> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an app code file

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the text of one file in the app's source.

Get paths from [List app code files](/api-reference/list-app-code-files). A file that list leaves out, such as `package-lock.json`, can still be read by naming it.

Only UTF-8 text files up to 5 MB can be read. A path outside the app is refused, and so are the app's `.git` folder and `.agents/.env`, which Base44 manages and which can hold credentials.

Reads come from the app's live sandbox, the same files the builder's code editor shows, including changes that haven't been published yet. If no sandbox is running, the call starts one, so the first call after a quiet period takes noticeably longer than later ones.

Internally this route can follow a feature branch, but the parameter that selects one isn't part of the public API, so reads come from the app's main line.

This is limited to 300 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key, including a read-only one, from anyone with access to the app, viewers included. Workspace API keys are not authorized for it.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/apps/{app_id}/code/content
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/code/content:
    get:
      summary: Get an app code file
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns the text of one file in the app's source.


        Get paths from [List app code
        files](/api-reference/list-app-code-files). A file that list leaves out,
        such as `package-lock.json`, can still be read by naming it.


        Only UTF-8 text files up to 5 MB can be read. A path outside the app is
        refused, and so are the app's `.git` folder and `.agents/.env`, which
        Base44 manages and which can hold credentials.


        Reads come from the app's live sandbox, the same files the builder's
        code editor shows, including changes that haven't been published yet. If
        no sandbox is running, the call starts one, so the first call after a
        quiet period takes noticeably longer than later ones.


        Internally this route can follow a feature branch, but the parameter
        that selects one isn't part of the public API, so reads come from the
        app's main line.


        This is limited to 300 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key, including a read-only
        one, from anyone with access to the app, viewers included. Workspace API
        keys are not authorized for it.</Note>
      operationId: content_api_apps__app_id__code_content_get
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app whose code to read.
            title: App Id
          description: ID of the app whose code to read.
          example: 6820f3a4e7b91d003c45a1f2
        - name: path
          in: query
          required: true
          schema:
            type: string
            description: Path of the file, relative to the app root.
            title: Path
          description: Path of the file, relative to the app root.
          example: src/pages/Home.jsx
      responses:
        '200':
          description: The file's text.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FileContent'
        '400':
          description: '`path` is empty, points outside the app, or is the app root.'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have access to this app, you used a workspace API key, or
            `path` is in the app's `.git` folder or is `.agents/.env`.
        '404':
          description: App not found, or there's no file at `path`.
        '413':
          description: The file is larger than 5 MB.
        '415':
          description: The file isn't UTF-8 text, or `path` is a folder.
        '422':
          description: '`path` is missing.'
        '429':
          description: >-
            Too many requests for this app in the last minute from personal API
            keys in your workspace.
components:
  schemas:
    FileContent:
      properties:
        path:
          type: string
          title: Path
          description: Path of the file, relative to the app root.
          example: src/pages/Home.jsx
        content:
          type: string
          title: Content
          description: The file's full text.
          example: |
            export default function Home() {
              return <h1>Home</h1>;
            }
      type: object
      required:
        - path
        - content
      title: FileContent
      description: One file's text.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````