

## Error response example

400 — `enabled` is missing or not a boolean:

```json
{
  "success": false,
  "error": {
    "code": "MISSING_REQUIRED_FIELDS",
    "message": "enabled must be a boolean."
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|---------|
| 400 | `INVALID_PARAMS` | `id` is not a positive integer. Message: `Document ID must be a positive integer.` |
| 400 | `MISSING_REQUIRED_FIELDS` | `enabled` is missing or not a boolean, for example `"true"` |
| 404 | `ENTITY_NOT_FOUND` | No document with this `id`. Message: `Document not found.` |
| 502 | `BITRIX_INVALID_RESPONSE` | Bitrix24 responded without the link state |
| 422 | `BITRIX_ERROR` | Bitrix24 rejected the request. The reason is in `error.message` |
| 403 | `BITRIX_ACCESS_DENIED` | Bitrix24 denied access to the document |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | The key is read-only |
| 403 | `SCOPE_DENIED` | The key lacks the `documentgenerator` scope |
| 401 | `MISSING_API_KEY` | The `X-Api-Key` header is missing |
| 401 | `TOKEN_MISSING` | No tokens are mapped to the key — an OAuth application key was called without a user session |

Full list of common API errors — [Errors](/docs/errors).

## Known specifics

**Anyone with the address can open the document via the link.** Disable the link when access is no longer needed: after `enabled: false`, the previous link returns `404` in the browser.

**Re-enabling gives a new address.** A repeated `enabled: true` on an already enabled link returns the same address. After disabling, the next enable issues a different address.

## See also

- [Get a document](/docs/entities/documents/get)
- [Download a document as DOCX](/docs/entities/documents/download)
- [Enable or disable a CRM document public link](/docs/entities/documents/crm-public-url)
- [Documents](/docs/entities/documents)
