Returns a finding when it belongs to the specified campaign. Returns 404 if the finding is not part of that campaign.
Optional caller-supplied correlation id. Must be a UUID when present. When omitted or blank, the API generates a UUID. A non-UUID value returns 400 CORRELATION.INVALID. If a write fails because a UUID is already in use, the API returns 409 UUID.DUPLICATE. The value used (caller or generated) is echoed as supportToken and in the X-Correlation-ID response header.
- Generated server urlhttps://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/campaigns/{campaignId}/findings/{resultId}
curl -i -X GET \
'https://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/campaigns/{campaignId}/findings/{resultId}?pretty=false' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'X-Correlation-ID: 497f6eca-6276-4993-bfeb-53cbbbba6f08'Finding resource. probeId and strategyId are human-readable probe and strategy names. gradingResult includes pass, score (finding risk score), and reason. Failed findings expose the explanation only under gradingResult.reason; top-level error appears only for runtime-error findings. _links.suppress is present when the finding is not suppressed; _links.unsuppress when it is suppressed.
{ "supportToken": "5bac741e-3f1c-4cd4-ad0d-a1492df0a5cc", "response": { "id": "string", "campaignId": "13f8bf6d-dc27-4a04-bffe-6e5b13c19ddf", "targetId": "cbca1126-180e-4334-9df8-cf82289d378b", "probeId": "string", "strategyId": "string", "prompt": "string", "output": "string", "error": "string", "gradingResult": { … }, "suppression": { … }, "multiInputPrompts": [ … ], "_links": { … } } }