---
title: "Get an authorized environment pack download"
method: GET
path: "/v1/validator/pack/{pack_sha256}"
tags: ["validator"]
---

# Get an authorized environment pack download

`GET /v1/validator/pack/{pack_sha256}`

Return a time-limited download URL and version metadata. Verify the delivered bytes against download_url_sha256; pack_sha256 identifies the parent pack.

## Path parameters

- `pack_sha256` string, required — Content hash of the sealed pack.

## Response `200`

Successful Response

- PackFetchResponse — Authorized environment delivery and its parent pack identity. Verify downloaded bytes against ``download_url_sha256``, not the parent ``pack_sha256``. Only tasks authorized for this delivery are included.
  - `pack_sha256` string, required — Content-addressed parent pack identity.
  - `download_url` string, required — Time-limited URL for the authorized archive.
  - `download_url_expires_at` string, date-time, required
  - `download_url_sha256` string, required — SHA-256 of the delivered archive bytes.
  - `download_url_size_bytes` integer, required — Byte size of the delivered archive.
  - `artifact_signature` unknown
  - `delivery_scope` 'qualifying'
  - `delivery_task_ids` string[], required — Exact task roster authorized in this delivery.
  - `contract_version` string, required
  - `runtime_version` string, required
  - `tool_contract_version` string, required
  - `verifier_version` string, required
  - `result_schema_version` string, required
  - `catalog_epoch` string, required
  - `catalog_sha256` string, required
  - `search_index_epoch` string, nullable, required
  - `search_index_sha256` string, nullable, required
  - `task_count` integer, required
  - `family_counts` object, required

## Other responses

- `401` — Missing or invalid authentication.
- `403` — Caller is not authorized.
- `404` — Environment pack not found.
- `409` — Environment delivery is not ready.
- `422` — Validation Error
- `429` — Request rate limited; honor Retry-After before retrying.
- `500` — The request could not be completed.
- `503` — A service is temporarily unavailable.

## Changes

- **2026-09-14** `b53d2cf1bdf6` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/oroagents/apis/oro-api/changes/v1/validator/pack/:pack_sha256/get.md)

---

[API](https://skmtc.dev/oroagents/apis/oro-api.md) · [All operations](https://skmtc.dev/oroagents/apis/oro-api/llms.txt) · [OpenAPI document](https://skmtc.dev/oroagents/apis/oro-api/revisions/3e921f170eed?raw)
