Skip to content

client.compliance.evidence

client.compliance.evidence — the compliance.evidence operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
run_id: str | None = None,
agent_id: str | None = None,
flow_id: str | None = None,
kind: str | None = None,
from_: str | None = None,
to: str | None = None,
timeout: float | None = None,
) -> ComplianceEvidenceCollectionPage

List compliance-evidence records. GET /v1/compliance/evidence

Cursor-paginated. Filters: ?runId= / ?agentId= / ?flowId= / ?kind= / ?from= / ?to= (all AND-composed). Fixed sort: timestamp asc, id asc — deterministic even when two records share a timestamp. Only mounted when CreateAppInput.auditEvents + CreateAppInput.complianceClassifier are both wired.

get(*, timeout: float | None = None) -> ComplianceEvidence

Fetch one compliance-evidence record. GET /v1/compliance/evidence/{evidenceId}

Returns the full evidence record. 404 compliance-evidence-not-found when the id is unknown within the tenant scope (never leaks the existence of another tenant's records).

export(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> SignedComplianceEvidenceBundle

Export a signed compliance-evidence bundle. POST /v1/compliance/evidence/export

Canonicalizes the filtered records as sorted-key JSON and signs with the deployment's Ed25519 key looked up by signingKeyId. Verification is a pure client-side operation: verifyEd25519(publicKey, bundleBytes, signature). Envelope shape matches ExportProvenanceResult + audit-bundle — verifiers reuse one wrapper across all three surfaces. Deployments without a signingKey binding mounted return 404 signing-not-configured.