Skip to main content
GET
Search accessible reports

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

programId
integer[]

Repeat to match any program ID.

Maximum array length: 100
statusId
integer[]

Repeat to match any status ID.

Maximum array length: 100
severityId
integer[]

Repeat to match any severity ID.

Maximum array length: 100
targetId
integer[]

Repeat to match any target ID.

Maximum array length: 100
assignedToUserId
string[]

Repeat to match any assignee user ID. Cannot be combined with isAssigned=false.

Maximum array length: 100
reporterUserId
string[]

Repeat to match any reporter user ID.

Maximum array length: 100
isAssigned
boolean | null
isKnownIssue
boolean | null
isEmbeddedSubmission
boolean | null
isDuplicate
boolean | null
hasReward
boolean | null

Matches reports with a positive bounty or bonus.

q
string

Trimmed keyword, up to 200 characters, searched across report ID, title, summary, description, impact, and CVE.

Maximum string length: 200
createdFromUtc
string<date-time>

Inclusive creation lower bound.

createdToUtc
string<date-time>

Inclusive creation upper bound.

lastActivityFromUtc
string<date-time>

Inclusive last-activity lower bound.

lastActivityToUtc
string<date-time>

Inclusive last-activity upper bound.

sort
string
default:-createdAt,-id

Comma-separated fields; prefix descending fields with -. Allowed: id, createdAt, lastActivityAt, severity, status, bounty, name. Default: -createdAt,-id.

cursor
string

Opaque cursor from nextCursor. It is rejected if reused with different filters or sorting.

limit
integer
default:50
Required range: 1 <= x <= 100

Response

Stable cursor page of reports

items
object[]
nextCursor
string | null

Opaque base64url seek cursor. Pass it unchanged with the same filters and sort.