files.download and are always tenant/environment scoped.
| Endpoint family | Scope | Purpose |
|---|---|---|
Signed download endpoints under /v1/files (with legacy /v1/s3 aliases) | files.download | Download files that the authenticated tenant and environment can access. |