Skip to content

List compliance-evidence records

GET
/v1/compliance/evidence
curl --request GET \
--url 'https://example.com/v1/compliance/evidence?limit=25&kind=access-event' \
--header 'Authorization: Bearer <token>'

Cursor-paginated. Filters: ?runId= / ?agentId= / ?flowId= / ?kind= / ?from= / ?to= (all AND-composed). Fixed sort: timestamp asc, id asc — deterministic even when two records share a timestamp. Only mounted when CreateAppInput.auditEvents + CreateAppInput.complianceClassifier are both wired.

limit
integer
default: 25 >= 1 <= 100

1..100. Default 25.

cursor
string

Opaque cursor from a prior response. Absent → first page.

runId
string

Filter to evidence records tied to this run id (exact match on provenanceRef.runId).

agentId
string

Filter to evidence records whose payload references this agent id.

flowId
string

Filter to evidence records whose payload references this flow id.

kind

Compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; clients must tolerate kinds they do not know.

string
>= 1 characters

Filter by evidence kind (any EvidenceKind). A kind the classifier does not mark exportable yields an empty page.

from
string format: date-time

ISO 8601 lower bound (inclusive) on timestamp.

to
string format: date-time

ISO 8601 upper bound (inclusive) on timestamp.

Page of compliance-evidence records.

Media typeapplication/json
object
data
required
Array<object>

One evidence record — matches @kindgi/specs/compliance-evidence.schema.json (payload is a versioned document opaque to the wire schema).

object
id
required
string
tenantId
required
string format: uuid
projectId

The project the underlying audit event belongs to. Absent for tenant-level events (e.g. authz decisions).

string format: uuid
kind
required

Compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; clients must tolerate kinds they do not know.

string
>= 1 characters
timestamp
required
string format: date-time
actor
object
kind
string
Allowed values: user agent system admin external
id
string
ipAddress
string
userAgent
string
subject
object
kind
string
id
string
outcome
string
Allowed values: allowed denied succeeded failed escalated
payload
required

Kind-specific payload document. Always carries version for on-read migration; other fields vary by kind.

object
key
additional properties
any
provenanceRef
object
runId
string
nodeId
string
recordId
string
signature
object
algorithm
required
string
Allowed value: ed25519
keyId
required
string
value
required

Base64-encoded signature bytes.

string
signedAt
required
string format: date-time
hasMore
required
boolean
nextCursor
string
Example
{
"data": [
{
"kind": "access-event",
"actor": {
"kind": "user"
},
"outcome": "allowed",
"signature": {
"algorithm": "ed25519"
}
}
]
}

Malformed cursor, from, or to.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}