> ## Documentation Index
> Fetch the complete documentation index at: https://developers.papelship.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List media

> **Permission:** `products:read`



## OpenAPI

````yaml /api-reference/openapi/user-api.yaml get /products/{id}/media
openapi: 3.0.3
info:
  title: PapelShip Store API
  version: 1.0.0
  description: >-
    Manage your PapelShip store from your own systems: create orders, sync
    products and stock, ship physical orders, answer support tickets and react
    to events.


    Every request needs your API key in `x-api-key` and your store ID in
    `x-store-hash`. Amounts are integers in minor units (`2999` = 29.99). Dates
    are ISO 8601 in UTC.
  contact:
    name: PapelShip Support
    email: support@papelship.com
    url: https://papelship.com
servers:
  - url: https://app.papelship.com/api/v1
    description: Production
security:
  - ApiKey: []
    StoreHash: []
tags:
  - name: Account
    description: Your key, store and payment methods.
  - name: Orders
    description: Create orders, take manual payments, cancel, refund and read deliveries.
  - name: Products
    description: Products and their settings.
  - name: Variants & stock
    description: Variants, physical stock and license keys.
  - name: Product content
    description: Media, SEO, payment methods, files and stock alerts.
  - name: Categories
    description: Organise products.
  - name: Groups
    description: Collections of products.
  - name: Coupons
    description: Discount codes.
  - name: Customers
    description: Buyers and their history.
  - name: Blocklist
    description: Emails and IPs that can't place orders.
  - name: Reviews
    description: Customer reviews.
  - name: Support
    description: Support tickets.
  - name: Subscriptions
    description: Recurring products and auto-renewals.
  - name: Fulfillment
    description: Ship physical orders.
  - name: Returns
    description: Return requests.
  - name: Shipping settings
    description: Zones, rates and locations.
  - name: Webhooks
    description: Endpoints, deliveries and event types.
  - name: Affiliates
    description: Partner programme.
  - name: Analytics
    description: Sales summary.
paths:
  /products/{id}/media:
    get:
      tags:
        - Product content
      summary: List media
      description: '**Permission:** `products:read`'
      operationId: listMedia
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
            example: AbC123xyz789
          description: Product hash ID (numeric ID also accepted).
      responses:
        '200':
          description: Media
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: true
                  media:
                    type: array
                    items:
                      $ref: '#/components/schemas/ProductMedia'
                required:
                  - success
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  schemas:
    ProductMedia:
      type: object
      properties:
        id:
          type: integer
        kind:
          type: string
          enum:
            - image
            - video
        url:
          type: string
        position:
          type: integer
        is_main:
          type: boolean
        meta:
          nullable: true
          type: object
        created_at:
          type: string
          format: date-time
          example: '2026-10-04T12:00:00.000Z'
    Error:
      type: object
      properties:
        success:
          type: boolean
          example: false
        code:
          type: string
          description: Machine-readable error code. Branch on this, not on the message.
          example: VALIDATION_FAILED
        error:
          type: string
          description: Human-readable message.
          example: customer_email must be a valid email address
        details:
          type: object
          properties: {}
          description: Extra context, for example `field` for validation errors.
          additionalProperties: true
        request_id:
          type: string
          description: Include this when you contact support.
          example: req_7YbK2mQ9xP1cRt4v
      required:
        - success
        - code
        - error
  responses:
    Unauthorized:
      description: >-
        Missing, invalid or expired API key.


        Codes: `MISSING_API_KEY`, `MISSING_STORE_HASH`, `INVALID_API_KEY`,
        `API_KEY_EXPIRED`
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            code: INVALID_API_KEY
            error: Invalid API Key
            request_id: req_7YbK2mQ9xP1cRt4v
    Forbidden:
      description: >-
        The key is not allowed to do this.


        Codes: `INSUFFICIENT_SCOPE`, `IP_NOT_ALLOWED`, `STORE_NOT_ALLOWED`,
        `STORE_API_NOT_IN_PLAN`, `FEATURE_NOT_ENABLED`
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            code: INSUFFICIENT_SCOPE
            error: This API key needs the orders:write permission
            request_id: req_7YbK2mQ9xP1cRt4v
    NotFound:
      description: |-
        The record does not exist in this store.

        Codes: `NOT_FOUND`, `STORE_NOT_FOUND`
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            code: NOT_FOUND
            error: Invoice not found
            request_id: req_7YbK2mQ9xP1cRt4v
    RateLimited:
      description: >-
        Too many requests. Wait `Retry-After` seconds.


        Codes: `RATE_LIMITED` (300 requests per minute per key),
        `STORE_API_MONTHLY_QUOTA_EXCEEDED` (your plan's monthly quota).
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            code: RATE_LIMITED
            error: Too many requests. The limit is 300 requests per minute per key.
            request_id: req_7YbK2mQ9xP1cRt4v
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Your Store API key (`pk_live_...`). Create it in **Developers › API
        keys**.
    StoreHash:
      type: apiKey
      in: header
      name: x-store-hash
      description: >-
        The ID of the store the request is for. Shown in **Developers › API
        keys**.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.