# List documents

> Lists the agency's documents on live trips, most recently changed first.

`GET /v1/documents`

Lists the agency's documents on live trips, most recently changed first. Filter by `tripId`, `folderId` (`none` = loose), `visibility` and `updatedSince`. For a 'new or changed document' polling trigger (n8n, Zapier), pass the last `updatedAt` you saw as `updatedSince` with `sort=updatedAt`: an upload, a rename, a move and a release to travelers all move `updatedAt`. Uploads that were never completed are not listed. Follow `nextCursor` until it is null.

**Permissions:** `documents:read` · **Kind:** read · **Cost:** 1 unit



## Path parameters

_None._

## Query parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `tripId` | uuid |  |  |
| `limit` | integer |  | 1–100, default 25 |
| `cursor` | string |  | max 500 chars |
| `sort` | "updatedAt" \| "-updatedAt" \| "createdAt" \| "-createdAt" |  | default "-updatedAt" |
| `folderId` | uuid \| "none" |  | One folder's documents; `none` = the loose ones (in no folder). |
| `visibility` | "staff" \| "traveler" |  |  |
| `updatedSince` | datetime |  |  |

## Response `200`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "list" | yes |  |
| `data` | object[] | yes |  |
| `data[].object` | "document" | yes |  |
| `data[].id` | uuid | yes |  |
| `data[].tripId` | uuid | yes |  |
| `data[].folderId` | uuid \| null | yes | The folder it is filed in; null = loose (in no folder). |
| `data[].name` | string | yes |  |
| `data[].mimeType` | string | yes |  |
| `data[].byteSize` | integer | yes | ≥ 0 |
| `data[].status` | "pending" \| "ready" | yes | `pending`: reserved, the upload is not complete — never listed. `ready`: a document. |
| `data[].visibility` | "staff" \| "traveler" | yes | `staff`: internal, only the agency sees it. `traveler`: released to the trip's travelers. |
| `data[].visibleToTravelersNow` | boolean | yes | Released AND the trip is published: the traveler's app shows it right now. |
| `data[].visibleAt` | string \| null | yes | When it was last released to travelers; null while internal. |
| `data[].visibleBy` | object \| null | yes |  |
| `data[].visibleBy.id` | string | yes |  |
| `data[].visibleBy.name` | string \| null | yes |  |
| `data[].uploadedBy` | object \| null | yes |  |
| `data[].uploadedBy.id` | string | yes |  |
| `data[].uploadedBy.name` | string \| null | yes |  |
| `data[].createdAt` | string | yes |  |
| `data[].updatedAt` | string | yes |  |
| `data[].appUrl` | string \| null | yes | The trip's Documents tab in bymundi. |
| `nextCursor` | string \| null | yes |  |

## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached

## Examples

#### curl

```bash
curl https://api.bymundi.com/v1/documents \
  -H "Authorization: Bearer $BYMUNDI_KEY"
```

#### JavaScript

```javascript
const res = await fetch("https://api.bymundi.com/v1/documents", {
  method: "GET",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
  },
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.get(
    "https://api.bymundi.com/v1/documents",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}"},
)
res.raise_for_status()
data = res.json()
```
