---
title: "Get Session PCAP"
method: GET
path: "/v3/sessions/{session_id}/frames"
tags: ["Sessions"]
---

# Get Session PCAP

`GET /v3/sessions/{session_id}/frames`

Returns raw PCAP bytes for a single session. The response is a binary
PCAP file suitable for analysis with tools like Wireshark.

## Path parameters

- `session_id` string, required

## Query parameters

- `scope` 'workspace' | 'demo'

## Response `200`

PCAP file for the requested session.

## Other responses

- `400` — Bad request - request syntax is invalid for the specified endpoint. Verify request syntax and try again.
- `401` — Unauthorized. Please check your API key.
- `403` — Forbidden - request is not authorized due to an invalid API key or plan limitations. If due to plan limitations, contact sales@greynoise.io to upgrade your plan and unlock full results.
- `404` — Resource not found.
- `429` — Too many requests. You've hit the rate-limit.
- `500` — Unexpected error

---

[API](https://skmtc.dev/greynoise/apis/greynoise-api.md) · [All operations](https://skmtc.dev/greynoise/apis/greynoise-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/greynoise/greynoise-api/revisions/30942574656d/schema)
