Skip to content

Get an event

GET /v1/events/{id} reads a decision and its review status. Use it to poll a REVIEW. The body is the same as POST /v1/events, including finalDecision, quotaExceeded, and sandbox.

Resolving a review does not emit a new webhook. decision stays at the value recorded when the event was created. While the review is pending, finalDecision is REVIEW. After approval it is ALLOW. After denial or expiry it is BLOCK.

Terminal window
curl "https://api.vulnify.io/v1/events/EVENT_ID" \
-H "Authorization: Bearer $VULNIFY_API_KEY"
const decision = await vulnify.getEvent(eventId);
decision = vulnify.get_event(event_id)

X-API-Key may replace the bearer header.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Parameters.
NameInRequiredTypeDescription
idpathyesstring

The same decision body as POST /v1/events, including quotaExceeded, sandbox and finalDecision

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Response body.
FieldTypeRequiredDescription
idstring (uuid)yes
decisionALLOW | REVIEW | BLOCKyesDecision recorded on the event. It does not change when a review is resolved.
finalDecisionALLOW | REVIEW | BLOCKyesEffective outcome. Equals `decision` when there is no review. REVIEW while a review is pending. ALLOW after approval, BLOCK after denial or expiry. Always present, including an idempotent replay of a response stored before this field existed: the replay derives it from the stored decision and the current review.
evaluatedDecisionALLOW | REVIEW | BLOCKyesWhat full enforcement would have decided. Differs from `decision` in monitor mode.
monitoredbooleanyes
riskLevelLOW | MEDIUM | HIGH | CRITICALyes
riskScoreinteger (0–100)yes
reasonsarray of stringyes
policyobject or nullyes
policy.idstring (uuid)yes
policy.namestringyes
dlpFindingsarray of stringyesSensitive-data types found in `content`.
lgpdCategoriesarray of IDENTIFICATION | CONTACT | LOCATION | FINANCIAL | HEALTH | COMPANY | CREDENTIALSyesLGPD categories derived from `dlpFindings`.
reviewobject or nullyesNull when the event has no human review.
review.statusPENDING | APPROVED | DENIED | EXPIREDyes
review.expiresAtstring or null (date-time)yes
review.decidedAtstring or null (date-time)yes
review.notestring or nullyes
quotaExceededbooleanyesPlan quota is over the limit. The decision is still made.
sandboxbooleanyesTrue when the event was created with a TEST key.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Response headers.
HeaderDescription
X-Request-IdRequest id for support and log correlation (a caller-sent plain id is kept).
x-api-versionMachine API contract (v1).
x-vulnify-versionAPI build (SemVer, see /changelog).
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Error responses.
StatusMeaning
400Validation error, or agent/resource was not identified
401Missing, invalid, revoked or expired API key
403API key is bound to another agent, or the caller IP is not in the key allowlist
404Unknown agent, resource, event or gateway route
429Rate limit exceeded

This route does not return 413. There is no Idempotency-Key and no Idempotent-Replay header.

Node.js getEvent throws on any non-OK status. It does not retry and it does not apply failMode. Python get_event retries timeouts, network errors, 408, 429, and 5xx, then raises VulnifyError. It does not apply fail_mode. See Errors.

The id comes from the id field of the create response. A fallback decision produced when the API was unreachable has id: null and cannot be fetched.

@vulnify/sdk 0.2.3 requires finalDecision on getEvent, and the result includes quotaExceeded and sandbox. vulnify 0.3.0 copies finalDecision to final_decision (still optional on Decision) and copies quotaExceeded and sandbox. The machine contract requires finalDecision, quotaExceeded, and sandbox on this body, including an idempotent replay of finalDecision.