Get an audit report
Findings, deltas against the previous run, and the outcome review of changes made since. runId accepts the literal latest for the most recent completed run.
Required scope: read.
Authorization
bearerAuth An API key from Workspace → Settings → API keys, sent as Authorization: Bearer tsk_….
Authorization has two independent axes.
The scope is ranked — a key satisfies any requirement at or below its own tier:
read— see state. Never changes anything.write— propose changes (theactions/*endpoints), trigger audits and reports.admin— connection, account import, sync, targets and brief.
There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.
The approval grant (can_approve) is a separate boolean, not a rung. Deciding a queued proposal — approve, reject, revert — needs write and the grant. Keeping them on separate axes is what makes the review gate a control rather than a convention: a key that may propose is not automatically a key that may approve its own proposal.
A key is either org-scoped (reaches every account, optionally limited to a subset) or bound to a single account.
In: header
Path Parameters
The account's project UUID — from GET /accounts, NOT the Apple asaOrgId. Pass the literal current with an account-scoped key to use its bound account.
An audit run UUID, or the literal latest.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/api/v1/accounts/current/audits/latest"{}