openapi: 3.1.0 info: title: PandaDoc REST API Logs Document Attachments API description: The PandaDoc REST API provides programmatic access to PandaDoc's document automation platform, enabling developers to create, send, track, and manage documents within their own applications. The API supports the full document lifecycle including generating documents from templates with dynamic data, collecting e-signatures, managing recipients, and tracking document status. Authentication is handled via API keys or OAuth 2.0, and a free sandbox environment is available for testing integrations before moving to production. An active Enterprise plan is required to access the production API. version: 7.18.0 contact: name: PandaDoc API Support url: https://developers.pandadoc.com/ email: api-track@pandadoc.com termsOfService: https://www.pandadoc.com/master-services-agreement/ servers: - url: https://api.pandadoc.com/public/v1 description: Production Server security: - apiKey: [] - oauth2: [] tags: - name: Document Attachments description: Operations for managing file attachments associated with a document, including uploading and downloading attachment files. paths: /documents/{id}/attachments: get: operationId: listDocumentAttachments summary: List Document Attachments description: Returns a list of all file attachments associated with a document. Includes attachment metadata such as name, size, and upload date. tags: - Document Attachments parameters: - $ref: '#/components/parameters/DocumentId' responses: '200': description: List of document attachments. content: application/json: schema: $ref: '#/components/schemas/DocumentAttachmentsResponse' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' /documents/{id}/attachments/{attachment_id}/download: get: operationId: downloadDocumentAttachment summary: Download Document Attachment description: Downloads a specific attachment file associated with a document. Returns the binary file content with appropriate content type headers. tags: - Document Attachments parameters: - $ref: '#/components/parameters/DocumentId' - name: attachment_id in: path required: true description: Unique identifier of the document attachment. schema: type: string responses: '200': description: Attachment file content. content: application/octet-stream: schema: type: string format: binary '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' components: schemas: DocumentAttachment: type: object description: A file attached to a document. properties: uuid: type: string description: Unique identifier of the attachment. name: type: string description: File name of the attachment. date_created: type: string format: date-time description: Timestamp when the attachment was uploaded. ErrorResponse: type: object description: Standard error response body. properties: type: type: string description: Error type identifier. detail: type: string description: Human-readable description of the error. DocumentAttachmentsResponse: type: object description: Attachments associated with a document. properties: attachments: type: array description: List of attachment records. items: $ref: '#/components/schemas/DocumentAttachment' responses: Unauthorized: description: Authentication credentials are missing or invalid. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' NotFound: description: The requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' TooManyRequests: description: Rate limit exceeded. Retry after the indicated delay. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' parameters: DocumentId: name: id in: path required: true description: Unique identifier of the document. schema: type: string securitySchemes: apiKey: type: apiKey in: header name: Authorization description: API Key authentication. Include the key in the Authorization header as "API-Key YOUR_API_KEY". Generate keys from the PandaDoc Developer Dashboard. oauth2: type: oauth2 description: OAuth 2.0 authentication. Use the authorization code flow to obtain user-scoped access tokens. Tokens expire after approximately one year. flows: authorizationCode: authorizationUrl: https://app.pandadoc.com/oauth2/authorize tokenUrl: https://api.pandadoc.com/oauth2/access_token scopes: read: Read access to documents, templates, contacts, and workspace data. write: Write access to create and modify documents, templates, and contacts. externalDocs: description: PandaDoc API Reference url: https://developers.pandadoc.com/reference/about