Skip to main content
GET
Contract risk flags

Authorizations

Authorization
string
header
required

OAuth 2.1 authorization code + PKCE (S256). Tokens are tenant-bound (company_id) and scoped. Discover endpoints via /.well-known/oauth-authorization-server.

Query Parameters

client
string

Agencies only: scan an owned client company instead of the token's own company. A company outside the caller's subtree returns 404, which masks whether it exists. Omit to scan the token's company.

Response

Success. Returns the resource envelope.

data
object
required

Early-warning risk flags across your own live contracts.