Fix SharePoint REST API Not Returning Images or Attachments
Question details
The SharePoint REST API response is omitting attachment files and image field data when retrieving list items.

- Product
- SharePoint
- Device & OS
- not provided
- Scenario
- A developer or user is querying a SharePoint list via REST API to retrieve list items along with their associated images and file attachments.
- Observed behavior
- The API response successfully includes standard list columns, but the attachment metadata and modern image fields are completely missing or inaccessible.
Ensure you have the correct SharePoint site URL and verify that your account or application has sufficient 'Read' permissions for both the target list and its attachments.
Explicitly Expand AttachmentFiles in the API Request
By default, the SharePoint REST API does not return attachment data to optimize payload size. You must explicitly request this data using the $expand parameter.
To retrieve attachment metadata alongside your list items, you need to modify your REST API query. The OData $expand command forces SharePoint to include the related attachment files array in the JSON response.
Identify the exact REST API URL you are using to fetch the list items, which usually looks like `/_api/web/lists/getbytitle('ListName')/items`.
Add `?$expand=AttachmentFiles` to the end of your endpoint URL. If you already have query parameters, use an ampersand, like `?$select=Title&$expand=AttachmentFiles`.
Run your API call again. The JSON response should now include an `AttachmentFiles` array containing the metadata and ServerRelativeUrl for each attachment.

Parse Structured JSON for Modern Image Fields
Modern SharePoint Image fields do not return a direct image URL as a simple string; instead, they return a structured JSON object that requires parsing.
Verify Permissions and Internal Field Names
Differences in permissions or a mismatch in internal field names between test and production environments can cause fields to be silently dropped from the API response.
Looking for a Free Alternative to Manage Office Documents?
While SharePoint effectively handles your web-based lists and REST API integrations, you may need a reliable desktop suite to open, view, and edit the actual Office documents (such as Word, Excel, and PowerPoint files) downloaded from those lists. WPS Office provides exceptional format compatibility and a familiar, professional interface at absolutely no cost.
- 1. Download WPS Office: Get the free WPS Office suite from the official website and install it on your PC or Mac.
- 2. Download your SharePoint files: Download the required document attachments from your SharePoint site to your local drive.
- 3. Edit with full compatibility: Open the downloaded files in WPS Office to edit, format, and save them with perfect Microsoft Office compatibility.

Frequently Asked Questions
Why does the SharePoint REST API return an empty array or omit attachments entirely?
This happens because the SharePoint REST API intentionally omits attachment metadata to improve query performance. You must explicitly request attachments by appending the `?$expand=AttachmentFiles` query parameter to your REST endpoint URL.
How do I get the direct image URL from a SharePoint modern image column via API?
Modern image columns return an escaped JSON string instead of a plain URL link. To retrieve the URL, you must access the field value in the API response and parse the JSON string in your code to extract the `serverRelativeUrl` property.
Can permission issues cause certain fields to disappear from the REST API response?
Yes. If the account or application making the API request lacks sufficient permissions for specific list items, attachments, or the referenced files, SharePoint may silently omit those specific fields from the JSON payload rather than returning a clear error.
How can I check the true internal field name for my SharePoint list column?
Navigate to your SharePoint List Settings in the web browser and click on the column name you want to query. Inspect the page URL in your browser's address bar; the exact text immediately following `Field=` is the internal field name you must use in your REST API calls.




