> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List available report transitions

> Returns only transitions that the token owner can execute from the report's current status. Requires reports:triage and a StandardAdmin or SuperAdmin report role.



## OpenAPI

````yaml /openapi/external-admin-v1.json get /reports/{id}/transitions
openapi: 3.0.3
info:
  title: Hackrate External Admin API
  version: v1
  description: >-
    Program discovery and report triage for users with assigned Hackrate roles.
    Tokens are created in Profile Settings > External API.
servers:
  - url: https://www.hckrt.com/api/v1/admin
security:
  - personalToken: []
paths:
  /reports/{id}/transitions:
    get:
      summary: List available report transitions
      description: >-
        Returns only transitions that the token owner can execute from the
        report's current status. Requires reports:triage and a StandardAdmin or
        SuperAdmin report role.
      parameters:
        - $ref: '#/components/parameters/reportId'
      responses:
        '200':
          description: Current status and executable transitions
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ReportTransitions'
              examples:
                newReport:
                  value:
                    currentStatus:
                      id: 1
                      name: New
                    availableTransitions:
                      - transition: triaged
                        targetStatus:
                          id: 3
                          name: Triaged
                        requiresMessage: false
                        requiresDuplicateOfReportId: false
                      - transition: duplicate
                        targetStatus:
                          id: 7
                          name: Duplicate
                        requiresMessage: false
                        requiresDuplicateOfReportId: true
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  parameters:
    reportId:
      name: id
      in: path
      required: true
      schema:
        type: integer
  schemas:
    ReportTransitions:
      type: object
      properties:
        currentStatus:
          $ref: '#/components/schemas/NamedIntegerValue'
        availableTransitions:
          type: array
          items:
            $ref: '#/components/schemas/AvailableTransition'
    NamedIntegerValue:
      type: object
      properties:
        id:
          type: integer
        name:
          type: string
    AvailableTransition:
      type: object
      properties:
        transition:
          type: string
          enum:
            - invalid
            - spam
            - out_of_scope
            - needs_more_info
            - triaged
            - resolved
            - accepted_risk
            - new_to_review
            - informative
            - duplicate
            - reopen
        targetStatus:
          $ref: '#/components/schemas/NamedIntegerValue'
        requiresMessage:
          type: boolean
        requiresDuplicateOfReportId:
          type: boolean
    ProblemDetails:
      type: object
      properties:
        type:
          type: string
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
  responses:
    Forbidden:
      description: The role or token scope does not allow the operation
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    NotFound:
      description: Resource not found or outside the token owner's access
    RateLimited:
      description: Per-token limit of 120 requests per minute exceeded
  securitySchemes:
    personalToken:
      type: http
      scheme: bearer
      bearerFormat: hckrt_pat token

````