List compliance-evidence records
const url = 'https://example.com/v1/compliance/evidence?limit=25&kind=access-event';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/compliance/evidence?limit=25&kind=access-event' \ --header 'Authorization: Bearer <token>'Cursor-paginated. Filters: ?runId= / ?agentId= / ?flowId= / ?kind= / ?from= / ?to= (all AND-composed). Fixed sort: timestamp asc, id asc — deterministic even when two records share a timestamp. Only mounted when CreateAppInput.auditEvents + CreateAppInput.complianceClassifier are both wired.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
Filter to evidence records tied to this run id (exact match on provenanceRef.runId).
Filter to evidence records whose payload references this agent id.
Filter to evidence records whose payload references this flow id.
Compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; clients must tolerate kinds they do not know.
Filter by evidence kind (any EvidenceKind). A kind the classifier does not mark exportable yields an empty page.
ISO 8601 lower bound (inclusive) on timestamp.
ISO 8601 upper bound (inclusive) on timestamp.
Responses
Section titled “Responses”Page of compliance-evidence records.
object
One evidence record — matches @kindgi/specs/compliance-evidence.schema.json (payload is a versioned document opaque to the wire schema).
object
The project the underlying audit event belongs to. Absent for tenant-level events (e.g. authz decisions).
Compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; clients must tolerate kinds they do not know.
object
object
Kind-specific payload document. Always carries version for on-read migration; other fields vary by kind.
object
object
object
Base64-encoded signature bytes.
Example
{ "data": [ { "kind": "access-event", "actor": { "kind": "user" }, "outcome": "allowed", "signature": { "algorithm": "ed25519" } } ]}Malformed cursor, from, or to.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}