## Public link to a file

`POST /v1/files/:id/public-link`

**Anyone can access the file without signing in. You cannot disable the link through the API: use the Bitrix24 interface or permanently delete the object.**

The method creates a link if none exists. Repeated calls return the same link. An existing link from another employee may be returned, possibly with a password or expiry. The response does not tell you whether it is protected. Never write the URL to logs, audit records or telemetry. Trash only suspends access; restoring the object opens the existing link again. A trashed object is allowed and returns meta.inTrash=true; the link shows an object-not-found page until restoration.

## Parameters

| Parameter | Type | Required | Description |
|---|---|---|---|
| id | integer | yes | Positive safe integer |

Key scope: disk. No body required. READONLY keys cannot publish.

## curl — personal key

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/files/42/public-link" -H "X-Api-Key: YOUR_API_KEY"
```

## curl — application key

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/files/42/public-link" -H "X-Api-Key: YOUR_APP_KEY"
```


## JavaScript — personal key

```javascript
const response = await fetch("https://vibecode.bitrix24.com/v1/files/42/public-link", {
  method: "POST",
  headers: { "X-Api-Key": "YOUR_API_KEY" },
});
const data = await response.json();
```


## JavaScript — application key

```javascript
const response = await fetch("https://vibecode.bitrix24.com/v1/files/42/public-link", {
  method: "POST",
  headers: { "X-Api-Key": "YOUR_APP_KEY" },
});
const data = await response.json();
```

## Response

```json
{"success":true,"data":{"url":"https://bitrix24public.com/example.bitrix24.com/file/EXAMPLE_LINK","revocableViaApi":false},"meta":{"inTrash":false}}
```

## Response fields

| Field | Type | Description |
|---|---|---|
| success | boolean | true |
| data.url | string | Public access secret |
| data.revocableViaApi | boolean | false |
| meta.inTrash | boolean | Trash state |

## Limitations and errors

File links require the portal disk_manual_external_link feature; an unavailable plan returns 403 DISK_PUBLIC_LINK_PLAN_UNAVAILABLE.

403 BITRIX_ACCESS_DENIED means no permission to change the object or public links are disabled on the portal; Bitrix24 does not distinguish these reasons. 404 ENTITY_NOT_FOUND means the object is absent. 422 DISK_PUBLIC_LINK_REFUSED means no link was returned. Writes are never automatically retried; 502 DISK_OUTCOME_UNKNOWN requires reading state before deciding whether to retry. Not supported in batch.

To permanently remove the object, use [purge](/docs/entities/files/purge).

Bitrix24 method: `disk.file.getExternalLink`.

400 — malformed path id:

```json
{"success":false,"error":{"code":"INVALID_ID","message":"id must be a positive safe integer."}}
```
