Preview - List security alerts for the tenant

Preview: This endpoint is currently in a preview state and is subject to breaking changes without warning.

Preview endpoint. This endpoint is in preview: its request and response shapes may change without a version increment. A v2 of this API is planned to supersede it, targeting 2026-11.

Returns alerts (UDM/AI-visibility match reports) for the authenticated tenant in reverse-chronological order (newest first), backed by DynamoDB. Results are paginated with an opaque cursor.
Filters: at most one of host, analytic, or severity may be applied; supplying more than one selects the first match in priority order (host > analytic > severity) and ignores the others. The time range is applied as a BETWEEN on the chosen index's sort key.
Pagination: when more results are available, the response includes a cursor. Pass it back as the cursor query parameter on the next request to fetch the following page; all other filter/range parameters are encoded in the cursor and may be omitted on subsequent requests.

Required Permissions: ai-visibility:read

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
date-time

Absolute inclusive UTC start timestamp (RFC3339). Must be paired with end; cannot be combined with range.

date-time

Absolute exclusive UTC end timestamp (RFC3339). Must be paired with start; cannot be combined with range.

string
^\s*(?:\d+w)?\s*(?:\d+d)?\s*(?:\d+h)?\s*$

Relative look-back duration composed of optional weeks (w), days (d), and hours (h) segments, in that order (e.g. 24h, 7d, 1w, 1w2d3h). Resolved server-side to [now-range, now). Mutually exclusive with start/end. Defaults to 24h when no time parameters are supplied.

string
Defaults to UTC

IANA timezone name (e.g. America/New_York, Europe/Paris) used to express the resolved range. For the stats endpoints it aligns day and week bin boundaries to that timezone's local midnight / start-of-week before the window is normalized to UTC for querying. Has no effect on endpoints that do not bucket by time. Defaults to UTC when omitted.

string

Filter alerts to a single host (matched on context.identity.claims.clientid, lowercased). Mutually exclusive with analytic and severity; when more than one is supplied, host wins.

uuid

Filter alerts to a single analytic (UUID matching the triggering fact's uuid). Mutually exclusive with host and severity; when host is also set, host wins.

integer
enum

Filter alerts to a single severity level. Mutually exclusive with host and analytic; loses to both when more than one is supplied.

Allowed:
integer
≥ 1
Defaults to 50

Max number of grouped rows to return (top-N by the ordering metric). Defaults to 50 when omitted.

string

Opaque base64-encoded pagination cursor returned by a previous list response. When supplied, all other filter/range query parameters are ignored - they are baked into the cursor.

Headers
uuid
required
^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$

The environment UUID identifier.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
OAuth2
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json