Returns a list of issues. Defaults to Open status when status is not provided.
Endpoint: GET /v1/issues. Authentication: requires AuthorizationHeader bearer token unless this operation's security is changed. Required AuthMind permission/scope: issues (grant this scope on the API token in Admin > API Tokens; a token without it receives 403 Forbidden). Documented parameters: from, size, sort_by, order_by, gen_timestamp_gt, first_flow_time_gt, risk, issue_type, playbook_name, status, issue_id. Pagination: use from and/or size as documented. Pagination convention for this endpoint: from is a one-based page number (default 1), size is the page length (default 50, subject to this endpoint's documented maximum). Sorting: use only documented sort fields and sort-order enum values. Response parsing: inspect success; on failure inspect error, errors, or message depending on the referenced schema.
Sort by field name
Controls sorting. Use only documented enum values when provided.
Allowed values: issue_id, issue_flows_count, issue_access_count, gen_timestamp, playbook_name, risk, issue_type, first_flow_time.
Used to retrieve only a specific issue type. If left empty, the issues will be retrieved for all the types.(recommended)
Allowed values: Access from Anonymous IP, Access from Public VPN, Access from Unauthorized Countries, Access to Anonymous IP, Access to Public VPN, Access to Unauthorized Countries, Auth Hash Quality, Auth Hash Security, Auth Protocol Quality, Compromised Password, Compromised User, Deviation in Daily Asset Activity, Enumeration of AD Admins, Enumeration of AD Users, Exposed Assets, Lack of MFA, Identity No MFA, Asset No MFA, Shadow Access, Shadow Assets, Shadow Identity Systems, Suspected AD NTLM Relay Attack, Suspected Attack on Disabled AD Account, Suspected Attack on Expired AD Account, Suspected Attack on Locked AD Account, Suspected AD Brute-force Attack, Suspected Identity Brute-force Attack, Suspected Directory/IdP Bot Attack, Suspected Directory/IdP Password Spray Attack, Suspicious Inbound Access, Suspicious Outbound Access, Unauthorized Asset Access, Unknown SaaS Access, Weak Password, Unauthorized Identity Access, Impossible Travel, Suspected Access Token Sharing.
- Mock serverhttps://apidoc.authmind.com/_mock/v1/docs/v1/issues
- https://apidoc.authmind.com/{{.Host}}/amapihttps://apidoc.authmind.com/{{.Host}}/amapi/v1/issues
curl -i -X GET \
'https://apidoc.authmind.com/_mock/v1/docs/v1/issues?from=0&size=0&sort_by=issue_id&order_by=asc&gen_timestamp_gt=string&first_flow_time_gt=string&risk=4&issue_type=Access%20from%20Anonymous%20IP&playbook_name=string&status=Open&issue_id=string' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>'Request completed successfully. See the referenced schema for the response envelope and result payload.
Error message returned when the request fails. This is free-form, human-readable text intended for logging/display -- AuthMind does not define a stable, cross-endpoint error-code contract for it. Branch integration logic on the HTTP status code and the success boolean, not on the contents of this string.
Primary response payload for this endpoint.
[ { "issue_id": 17263, "message": "The directory on example.com uses a weak hash algorithm md4 which is not secure and easy to crack.", "issue_flows_count": 42, "issue_access_count": 8, "first_flow_time": "2024-07-01T10:31:42.000Z", "gen_timestamp": "2024-08-01T10:31:42.000Z", "issue_type": "Auth Hash Security", "playbook_name": "Auth Hash Security Playbook", "risk": 3, "incident_accesses_url": "https://console.authmind.com/issues?q=id%3A3817066", "incident_access_api": "https://console.authmind.com/amapi/v1/issue/17263-1722579276407/accesses" } ]
{ "error": "", "result": [ { … } ], "success": true, "total": 2 }