Skip to main content
Downloads work like uploads: bytes never come through the JSON API. You ask for download links and get signed URLs, one per file plus a zip, that need no API key. Hand them to curl, a queue worker or an AI agent. Every URL supports Range, so a dropped download continues where it stopped.

Prerequisites

  • An API key, exported as YUNGLE_API_KEY:
    • transfers:read for your own transfers.
    • collections:read for your own collections.
    • Any scope for a link someone shared with you. Free keys work for all three.
  • Optional: the CLI. yungle get <link> needs no account at all.

Steps

1

Get the download links

Pick the call that matches what you are downloading:
All three return the same shape:
  • zipUrl downloads everything as one zip, with folders kept. It is null when there is only one file, or while a transfer is still uploading.
  • path is the file’s folder. In a collection it is "" for a file at the top level.
  • crc32 is the file’s checksum as 8 hex digits, for checking a download. It can be null.
  • A collection returns up to 10,000 files.
2

Download the files

Fetch each downloadUrl (or zipUrl) with any HTTP client. No Authorization header is needed: the URL is the credential, so keep it out of logs and chats you do not control.
The URLs work for 24 hours (urlsExpireAt). A download already running is not cut off when they expire, but resuming it afterwards needs fresh URLs, so call step 1 again.The Python SDK can save a whole set of links in one call. It keeps folders, resumes partial files, skips files already complete, and checks each checksum:
3

Know what counts as a download

The two kinds of call are counted differently:
  • Your own files (/transfers/{id}/download-links, /collections/{id}/download-links) are not a recipient download. They never appear in download receipts or transfer.downloaded webhooks, and never use up a download limit.
  • A shared link (/links/resolve) is treated exactly like a person opening it in a browser. Each call is one download of a transfer: it appears in the sender’s receipts and counts against their maxDownloads.
4

Handle the refusals

/links/resolve applies the same rules as the web page:Your own transfer’s download links return 410 link_unavailable once it has expired or been revoked, and 409 e2ee_unsupported for an end-to-end encrypted transfer.

Scanning and availability

Every file is scanned for malware after it uploads. A file whose scan is still pending, or that the scanner could not inspect (scanResult: "unscanned", usually very large files), is downloadable. A file found to be infected has its encryption key destroyed at once, so its download URL answers 404 for everyone, you included. Check scanResult per file with GET /transfers/{id}. See Files and scanning.

Track who downloaded your transfer

For a transfer you sent, GET /transfers/{id}/downloads returns each download event and, per recipient, whether they downloaded. Recipients you emailed get a personal link, so their downloads carry their address; downloads through a link you shared yourself have recipientEmail: null. One visit is one download, however many files it took. Send a transfer walks through reading the receipts. To be told the moment a download happens instead of polling, subscribe to transfer.downloaded with a webhook.

Next steps

Webhooks

Get transfer.downloaded as it happens.

Send a transfer

Read per-recipient receipts and set a download limit.

Receive files

Collect files from others, then download them here.

API reference

The download endpoints in full.