> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hi-doctor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Download a health document

> Stream a document's bytes, as a download, after access checks.

``as_attachment=True`` is the security control this whole feature rests on.
Patient documents are largely PDFs, and a PDF rendered INLINE runs its
embedded JavaScript inside the browser's viewer, on our origin. We do not
sanitise PDFs — that cannot be done reliably — so we never render one. The
patient's own reader opens it, exactly like an email attachment.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/users/documents/{document_id}/content/
openapi: 3.0.3
info:
  title: Hi-Doctor API
  version: 1.0.0
  description: >-
    Patient-facing REST API for Hi-Doctor.


    Authenticate with email and password to get an `access` token, then send it
    as `Authorization: Bearer <token>` on every request that needs one.
    Registering, verifying the code, signing in and refreshing the token all
    work without a bearer token.


    Every account-scoped endpoint returns only the authenticated patient's own
    records. A resource you cannot see is indistinguishable from one that does
    not exist.
  contact:
    name: Hi-Doctor
    email: hello@hi-doctor.ai
    url: https://hi-doctor.ai
servers:
  - url: https://api.hi-doctor.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Account
    description: Registration, email verification, sign-in and profile.
  - name: Questionnaires
    description: Complete a consultation questionnaire and submit it for medical review.
  - name: Consultations
    description: Consultations a doctor has reviewed or is reviewing.
  - name: Prescriptions
    description: Prescriptions and reissue requests.
  - name: Billing
    description: Checkout, subscription management and the Stripe billing portal.
  - name: Records
    description: Orders, invoices and side-effect reports.
  - name: Messages
    description: The patient's private thread with their medical team.
  - name: Progress
    description: Weight, injection and note tracking. Requires an active treatment plan.
  - name: Referrals
    description: Referral summary and transactions.
  - name: Attribution
    description: Lead and attribution events from the landing funnel.
paths:
  /v1/users/documents/{document_id}/content/:
    get:
      tags:
        - Records
      summary: Download a health document
      description: >-
        Stream a document's bytes, as a download, after access checks.


        ``as_attachment=True`` is the security control this whole feature rests
        on.

        Patient documents are largely PDFs, and a PDF rendered INLINE runs its

        embedded JavaScript inside the browser's viewer, on our origin. We do
        not

        sanitise PDFs — that cannot be done reliably — so we never render one.
        The

        patient's own reader opens it, exactly like an email attachment.
      operationId: users_documents_content_retrieve
      parameters:
        - in: path
          name: document_id
          schema:
            type: string
            format: uuid
          required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                type: string
                format: binary
          description: The document, always as an attachment download.
        '401':
          description: >-
            No bearer token, or a token that is expired or malformed.
            Re-authenticate; do not retry the same token.
          content:
            application/json:
              example:
                detail: Given token not valid for any token type
                code: token_not_valid
                messages:
                  - token_class: AccessToken
                    token_type: access
                    message: Token is invalid
        '404':
          description: No such document for this caller.
          content:
            application/json:
              example:
                detail: No Consultation matches the given query.
        '503':
          description: Stored file could not be read.
      security:
        - jwtAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Access token from POST /v1/users/token/
    jwtAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````