Skip to content

ListIssues

Request

Returns a list of issues. Defaults to Open status when status is not provided.

Endpoint: GET /v1/issues. Authentication: requires AuthorizationHeader bearer token unless this operation's security is changed. Required AuthMind permission/scope: issues (grant this scope on the API token in Admin > API Tokens; a token without it receives 403 Forbidden). Documented parameters: from, size, sort_by, order_by, gen_timestamp_gt, first_flow_time_gt, risk, issue_type, playbook_name, status, issue_id. Pagination: use from and/or size as documented. Pagination convention for this endpoint: from is a one-based page number (default 1), size is the page length (default 50, subject to this endpoint's documented maximum). Sorting: use only documented sort fields and sort-order enum values. Response parsing: inspect success; on failure inspect error, errors, or message depending on the referenced schema.

Security
AuthorizationHeader
Query
frominteger

Page number

Pagination parameter. One-based page number for this endpoint (default 1, minimum 1).

sizeinteger

Record per page

Pagination page size / maximum records to return. Respect any endpoint-specific default or maximum stated here.

sort_bystring

Sort by field name

Controls sorting. Use only documented enum values when provided.

Allowed values: issue_id, issue_flows_count, issue_access_count, gen_timestamp, playbook_name, risk, issue_type, first_flow_time.

Enum:"issue_id""issue_flows_count""issue_access_count""gen_timestamp""playbook_name""risk""issue_type""first_flow_time"
order_bystring

Order by field asc/desc. If not set it is by default descending.

Controls sorting. Use only documented enum values when provided.

Allowed values: asc, desc.

Enum:"asc""desc"
gen_timestamp_gtstring

Latest activity time greater than

Use the timestamp format stated in this endpoint (YYYY-MM-DD HH:MM:SS), interpreted as UTC.

first_flow_time_gtstring

first flow time greater than

Use the timestamp format stated in this endpoint (YYYY-MM-DD HH:MM:SS), interpreted as UTC.

riskstring

Risk associated with the playbook selected. 4 is critical, 3 is high risk, 2 is medium and 1 means Low risk

Allowed values: 4, 3, 2, 1.

Enum:"4""3""2""1"
issue_typestring

Used to retrieve only a specific issue type. If left empty, the issues will be retrieved for all the types.(recommended)

Allowed values: Access from Anonymous IP, Access from Public VPN, Access from Unauthorized Countries, Access to Anonymous IP, Access to Public VPN, Access to Unauthorized Countries, Auth Hash Quality, Auth Hash Security, Auth Protocol Quality, Compromised Password, Compromised User, Deviation in Daily Asset Activity, Enumeration of AD Admins, Enumeration of AD Users, Exposed Assets, Lack of MFA, Identity No MFA, Asset No MFA, Shadow Access, Shadow Assets, Shadow Identity Systems, Suspected AD NTLM Relay Attack, Suspected Attack on Disabled AD Account, Suspected Attack on Expired AD Account, Suspected Attack on Locked AD Account, Suspected AD Brute-force Attack, Suspected Identity Brute-force Attack, Suspected Directory/IdP Bot Attack, Suspected Directory/IdP Password Spray Attack, Suspicious Inbound Access, Suspicious Outbound Access, Unauthorized Asset Access, Unknown SaaS Access, Weak Password, Unauthorized Identity Access, Impossible Travel, Suspected Access Token Sharing.

Enum:"Access from Anonymous IP""Access from Public VPN""Access from Unauthorized Countries""Access to Anonymous IP""Access to Public VPN""Access to Unauthorized Countries""Auth Hash Quality""Auth Hash Security""Auth Protocol Quality""Compromised Password"
playbook_namestring

Playbook name

statusstring

Incident status. Defaults to Open when not provided.

Allowed values: Open, Closed, Resolved.

Enum:"Open""Closed""Resolved"
issue_idstring

Issue id

curl -i -X GET \
  'https://apidoc.authmind.com/_mock/v1/docs/v1/issues?from=0&size=0&sort_by=issue_id&order_by=asc&gen_timestamp_gt=string&first_flow_time_gt=string&risk=4&issue_type=Access%20from%20Anonymous%20IP&playbook_name=string&status=Open&issue_id=string' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>'

Responses

Request completed successfully. See the referenced schema for the response envelope and result payload.

Bodyapplication/json
errorstring

Error message returned when the request fails. This is free-form, human-readable text intended for logging/display -- AuthMind does not define a stable, cross-endpoint error-code contract for it. Branch integration logic on the HTTP status code and the success boolean, not on the contents of this string.

resultArray of objects(models.IssueListingOut)

Primary response payload for this endpoint.

Example:
[ { "issue_id": 17263, "message": "The directory on example.com uses a weak hash algorithm md4 which is not secure and easy to crack.", "issue_flows_count": 42, "issue_access_count": 8, "first_flow_time": "2024-07-01T10:31:42.000Z", "gen_timestamp": "2024-08-01T10:31:42.000Z", "issue_type": "Auth Hash Security", "playbook_name": "Auth Hash Security Playbook", "risk": 3, "incident_accesses_url": "https://console.authmind.com/issues?q=id%3A3817066", "incident_access_api": "https://console.authmind.com/amapi/v1/issue/17263-1722579276407/accesses" } ]
successboolean

Indicates whether the request was successful.

totalinteger

Total number of records matching the request, when provided by the API.

Example:2
Response
{ "error": "", "result": [ { … } ], "success": true, "total": 2 }