> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List the Report Management timeline

> Requires reports:read and uses the same report access rules as report details. Activities are existing comments and system comments; no legacy text classification is inferred.



## OpenAPI

````yaml /openapi/external-admin-v1.json get /reports/{id}/activities
openapi: 3.0.3
info:
  title: Hackrate External Admin API
  version: v1
  description: >-
    Program discovery and report triage for users with assigned Hackrate roles.
    Tokens are created in Profile Settings > External API.
servers:
  - url: https://www.hckrt.com/api/v1/admin
security:
  - personalToken: []
paths:
  /reports/{id}/activities:
    get:
      summary: List the Report Management timeline
      description: >-
        Requires reports:read and uses the same report access rules as report
        details. Activities are existing comments and system comments; no legacy
        text classification is inferred.
      parameters:
        - $ref: '#/components/parameters/reportId'
        - name: direction
          in: query
          description: Ascending matches the management timeline.
          schema:
            type: string
            enum:
              - asc
              - desc
            default: asc
        - name: cursor
          in: query
          description: Opaque cursor bound to this report and the selected direction.
          schema:
            type: string
        - name: limit
          in: query
          schema:
            type: integer
            default: 50
            minimum: 1
            maximum: 100
      responses:
        '200':
          description: Cursor page of timeline activities
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActivityPage'
              examples:
                timeline:
                  value:
                    items:
                      - id: 845
                        message: Severity changed to **High**.
                        createdAt: '2026-09-21T10:15:00Z'
                        isInternal: true
                        hasEvidence: false
                        actor: null
                    nextCursor: null
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  parameters:
    reportId:
      name: id
      in: path
      required: true
      schema:
        type: integer
  schemas:
    ActivityPage:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/ReportActivity'
        nextCursor:
          type: string
          nullable: true
    ReportActivity:
      type: object
      description: >-
        A comment or system entry from the Report Management timeline. Legacy
        text is not classified into inferred event types.
      properties:
        id:
          type: integer
          format: int64
        message:
          type: string
          description: Markdown timeline message.
        createdAt:
          type: string
          format: date-time
        isInternal:
          type: boolean
        hasEvidence:
          type: boolean
          description: True when the timeline comment has PicFromAzure evidence.
        actor:
          allOf:
            - $ref: '#/components/schemas/Person'
          nullable: true
    ProblemDetails:
      type: object
      properties:
        type:
          type: string
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
    Person:
      type: object
      properties:
        id:
          type: string
        nickname:
          type: string
        email:
          type: string
          format: email
  responses:
    BadRequest:
      description: Invalid filter, sort, range, limit, direction, or cursor
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    Forbidden:
      description: The role or token scope does not allow the operation
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    NotFound:
      description: Resource not found or outside the token owner's access
    RateLimited:
      description: Per-token limit of 120 requests per minute exceeded
  securitySchemes:
    personalToken:
      type: http
      scheme: bearer
      bearerFormat: hckrt_pat token

````