Skip to main content
GET
List the filterable facet values a set of findings carries, with counts

Authorizations

Authorization
string
header
required

An Earnie API key, sent as Authorization: Bearer sk_earnie_.... Create one under Settings > API keys. The key's scopes decide which operations it may call.

Query Parameters

org_id
string<uuid>

Optional. Defaults to the authenticated principal's organization. When supplied it MUST match the caller's org (else 403).

project_id
string<uuid>
state
string

One of open, assigned, resolved, superseded_by_rule, reopened, as GET /v1/findings' own state filter accepts it. An unrecognised value is rejected with 400 rather than ignored, for the same reason an unrecognised facet path is. Not declared as an inline enum deliberately. oapi-codegen names a generated enum constant by its bare value unless another enum in the same document shares it, so repeating these five values here renames the constants of unrelated operations that happen to share one. The vocabulary is findings/domain.State either way, and this endpoint checks against it directly.

domain_slug
string

Narrow to one producing scanner, as on GET /v1/findings.

scan_id
string<uuid>
path_prefix
string

Same exact-path-or-subtree match as GET /v1/findings. Do NOT pass a trailing slash.

purl
string
facet
string[]

The current selection, counted disjunctively (see above). The same <path>:<value> vocabulary and validation as GET /v1/findings' facet: values of one path are OR-ed, paths are AND-ed, and an unrecognised or non-entitled path is rejected with 400.

q
string

Free-text SUBSEQUENCE search over a finding's path, purl, basename and title: the exact haystack and matcher of GET /v1/findings/files' q, so a count here equals the number of findings that list aggregates for the same query.

domain
string

Narrow to one product finding family (oss, deps, crypto, ai, provenance), as GET /v1/findings' domain. Unknown values are ignored (no filter applied), exactly as GET /v1/findings ignores them, so the counts keep describing the list. Not declared as an inline enum, for the reason state above gives.

path
string[]

Restrict the response to these facet paths. Repeatable. Omitted returns every path the narrowed population carries and this organization is entitled to see. An unrecognised path is rejected with 400, for the same reason the list filter rejects one.

limit
integer
default:100

Maximum values per facet path, ordered by count descending then value ascending. A path with more sets truncated, so a caller can tell a short list from a complete one. Out-of-range values fall back to the default.

Required range: x <= 1000

Response

The facet values the narrowed findings carry

facets
object[]
required