Findings
List findings
List the organization’s findings, newest first, with the shared lean paginated contract. Regular callers see published findings only; effective super-admins may additionally read all drafts, and a scoped pentester may list drafts they authored.
GET
List findings
Authorizations
A Tolmo API token, sent as Authorization: Bearer <token>. Either a user token (usr_tok.*, minted by tolmo auth login, scoped to your own permissions) or an org API token created in the Tolmo app, for CI and automation.
Path Parameters
Query Parameters
Available options:
open, in_review, closed, acknowledged, false_positive, canceled Available options:
critical, high, medium, low, info Available options:
open, in_review, closed, acknowledged, false_positive, canceled Available options:
open, in_review, closed, acknowledged, false_positive, canceled Available options:
critical, high, medium, low, info Available options:
critical, high, medium, low, info Maximum string length:
512Pattern:
^\d{4}-\d{2}-\d{2}$Pattern:
^\d{4}-\d{2}-\d{2}$Pattern:
^\d{4}-\d{2}-\d{2}$Pattern:
^\d{4}-\d{2}-\d{2}$Available options:
severity, status, created, updated, createdAt, updatedAt Available options:
asc, desc Required range:
1 <= x <= 10000Required range:
1 <= x <= 100Required range:
1 <= x <= 100Pattern:
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Response
Default Response