# File Download API Reference | SEC API > Complete API reference for the SEC EDGAR Download API. The URL format, every path parameter, authentication, response content types and status codes, with a real example response. Source: https://sec-api.io/api-reference/download-api Filing search and retrieval GET`https://edgar-mirror.sec-api.io///` Download any of the 20 million EDGAR filings, and the 100 million exhibits and attachments filed since 1993, exactly as they were filed. The response is the original file content, such as HTML, XML, TXT, PDF, Excel or an image, and a new file is available about 300 milliseconds after EDGAR publishes it. [Read the guide for this API →](https://sec-api.io/docs/edgar-file-and-sec-filings-download-api) ## Authentication Send the API key either as a header or as a query parameter. The header is preferred; the query parameter exists for cases where a header cannot be set, such as opening a URL directly in a browser. Authorization: required header The API key on its own. Do not prefix it with Bearer or any other word. Example `Authorization: YOUR_API_KEY` token: optional query parameter The API key, appended to the URL. Use this only when a header is not possible. ## Path parameters Supplied as part of the URL. cik: required string CIK of the filer, taken from the original sec.gov URL. Leading zeros may be kept or removed, and the full sec.gov path form /Archives/edgar/data//... is accepted as well. Example `815094` accession-no: required string Accession number of the filing with the hyphens removed, so 000156459021006205 rather than 0001564590-21-006205. Example `000156459021006205` filename: required string Name of the file inside the filing. Any file type is supported, including .htm, .txt, .xml, .xsd, .pdf, .xlsx and images. Example `abmd-8k_20210211.htm` ## Response Content-Type: application/octet-stream. body: string or binary The original EDGAR file, preserved as filed and returned without modification. There is no JSON envelope around it. Content-Type: response header MIME type of the returned file, taken from the file itself. An HTML file returns text/html, an XML file returns text/xml, an image returns image/png or image/jpeg, and so on. All MIME types are supported. Content-Encoding: response header Set to gzip by default. A browser, and the Python and Node.js SDKs, decompress the body for you. A low-level HTTP client has to decompress it itself. ## Status codes | | | | --- | --- | | `200` | Success. The body is the original file content. | | `403` | The API key is missing, or it is not valid. | | `404` | No file exists at the requested path on EDGAR. | | `429` | Too many requests. The limit is 200 requests per second, or 60,000 files per five-minute window. Slow the request rate and retry. | | `500` | Server error. Retry, and report it if it persists. | ## Request example GET https://edgar-mirror.sec-api.io/// ```bash https://edgar-mirror.sec-api.io/815094/000156459021006205/abmd-8k_20210211.htm https://edgar-mirror.sec-api.io/Archives/edgar/data/815094/000156459021006205/abmd-8k_20210211.htm https://edgar-mirror.sec-api.io/815094/000156459021006205/abmd-8k_20210211.htm?token=YOUR_API_KEY ``` ```python from sec_api import DownloadApi downloadApi = DownloadApi("YOUR_API_KEY") content = downloadApi.get_file("https://www.sec.gov/Archives/edgar/data/815094/000156459021006205/abmd-8k_20210211.htm") ``` ```javascript import { downloadApi } from "sec-api"; downloadApi.setApiKey("YOUR_API_KEY"); const content = await downloadApi.getFile("https://www.sec.gov/Archives/edgar/data/815094/000156459021006205/abmd-8k_20210211.htm"); ``` ```bash curl -X GET "https://edgar-mirror.sec-api.io/815094/000156459021006205/abmd-8k_20210211.htm" \ -H "Authorization: YOUR_API_KEY" ``` ## Response example 200 OK · application/octet-stream ```bash abmd-8k_20210211.htm
... ```