Guides · Sep 26, 2026 · 3 min read
Airtable attachment backup: why your exported links stop working within hours
Airtable attachment URLs expire shortly after they are generated. What that means for old exports, how to download every attachment in bulk, and how to keep them safe.
If you have an Airtable export from a while ago and the attachment links in it return errors, nothing is wrong with your file. The links were designed to stop working.
What changed
In November 2022 Airtable moved attachment URLs to expiring links. Any URL you get from the API, from a CSV export, or by copying a link in the interface is valid for a couple of hours and then returns an error. The file itself is untouched inside Airtable. Only the address expired.
The reason is sensible, since a permanent public URL to every file in every base is a security problem. The consequence for backups is less pleasant: an export that contains attachment URLs instead of attachment files is not a backup of your attachments. It is a list of files you once had access to.
Why this matters more than it sounds
Attachments are often the part of a base that cannot be recreated. Records can be re-entered from memory or from another system. A signed contract, a product photo shoot, a client's uploaded brief, or an inspection photo cannot. They also tend to be the largest part of a base by a wide margin, so they are the part most likely to be skipped by a casual backup.
How to download every attachment
The only reliable method is to fetch the file within the window while the link is valid, which means doing it in the same pass that reads the records.
With the API, for each table:
- Request a page of records.
- For each record, look at every field whose type is
multipleAttachments. Each entry has anid, afilename, aurl, asize, and atype. - Download each
urlto disk immediately, naming the file so you can trace it back: table, record id, attachment id, original filename. - Move to the next page.
Do not collect the URLs first and download later. A large base takes long enough to walk that the first URLs will have expired by the time you return to them.
Things that catch people out:
- Size. A single base on a Team plan can hold tens of gigabytes of attachments. Stream each file to disk rather than reading it into memory.
- Rate limits. The records endpoint allows 5 requests per second per base. The attachment downloads are separate and can go faster, but the record pages that reveal them cannot.
- Duplicates. The same file attached to several records is served as separate attachments with separate ids. Deduplicate by content hash if storage cost matters.
- Thumbnails. The API also returns thumbnail URLs. Skip them; the original is what you want.
Where to keep them
Anywhere that is not Airtable and not your laptop. Object storage such as Cloudflare R2, Backblaze B2, or Amazon S3 costs a few dollars per terabyte per month and is built for exactly this. Keep the attachments next to the records that reference them, in the same dated archive, so a file is never orphaned from its context.
The short route
Tablevault's free export does this for one base: it reads the schema, pages through every table, downloads every attachment while its link is live, and emails you one zip with the files organised by table and record, plus the records themselves as JSON and CSV. It uses a read-only token you create, and deletes the token afterwards.
If you have not looked at your attachments outside Airtable recently, that first zip is usually an eye-opener about how much of your business lives in those fields.