> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Search accessible reports

> Requires reports:read. Repeated values are ORed within one filter and different filters are ANDed. Up to 100 values are accepted per repeated filter. Sorting accepts at most three unique requested fields; report ID is added as a deterministic tie-breaker. New cursors are versioned opaque base64url values bound to the canonical filters and sort. Legacy createdAt:id cursors remain accepted only for the default -createdAt,-id ordering.



## OpenAPI

````yaml /openapi/external-admin-v1.json get /reports
openapi: 3.0.3
info:
  title: Hackrate External Admin API
  version: v1
  description: >-
    Program discovery and report triage for users with assigned Hackrate roles.
    Tokens are created in Profile Settings > External API.
servers:
  - url: https://www.hckrt.com/api/v1/admin
security:
  - personalToken: []
paths:
  /reports:
    get:
      summary: Search accessible reports
      description: >-
        Requires reports:read. Repeated values are ORed within one filter and
        different filters are ANDed. Up to 100 values are accepted per repeated
        filter. Sorting accepts at most three unique requested fields; report ID
        is added as a deterministic tie-breaker. New cursors are versioned
        opaque base64url values bound to the canonical filters and sort. Legacy
        createdAt:id cursors remain accepted only for the default -createdAt,-id
        ordering.
      parameters:
        - name: programId
          in: query
          description: Repeat to match any program ID.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: integer
        - name: statusId
          in: query
          description: Repeat to match any status ID.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: integer
        - name: severityId
          in: query
          description: Repeat to match any severity ID.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: integer
        - name: targetId
          in: query
          description: Repeat to match any target ID.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: integer
        - name: assignedToUserId
          in: query
          description: >-
            Repeat to match any assignee user ID. Cannot be combined with
            isAssigned=false.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: string
        - name: reporterUserId
          in: query
          description: Repeat to match any reporter user ID.
          style: form
          explode: true
          schema:
            type: array
            maxItems: 100
            items:
              type: string
        - name: isAssigned
          in: query
          schema:
            type: boolean
            nullable: true
        - name: isKnownIssue
          in: query
          schema:
            type: boolean
            nullable: true
        - name: isEmbeddedSubmission
          in: query
          schema:
            type: boolean
            nullable: true
        - name: isDuplicate
          in: query
          schema:
            type: boolean
            nullable: true
        - name: hasReward
          in: query
          description: Matches reports with a positive bounty or bonus.
          schema:
            type: boolean
            nullable: true
        - name: q
          in: query
          description: >-
            Trimmed keyword, up to 200 characters, searched across report ID,
            title, summary, description, impact, and CVE.
          schema:
            type: string
            maxLength: 200
          example: CVE-2026-1234
        - name: createdFromUtc
          in: query
          description: Inclusive creation lower bound.
          schema:
            type: string
            format: date-time
        - name: createdToUtc
          in: query
          description: Inclusive creation upper bound.
          schema:
            type: string
            format: date-time
        - name: lastActivityFromUtc
          in: query
          description: Inclusive last-activity lower bound.
          schema:
            type: string
            format: date-time
        - name: lastActivityToUtc
          in: query
          description: Inclusive last-activity upper bound.
          schema:
            type: string
            format: date-time
        - name: sort
          in: query
          description: >-
            Comma-separated fields; prefix descending fields with -. Allowed:
            id, createdAt, lastActivityAt, severity, status, bounty, name.
            Default: -createdAt,-id.
          schema:
            type: string
            default: '-createdAt,-id'
          example: '-lastActivityAt,-severity'
        - name: cursor
          in: query
          description: >-
            Opaque cursor from nextCursor. It is rejected if reused with
            different filters or sorting.
          schema:
            type: string
          example: eyJWZXJzaW9uIjoyLC4uLn0
        - name: limit
          in: query
          schema:
            type: integer
            default: 50
            minimum: 1
            maximum: 100
      responses:
        '200':
          description: Stable cursor page of reports
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ReportPage'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  schemas:
    ReportPage:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/ReportSummary'
        nextCursor:
          type: string
          nullable: true
          description: >-
            Opaque base64url seek cursor. Pass it unchanged with the same
            filters and sort.
    ReportSummary:
      type: object
      properties:
        id:
          type: integer
        name:
          type: string
        createdAt:
          type: string
          format: date-time
        lastActivityAt:
          type: string
          format: date-time
          description: >-
            Newest report timeline comment timestamp, or createdAt when the
            report has no comments.
        programId:
          type: integer
        target:
          $ref: '#/components/schemas/NamedIntegerValue'
        status:
          $ref: '#/components/schemas/NamedIntegerValue'
        severity:
          $ref: '#/components/schemas/NamedIntegerValue'
        reporter:
          $ref: '#/components/schemas/Person'
        assignedTo:
          allOf:
            - $ref: '#/components/schemas/Person'
          nullable: true
    ProblemDetails:
      type: object
      properties:
        type:
          type: string
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
    NamedIntegerValue:
      type: object
      properties:
        id:
          type: integer
        name:
          type: string
    Person:
      type: object
      properties:
        id:
          type: string
        nickname:
          type: string
        email:
          type: string
          format: email
  responses:
    BadRequest:
      description: Invalid filter, sort, range, limit, direction, or cursor
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    Forbidden:
      description: The role or token scope does not allow the operation
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    RateLimited:
      description: Per-token limit of 120 requests per minute exceeded
  securitySchemes:
    personalToken:
      type: http
      scheme: bearer
      bearerFormat: hckrt_pat token

````