Skip to main content
GET
List secret findings

Authorizations

Authorization
string
header
required

A Tolmo API token, sent as Authorization: Bearer <token>. Either a user token (usr_tok.*, minted by tolmo auth login, scoped to your own permissions) or an org API token created in the Tolmo app, for CI and automation.

Path Parameters

orgSlug
string
required

Query Parameters

resourceKey
string
severity
string
ruleId
string
since
string<date-time>

ISO-8601 timestamp; only secrets last seen on or after this point are returned

Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
limit
integer
Required range: 1 <= x <= 500
offset
integer
Required range: 0 <= x <= 9007199254740991
unprocessedForScan
string

When set, returns only rows whose triage is missing or evaluated against a different scan than latest_scan_id. Drives the secret-finding-triage agent sweep.

Response

200 - application/json

Default Response

id
string
required
orgId
string
required
resourceKey
string
required
fingerprint
string
required
source
string
required
engine
string
required
engineVersion
string
required
ruleId
string
required
propertyPath
string
required
severity
string
required
entropy
number
required
verificationState
string
required
origin
string
required
matchContext
string
required
startLine
number
required
endLine
number
required
startColumn
number
required
endColumn
number
required
firstSeenAt
string
required
lastSeenAt
string
required
latestScanId
string
required
createdAt
string
required
updatedAt
string
required
triageVerdict
enum<string> | null
required
Available options:
real_secret,
likely_real,
likely_false_positive,
clear_false_positive
triageConfidence
enum<string> | null
required
Available options:
high,
medium,
low
triageSeverity
enum<string> | null
required
Available options:
critical,
high,
medium,
low
triageReasoning
string | null
required
triageModel
string | null
required
triageVerified
boolean | null
required
triageVerificationMethod
string | null
required
triageEvaluatedScanId
string | null
required
triageEvaluatedAt
string | null
required
triagePostedFindingId
string | null
required
integrationId
string | null
required
isActive
boolean | null
required
activeLastSeenAt
string | null
required
lastValidatedAt
string | null
required
validationError
string | null
required
validationMethod
string | null
required
tokenOwner
string | null
required
tokenOwnerType
string | null
required
tokenScopes
string[] | null
required
tokenPrivilege
string | null
required
tokenIdentity
object | null
required