Skip to content

List provenance records

GET
/v1/provenance
curl --request GET \
--url 'https://example.com/v1/provenance?limit=25' \
--header 'Authorization: Bearer <token>'

Cursor-paginated. Metadata rows only — clients fetch the DAG payload via GET /v1/provenance/{runId}. Fixed sort: createdAt desc, id desc. Filters: ?runId=, ?agentId=, ?createdAfter=.

limit
integer
default: 25 >= 1 <= 100

1..100. Default 25.

cursor
string

Opaque cursor from a prior response. Absent → first page.

runId
string format: uuid

Filter records to this run id (exact match).

agentId
string

Filter records to those with at least one DAG node whose actor = <agentId> (agent-driven turns tag their nodes with the agent id).

createdAfter
string format: date-time

ISO 8601 timestamp; return records created strictly after this.

Page of records.

Media typeapplication/json
object
data
required
Array<object>

Lightweight metadata row returned by list. Excludes the full DAG payload — clients fetch the DAG via GET /v1/provenance/{runId}.

object
id
required
string format: uuid
runId
required
string format: uuid
tenantId
required
string format: uuid
version
required

Schema version of the record document (semver).

string
flowRef
object
id
required
string
version
required
string
signed
required

True when the emission-time signature is present. Independent of whether the export route can produce a signed bundle.

boolean
createdAt
required
string format: date-time
hasMore
required
boolean
nextCursor
string
Examplegenerated
{
"data": [
{
"id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"runId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"tenantId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"version": "example",
"flowRef": {
"id": "example",
"version": "example"
},
"signed": true,
"createdAt": "2026-04-15T12:00:00Z"
}
],
"hasMore": true,
"nextCursor": "example"
}

Malformed cursor or createdAfter timestamp.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}