> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tolmo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a unified finding

> Fetch a Tolmo-authored or third-party finding by its unified finding ID, including its description and assessment history. Returns 404 when the finding is not visible to the caller.



## OpenAPI

````yaml /api-reference/openapi.json get /api/v1/orgs/{orgSlug}/external-findings/{externalFindingId}
openapi: 3.0.3
info:
  title: Tolmo API
  version: 1.0.0
  description: >-
    The Tolmo REST API. Use an organization API key for automation or a CLI user
    token for user-authenticated operations. Most endpoints are scoped to one
    organization.
servers:
  - url: https://api.tolmo.com
    description: Production
security: []
paths:
  /api/v1/orgs/{orgSlug}/external-findings/{externalFindingId}:
    get:
      tags:
        - external-findings
      summary: Get a unified finding
      description: >-
        Fetch a Tolmo-authored or third-party finding by its unified finding ID,
        including its description and assessment history. Returns 404 when the
        finding is not visible to the caller.
      operationId: apiGetExternalFinding
      parameters:
        - schema:
            type: string
          in: path
          name: orgSlug
          required: true
        - schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          in: path
          name: externalFindingId
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  externalId:
                    type: string
                  title:
                    type: string
                  severity:
                    type: string
                  origin:
                    type: string
                  recordOrigin:
                    type: string
                    enum:
                      - external
                      - agent
                      - manual
                  originalPlatformUrl:
                    nullable: true
                    type: string
                  originalPlatformStatus:
                    nullable: true
                    type: string
                  status:
                    type: string
                    enum:
                      - open
                      - in_review
                      - closed
                      - acknowledged
                      - false_positive
                      - canceled
                  statusEditable:
                    type: boolean
                  platformResolution:
                    nullable: true
                    type: string
                  inReviewReason:
                    nullable: true
                    type: string
                  inReviewUrl:
                    nullable: true
                    type: string
                  state:
                    type: string
                    enum:
                      - unprocessed
                      - duplicate
                      - ingested
                      - awaiting_exploit
                      - exploit_blocked
                      - defense_in_depth
                      - exploited
                      - exploit_not_produced
                      - false_positive
                      - resolved
                  agenticStatus:
                    nullable: true
                    type: string
                  lastRetestVerdict:
                    nullable: true
                    type: string
                  lastRetestedAt:
                    nullable: true
                    type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                  retest:
                    type: string
                    enum:
                      - none
                      - pending
                      - confirmed
                      - failed
                  cveDispatchable:
                    type: boolean
                  resourceKey:
                    nullable: true
                    type: string
                  resourceName:
                    nullable: true
                    type: string
                  kind:
                    nullable: true
                    type: string
                  ruleName:
                    nullable: true
                    type: string
                  targetUrls:
                    type: array
                    items:
                      type: string
                  firstSeenAt:
                    nullable: true
                    type: string
                  lastSeenAt:
                    nullable: true
                    type: string
                  updatedAt:
                    type: string
                  lastActivity:
                    nullable: true
                    type: object
                    properties:
                      kind:
                        type: string
                        enum:
                          - state
                          - status
                      from:
                        nullable: true
                        type: string
                      to:
                        type: string
                      at:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      by:
                        nullable: true
                        type: string
                    required:
                      - kind
                      - from
                      - to
                      - at
                      - by
                    additionalProperties: false
                  tolmoFinding:
                    nullable: true
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      title:
                        type: string
                      severity:
                        type: string
                      status:
                        type: string
                      relationship:
                        type: string
                        enum:
                          - created
                          - linked
                          - duplicate
                          - merged
                      url:
                        type: string
                    required:
                      - id
                      - title
                      - severity
                      - status
                      - relationship
                      - url
                    additionalProperties: false
                  body:
                    nullable: true
                    type: string
                  ruleId:
                    nullable: true
                    type: string
                  raw: {}
                  reports:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        state:
                          type: string
                          enum:
                            - unprocessed
                            - duplicate
                            - ingested
                            - awaiting_exploit
                            - exploit_blocked
                            - defense_in_depth
                            - exploited
                            - exploit_not_produced
                            - false_positive
                            - resolved
                        title:
                          type: string
                        agentName:
                          nullable: true
                          type: string
                        verdict:
                          nullable: true
                          type: string
                        summary:
                          nullable: true
                          type: string
                        markdown:
                          nullable: true
                          type: string
                        createdAt:
                          type: string
