I'm unable to download attachments from Confluence pages using a scoped API token with all the read scopes. The attachment metadata API works fine, but the actual download fails with 401 Unauthorized.
Setup:
Using scoped API token from a service account (not personal account)
Scopes: all read scopes granular and classic
Service account has view permissions on the target spaces/pages
Calling via <a href="https://api.atlassian.com/ex/confluence/%7BcloudId%7D/wiki/api/v2/pages/%7BpageId%7D/attachments" rel="noopener nofollow noreferrer" target="_blank">api.atlassian.com/ex/confluence/{cloudId}/wiki/api/v2/pages/{pageId}/attachments</a> — this succeeds and returns attachment metadata with downloadLink
The downloadLink from the metadata returns a relative path like /wiki/download/attachments/{pageId}/{filename}?api=v2. When I:
Build the full URL: https://{domain}.atlassian.net/wiki/download/attachments/{pageId}/{filename}?api=v2 + Bearer {token}
Or call: <a href="https://api.atlassian.com/ex/confluence/%7BcloudId%7D/wiki/download/attachments/%7BpageId%7D/%7Bfilename%7D?api=v2" rel="noopener nofollow noreferrer" target="_blank">api.atlassian.com/ex/confluence/{cloudId}/wiki/download/attachments/{pageId}/{filename}?api=v2</a> Bearer {token}
Or use the dedicated download endpoint: /wiki/rest/api/content/{pageId}/child/attachment/{attId}/download + Bearer {token}
All return 401 Unauthorized
Questions:
Does the download endpoint require additional scopes beyond read:attachment:confluence?
Is there a different download endpoint for scoped tokens? (e.g. always use /content/{id}/child/attachment/{attId}/download?)
Does the service account need explicit attachment download permissions beyond space/page view access?