Download links
Files are never served from permanent URLs. Every download goes through a signed,
short-lived link of the form https://fw.unitcircle.ca/dl/<payload>.<signature>. You get these links
from:
| Where | Link |
|---|---|
| Update check | firmware-url and release-notes-url |
| Download a log file | Location header of the 302 |
| Download the binary and release notes | Location header of the 302 |
- No authentication. The link itself is the permission — treat it like a password until it expires.
- Expiry: 5 minutes after it was issued (
expiresin update-check responses). Links are tamper-proof: changing any character invalidates them. - Counting: each use increases the file's download counter and appears in your usage statistics.
- A build that has been withdrawn can no longer be downloaded, even with a link that hasn't expired.
Follow a download link
GET /dl/{token}
No authentication
Redirects (302) to a 60-second pre-signed URL on the object store; the final response
has Content-Disposition: attachment with a descriptive file name such as
demo-example-hw-2.0.0-1.6.0-10-g30d0049-AFI.bin. Some single-server installations stream
the file directly with 200 instead. Follow redirects and both work.
Try it sends an example token that has long expired, so it shows the 410. Get a
live link from an update check and open it in your browser.
Path parameters
tokenstring requiredThe link's token, as returned by the endpoints above.
GET /dl/{token}
curl -L -o download.bin "https://fw.unitcircle.ca/dl/AaDZvRgieMa7-iOfg8tIIwEBoNs4s_t69LRrY4rsgor1AAAAAGq3GqmtZSivSOwgVg.cpUONuHCrbh7vwlVE-vZGoihrd4"
http --follow --download GET "https://fw.unitcircle.ca/dl/AaDZvRgieMa7-iOfg8tIIwEBoNs4s_t69LRrY4rsgor1AAAAAGq3GqmtZSivSOwgVg.cpUONuHCrbh7vwlVE-vZGoihrd4"
import requests
r = requests.get(
"https://fw.unitcircle.ca/dl/AaDZvRgieMa7-iOfg8tIIwEBoNs4s_t69LRrY4rsgor1AAAAAGq3GqmtZSivSOwgVg.cpUONuHCrbh7vwlVE-vZGoihrd4",
)
r.raise_for_status() # requests follows the redirect to the file
open("download.bin", "wb").write(r.content)
Response
HTTP/1.1 302 Found Location: https://<object store>/…/firmware.bin?X-Amz-Algorithm=AWS4-HMAC-SHA256&…&X-Amz-Expires=60&… Cache-Control: no-store
{"type":"about:blank","title":"Gone","status":410,"detail":"this download link is invalid or has expired; request a new one","instance":"/dl/AaDZ…","request_id":"…"}{"type":"about:blank","title":"Too Many Requests","status":429,"detail":"rate limit exceeded; retry after 1 s","instance":"/dl/AaDZ…","request_id":"…"}