                        durationMs:
                          nullable: true
                          type: integer
                          minimum: 0
                          maximum: 9007199254740991
                        reportUrl:
                          nullable: true
                          type: string
                        confidence:
                          nullable: true
                          type: string
                          enum:
                            - high
                            - medium
                            - low
                        stage:
                          type: string
                          enum:
                            - false_positive_triage
                            - exploitation
                        outcome:
                          type: string
                          enum:
                            - false_positive
                            - resolved
                            - needs_exploitation
                            - exploited
                            - exploitation_unsuccessful
                            - inconclusive
                        reportMarkdown:
                          nullable: true
                          type: string
                        agentOutputId:
                          nullable: true
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        workflowRunId:
                          nullable: true
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      required:
                        - id
                        - state
                        - title
                        - agentName
                        - verdict
                        - summary
                        - markdown
                        - createdAt
                        - durationMs
                        - reportUrl
                        - confidence
                        - stage
                        - outcome
                        - reportMarkdown
                        - agentOutputId
                        - workflowRunId
                      additionalProperties: false
                  transitions:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        fromState:
                          nullable: true
                          type: string
                        toState:
                          type: string
                        fromDuplicateOf:
                          nullable: true
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        toDuplicateOf:
                          nullable: true
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        changedBy:
                          type: string
                        reason:
                          nullable: true
                          type: string
                        changedAt:
                          type: string
                        report:
                          nullable: true
                          type: object
                          properties:
                            markdown:
                              type: string
                            agentName:
                              nullable: true
                              type: string
                            stage:
                              type: string
                          required:
                            - markdown
                            - agentName
                            - stage
                          additionalProperties: false
                      required:
                        - id
                        - fromState
                        - toState
                        - fromDuplicateOf
                        - toDuplicateOf
                        - changedBy
                        - reason
                        - changedAt
                        - report
                      additionalProperties: false
                  duplicateOf:
                    nullable: true
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      title:
                        type: string
                      severity:
                        type: string
                      state:
                        type: string
                      origin:
                        type: string
                    required:
                      - id
                      - title
                      - severity
                      - state
                      - origin
                    additionalProperties: false
                  duplicates:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        title:
                          type: string
                        severity:
                          type: string
                        state:
                          type: string
                        origin:
                          type: string
                      required:
                        - id
                        - title
                        - severity
                        - state
                        - origin
                      additionalProperties: false
                  duplicateCount:
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                  verificationRun:
                    nullable: true
                    type: object
                    properties:
                      status:
                        type: string
                        enum:
                          - running
                      startedAt:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      workflowId:
                        type: string
                    required:
                      - status
                      - startedAt
                      - workflowId
                    additionalProperties: false
                required:
                  - id
                  - externalId
                  - title
                  - severity
                  - origin
                  - recordOrigin
                  - originalPlatformUrl
                  - originalPlatformStatus
                  - status
                  - statusEditable
                  - platformResolution
                  - inReviewReason
                  - inReviewUrl
                  - state
                  - agenticStatus
                  - lastRetestVerdict
                  - lastRetestedAt
                  - retest
                  - cveDispatchable
                  - resourceKey
                  - resourceName
                  - kind
                  - ruleName
                  - targetUrls
                  - firstSeenAt
                  - lastSeenAt
                  - updatedAt
                  - lastActivity
                  - tolmoFinding
                  - body
                  - ruleId
                  - raw
                  - reports
                  - transitions
                  - duplicateOf
                  - duplicates
                  - duplicateCount
                  - verificationRun
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HttpError'
      security:
        - bearerAuth: []
components:
  schemas:
    HttpError:
      type: object
      properties:
        statusCode:
          type: number
        code:
          type: string
        error:
          type: string
        message:
          type: string
      title: HttpError
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A Tolmo API token, sent as `Authorization: Bearer <token>`. Either a
        user token (`usr_tok.*`, minted by `tolmo auth login`, scoped to your
        own permissions) or an org API token created in the Tolmo app, for CI
        and automation.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.