The root cause was in the OpenAPI spec, not your code: the `permissions` field changed shape (from a list of string ids to a list of objects) and the generated SDK's parsing model rejected real responses. Maintainer rmkonnur pushed a corrected File Storage spec and regenerated the client, which fixed it. Takeaways: (1) upgrade merge-python-client to the latest release when you hit pydantic ValidationError on list() calls, spec drift is the usual culprit; (2) if you cannot upgrade, skip the SDK and call the REST endpoint directly (`GET https://api.merge.dev/api/filestorage/v1/files` with your API key and account token headers) and parse the JSON yourself.