Skip to content

A link to download an artifact as a zip file (an artifact an older runner kept is a .tar.gz), good for 10 minutes and needing no token.

GET/repos/{owner}/{name}/actions/artifacts/{id}/zip

Over REST, GET …/zip answers 302 with the link in Location, as GitHub does: curl -L follows it. Over MCP the link is returned as url, with expires_at. Needs the Read role.

Over REST the answer is 302 Found with the link in Location, as GitHub’s is, so curl -L -o web-dist.zip …/zip saves the file; the body above is what the MCP workflow tool’s download_artifact returns. The link needs no token and stops working after 10 minutes.

  • Authentication: Optional. Public data can be read without a token; send one to see what is private.
  • MCP tool: workflow with action download_artifact, and the same inputs
  • Scope: An access token needs workflows:read.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id integer or string Yes The artifact’s id, a number.
curl https://api.g1t.sh/repos/flagon-io/g1t/actions/artifacts/4182/zip \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"url": "https://api.g1t.sh/actions/toolkit/blobs/eyJrIjoiYXJ0aWZhY3QiLCJpIjoiNDE4MiJ9.q3VbS1x9",
"expires_at": "2026-10-08T15:13:00.000Z",
"artifact": {
"id": 4182,
"node_id": "artifact_4182",
"name": "web-dist",
"size_in_bytes": 18734120,
"url": "https://api.g1t.sh/repos/flagon-io/g1t/actions/artifacts/4182",
"archive_download_url": "https://api.g1t.sh/repos/flagon-io/g1t/actions/artifacts/4182/zip",
"expired": false,
"digest": "sha256:5f1c3a9e7b2d4f6a8c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f2a4c6e8b0d1f3a",
"created_at": "2026-10-08T14:03:51.204Z",
"updated_at": "2026-10-08T14:03:52.880Z",
"expires_at": "2026-10-22T14:03:51.204Z",
"workflow_run": {
"id": "run_01kq9c4e6g8j0m2p4r6t8v0x2z",
"repository_id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0",
"head_repository_id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0",
"head_branch": "main",
"head_sha": "7c1e9a4b2d6f80135ac9e2b7d4f6a8c0e1b3d5f7"
}
}
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.