Overview
Allow an authorized application to render or download a File-Vault file without exposing physical storage paths.
Prerequisites
Permissions required
Steps (4)
-
1
Identify the file
Use the File-Vault file id that the authorized application is permitted to access.
Tips
Validation
Success criteria
-
2
Request files.deliveryToken
Call the authorized delivery-token capability through the trusted app transport.
Tips
Validation
Success criteria
-
3
Pass authorization
File-Vault verifies the application operation grant and resource authorization for the requested file.
Tips
Validation
Success criteria
-
4
Use the delivery contract
Use the short-lived signed File-Vault delivery URL/token in the consuming application.
Tips
Validation
Success criteria
About this guide
File-Vault provides a governed workspace for files and documents. Teams use a familiar File Explorer to browse folders, search, upload, preview, download, copy, move, rename, trash, restore, share, inspect versions, and manage metadata without exposing physical storage paths.
Governance controls include document categories and types, classification, retention, download and link policies, resource ACLs, folder templates, routing rules, legal holds, audit records, security-review records, webhook subscriptions, and usage reporting. Access is evaluated through workspace permissions and File-Vault resource policy before protected operations are performed.
Other applications can use File-Vault as their secure file layer through explicit capabilities for upload planning, secure upload, binding, unbinding, search, signed delivery, folders, versions, shares, audit, reports, webhooks, and ContextResolver. Handler, RCP, and Bridge v2 converge on the same operation and resource authorization model.