403.404. The image itself is served without authentication at path (at most 48 by 48 pixels), path-small (the same image), and path-large (at most 256 by 256 pixels), so anyone who has the filename can load it. To read the contact's current avatar without knowing its filename, call GET /domains/{domain}/users/{user}/contacts/{contact_id}/avatar. Only GET and DELETE are served on this path; POST and PUT return 405 Method Not Allowed. Upload to the avatar collection path, not to a filename. A shared contact's avatar is under /domains/{domain}/contacts/{contact_id}/avatar/{filename}.Authorization: Bearer ********************curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/domains/example.com/users/1001/contacts/5f2b7c9e1a4d8e3b6c0f9a2d7e1b4c8a/avatar/1a79a4d60de6718e8e5b326e338ae533.webp' \
--header 'Authorization: Bearer <token>'{
"filename": "1a79a4d60de6718e8e5b326e338ae533.webp",
"user": "1001",
"domain": "example.com",
"contact_id": "5f2b7c9e1a4d8e3b6c0f9a2d7e1b4c8a",
"filetype": "image/webp",
"filesize-large-bytes": 7852,
"filesize-small-bytes": 1026,
"path": "/ns-api/v2/avatar/1a79a4d60de6718e8e5b326e338ae533.webp",
"path-large": "/ns-api/v2/avatar/256/1a79a4d60de6718e8e5b326e338ae533.webp",
"path-small": "/ns-api/v2/avatar/48/1a79a4d60de6718e8e5b326e338ae533.webp",
"created-datetime": "2026-09-01T14:30:00+00:00"
}