Guides · Sep 26, 2026 · 3 min read

Airtable attachment backup: why your exported links stop working within hours

Airtable attachment URLs expire shortly after they are generated. What that means for old exports, how to download every attachment in bulk, and how to keep them safe.

If you have an Airtable export from a while ago and the attachment links in it return errors, nothing is wrong with your file. The links were designed to stop working.

What changed

In November 2022 Airtable moved attachment URLs to expiring links. Any URL you get from the API, from a CSV export, or by copying a link in the interface is valid for a couple of hours and then returns an error. The file itself is untouched inside Airtable. Only the address expired.

The reason is sensible, since a permanent public URL to every file in every base is a security problem. The consequence for backups is less pleasant: an export that contains attachment URLs instead of attachment files is not a backup of your attachments. It is a list of files you once had access to.

Why this matters more than it sounds

Attachments are often the part of a base that cannot be recreated. Records can be re-entered from memory or from another system. A signed contract, a product photo shoot, a client's uploaded brief, or an inspection photo cannot. They also tend to be the largest part of a base by a wide margin, so they are the part most likely to be skipped by a casual backup.

How to download every attachment

The only reliable method is to fetch the file within the window while the link is valid, which means doing it in the same pass that reads the records.

With the API, for each table:

  1. Request a page of records.
  2. For each record, look at every field whose type is multipleAttachments. Each entry has an id, a filename, a url, a size, and a type.
  3. Download each url to disk immediately, naming the file so you can trace it back: table, record id, attachment id, original filename.
  4. Move to the next page.

Do not collect the URLs first and download later. A large base takes long enough to walk that the first URLs will have expired by the time you return to them.

Things that catch people out:

  • Size. A single base on a Team plan can hold tens of gigabytes of attachments. Stream each file to disk rather than reading it into memory.
  • Rate limits. The records endpoint allows 5 requests per second per base. The attachment downloads are separate and can go faster, but the record pages that reveal them cannot.
  • Duplicates. The same file attached to several records is served as separate attachments with separate ids. Deduplicate by content hash if storage cost matters.
  • Thumbnails. The API also returns thumbnail URLs. Skip them; the original is what you want.

Where to keep them

Anywhere that is not Airtable and not your laptop. Object storage such as Cloudflare R2, Backblaze B2, or Amazon S3 costs a few dollars per terabyte per month and is built for exactly this. Keep the attachments next to the records that reference them, in the same dated archive, so a file is never orphaned from its context.

The short route

Tablevault's free export does this for one base: it reads the schema, pages through every table, downloads every attachment while its link is live, and emails you one zip with the files organised by table and record, plus the records themselves as JSON and CSV. It uses a read-only token you create, and deletes the token afterwards.

If you have not looked at your attachments outside Airtable recently, that first zip is usually an eye-opener about how much of your business lives in those fields.