Overview
We are strengthening how conversation attachments are accessed to provide better security and more granular control over sensitive files.
As part of this update, attachments will no longer rely on directly accessible links. Applications accessing attachments outside of HighLevel will need the appropriate permission and authenticated access.
This change will initially apply to
email conversation attachments
, with other conversation channels planned for future phases.
Why are we doing this?
Conversation attachments can contain sensitive or confidential customer information. To strengthen data protection, we are introducing additional access controls around these files. This ensures that attachments are only accessible to applications and users with the appropriate permissions, while also creating a more consistent and secure approach to file access across HighLevel.
What are we doing?
We are introducing a new permission-based access model for conversation attachments.
With this change:
  • Applications will need an additional
    file access permission
    to access conversation attachments.
  • Attachment links will move to a new, more secure format.
  • Applications accessing or displaying attachments outside of HighLevel will need to verify that they have permission before retrieving the file.
  • Existing attachment links will
    continue to work during only till Nov 30, 2026
    , giving developers time to make the required updates.
  • The first phase will cover email attachments. We plan to extend this approach to other conversation channels and file-based custom fields in future phases.
Who will be affected by this change?
For most HighLevel users,
there will be no change to the existing experience
. This change primarily
affects marketplace developers and applications that access or display email conversation attachments
outside of HighLevel. These developers will need to update their applications with the new file access permission and ask existing users to reauthorize their application. Developers will need to
complete the required updates by Nov 30, 2026
, after which the new access controls will take effect.
PS: Applications that do not access conversation attachments do not need to take any action.