Recent analysis jobs (the runs list). `?limit=` (default 50).
const url = 'https://example.com/api/v1/analysis/jobs';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/analysis/jobs \ --header 'Authorization: Bearer <token>'Skeleton mode has no runner, so this answers an empty list rather than a 503: the runs list is a panel on a page that otherwise works, and an error there would break the page.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Responses
Section titled “Responses”Recent runs, newest first; empty when this deployment has no runner
A job row, as served to the API / SSE. Timestamps are epoch-millis so the WebUI formats relative times without a date dependency.
object
Examplegenerated
[ { "created_ms": 1, "error": "example", "finding_count": 1, "finished_ms": 1, "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "params": "example", "pct": 1, "phase": "example", "scope_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "scope_kind": "example", "scope_label": "example", "started_ms": 1, "state": "example", "summary": "example", "tool": "example" }]No valid bearer token
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Role lacks the read permission
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}