Skip to main content
GET
Get a unified finding

Authorizations

Authorization
string
header
required

A Tolmo API token, sent as Authorization: Bearer <token>. Either a user token (usr_tok.*, minted by tolmo auth login, scoped to your own permissions) or an org API token created in the Tolmo app, for CI and automation.

Path Parameters

orgSlug
string
required
externalFindingId
string<uuid>
required
Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$

Response

Default Response

id
string<uuid>
required
Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
externalId
string
required
title
string
required
severity
string
required
origin
string
required
recordOrigin
enum<string>
required
Available options:
external,
agent,
manual
originalPlatformUrl
string | null
required
originalPlatformStatus
string | null
required
status
enum<string>
required
Available options:
open,
in_review,
closed,
acknowledged,
false_positive,
canceled
statusEditable
boolean
required
platformResolution
string | null
required
inReviewReason
string | null
required
inReviewUrl
string | null
required
state
enum<string>
required
Available options:
unprocessed,
duplicate,
ingested,
awaiting_exploit,
exploit_blocked,
defense_in_depth,
exploited,
exploit_not_produced,
false_positive,
resolved
agenticStatus
string | null
required
lastRetestVerdict
string | null
required
lastRetestedAt
string<date-time> | null
required
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
retest
enum<string>
required
Available options:
none,
pending,
confirmed,
failed
cveDispatchable
boolean
required
resourceKey
string | null
required
resourceName
string | null
required
kind
string | null
required
ruleName
string | null
required
targetUrls
string[]
required
firstSeenAt
string | null
required
lastSeenAt
string | null
required
updatedAt
string
required
lastActivity
object | null
required
tolmoFinding
object | null
required
body
string | null
required
ruleId
string | null
required
raw
any
required
reports
object[]
required
transitions
object[]
required
duplicateOf
object | null
required
duplicates
object[]
required
duplicateCount
integer
required
Required range: 0 <= x <= 9007199254740991
verificationRun
object | null
required