> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tolmo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Review secret findings

> Read detected secrets and their triage state through the public REST API.

Use the public API to review secret detections in your organization's resources. Secret findings are separate from the unified vulnerability findings list.

## List detections

```bash theme={null}
curl --get https://api.tolmo.com/api/v1/orgs/acme/secret-findings \
  --header "Authorization: Bearer $TOLMO_API_TOKEN" \
  --data-urlencode severity=high \
  --data-urlencode limit=50 \
  --data-urlencode offset=0
```

Filter by `resourceKey`, `severity`, `ruleId`, or `since`. `since` is an ISO 8601 timestamp applied to the last observation time. The endpoint returns an array and supports `limit` up to `500` with an `offset`.

Each record includes its detection ID, resource key, rule, severity, observation times, and available triage results. See [List secret findings](/api-reference/secrets/list-secret-findings) for the full schema.

The response includes any triage verdict, confidence, and reasoning already recorded for each detection. A missing triage value means it has not yet been assessed.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.