403.404. The image itself is served without authentication at path (at most 48 by 48 pixels), path-small (the same image), and path-large (at most 256 by 256 pixels), so anyone who has the filename can load it. To read the contact's current avatar without knowing its filename, call GET /domains/{domain}/contacts/{contact_id}/avatar. Only GET and DELETE are served on this path; POST and PUT return 405 Method Not Allowed. Upload to the avatar collection path, not to a filename.Authorization: Bearer ********************curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/domains/example.com/contacts/0c4e8a2f6b1d9e3a7c5f0b8d2e6a4c1f/avatar/1a79a4d60de6718e8e5b326e338ae533.webp' \
--header 'Authorization: Bearer <token>'{
"filename": "1a79a4d60de6718e8e5b326e338ae533.webp",
"user": "domain",
"domain": "example.com",
"contact_id": "0c4e8a2f6b1d9e3a7c5f0b8d2e6a4c1f",
"filetype": "image/webp",
"filesize-large-bytes": 7852,
"filesize-small-bytes": 1026,
"path": "/ns-api/v2/avatar/1a79a4d60de6718e8e5b326e338ae533.webp",
"path-large": "/ns-api/v2/avatar/256/1a79a4d60de6718e8e5b326e338ae533.webp",
"path-small": "/ns-api/v2/avatar/48/1a79a4d60de6718e8e5b326e338ae533.webp",
"created-datetime": "2026-09-01T14:30:00+00:00"
}