Skip to content

Fetch one compliance-evidence record

GET
/v1/compliance/evidence/{evidenceId}
curl --request GET \
--url https://example.com/v1/compliance/evidence/example \
--header 'Authorization: Bearer <token>'

Returns the full evidence record. 404 compliance-evidence-not-found when the id is unknown within the tenant scope (never leaks the existence of another tenant’s records).

evidenceId
required
string
>= 1 characters

ComplianceEvidenceId — caller-supplied semantic id.

Full evidence record.

Media typeapplication/json

One evidence record — matches @kindgi/specs/compliance-evidence.schema.json (payload is a versioned document opaque to the wire schema).

object
id
required
string
tenantId
required
string format: uuid
projectId

The project the underlying audit event belongs to. Absent for tenant-level events (e.g. authz decisions).

string format: uuid
kind
required

Compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; clients must tolerate kinds they do not know.

string
>= 1 characters
timestamp
required
string format: date-time
actor
object
kind
string
Allowed values: user agent system admin external
id
string
ipAddress
string
userAgent
string
subject
object
kind
string
id
string
outcome
string
Allowed values: allowed denied succeeded failed escalated
payload
required

Kind-specific payload document. Always carries version for on-read migration; other fields vary by kind.

object
key
additional properties
any
provenanceRef
object
runId
string
nodeId
string
recordId
string
signature
object
algorithm
required
string
Allowed value: ed25519
keyId
required
string
value
required

Base64-encoded signature bytes.

string
signedAt
required
string format: date-time
Example
{
"kind": "access-event",
"actor": {
"kind": "user"
},
"outcome": "allowed",
"signature": {
"algorithm": "ed25519"
}
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

No evidence record with that id under this tenant.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}