> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beinfi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List invoice download links

> Returns the download links this invoice's payments unlocked, so you can deliver the file on your own thank-you page instead of relying only on the delivery email.
Requires a secret key (`sk_`) with the `billing:read` scope: the link grants access to the paid product, so a publishable key cannot read it.
An empty list is normal while the invoice is unpaid, the product has no deliverable, or delivery has not been processed yet. Check again shortly.




## OpenAPI

````yaml /api-reference/openapi.en.json get /billing/invoices/{invoiceID}/deliverable
openapi: 3.1.0
info:
  title: Infi API
  version: 0.0.1
  description: >
    The Infi REST API: catalog, customers, usage metering, subscriptions,

    invoices, payments and checkout.


    **Authentication.** Send your secret key as `Authorization: Bearer
    sk_test_…`

    (sandbox) or `sk_live_…` (production). The key prefix selects the
    environment.

    Checkout routes (`/pay/*`) and `/public/*` take no key: they run in the

    payer's browser.


    **Idempotency.** Every request that changes data requires an

    `Idempotency-Key` header. A retry with the same key returns the original

    response instead of running again.


    **Amounts.** Money and quantities travel as decimal strings (`"150.00"`,

    `"0.0001"`), never as floating-point numbers.


    **Errors.** The body carries `error_code` (stable, branch on it), `message`

    (for humans) and `tracer_id` (send it to support). Rate-limit and
    idempotency

    errors are nested under `error`, with `code` and `request_id`.
servers:
  - url: https://api-sandbox.beinfi.com
    description: Sandbox
  - url: https://api.beinfi.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Catalog
  - name: Customers
  - name: Metering
  - name: Subscriptions
  - name: Invoices
  - name: Payments
  - name: Checkout
  - name: Coupons
  - name: Billing
  - name: Account
  - name: Webhooks
  - name: Test account
  - name: Rail
  - name: Storefronts
paths:
  /billing/invoices/{invoiceID}/deliverable:
    parameters:
      - name: invoiceID
        in: path
        required: true
        schema:
          type: string
          format: uuid
    get:
      tags:
        - Billing
      summary: List invoice download links
      description: >
        Returns the download links this invoice's payments unlocked, so you can
        deliver the file on your own thank-you page instead of relying only on
        the delivery email.

        Requires a secret key (`sk_`) with the `billing:read` scope: the link
        grants access to the paid product, so a publishable key cannot read it.

        An empty list is normal while the invoice is unpaid, the product has no
        deliverable, or delivery has not been processed yet. Check again
        shortly.
      operationId: listInvoiceDeliverableGrants
      responses:
        '200':
          content:
            application/json:
              schema:
                type: object
                properties:
                  grants:
                    type: array
                    items:
                      $ref: '#/components/schemas/DeliverableGrant'
          description: The invoice's download links (may be empty).
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  schemas:
    DeliverableGrant:
      type: object
      properties:
        paymentId:
          type: string
          format: uuid
          description: The payment that unlocked the download.
        token:
          type: string
          description: >-
            The code inside `downloadUrl`. Treat it like a password: whoever
            holds it can download the paid product.
        downloadUrl:
          type: string
          description: Download link for the buyer. Answers `410` once `revokedAt` is set.
        emailSentAt:
          type:
            - string
            - 'null'
          format: date-time
          description: When the delivery email with this link was sent.
        revokedAt:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            When the download was turned off, by a full refund or a chargeback
            on the payment. Once set, the link answers `410`: stop showing the
            download button.
        createdAt:
          type: string
          format: date-time
      description: A download link unlocked by a payment.
    Error:
      type: object
      required:
        - message
        - error_code
        - tracer_id
      properties:
        message:
          type: string
          description: Human-readable sentence.
        error_code:
          $ref: '#/components/schemas/ErrorCode'
          description: Stable error code. Branch on it.
        tracer_id:
          type: string
          description: Request id. Include it when contacting support.
      description: >-
        The standard error body. It is flat (no `error` wrapper) and the trace
        id is `tracer_id`.
    ErrorCode:
      type: string
      examples:
        - internal_error
        - validation_failed
        - bad_request
        - unauthorized
        - forbidden
        - not_found
        - conflict
        - rate_limited
      description: >-
        Stable error code. The list is open: besides the generic codes, each
        area defines its own (`coupon_expired`, `insufficient_balance`,
        `version_not_draft`, `idempotency_key_reused`…). Handle a code you do
        not recognize by its HTTP status and show `message`; do not fail parsing
        the response.
  responses:
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Missing or invalid API key.
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: The key is not allowed to perform this operation.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your account's secret key: `Authorization: Bearer sk_test_…` or
        `sk_live_…`. Server-side only.

````