List decisions for a control
curl --request GET \
--url https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"page": 123,
"per_page": 123,
"total_pages": 123,
"total_count": 123,
"decisions": [
{
"attestation_id": "<string>",
"created_at": 123,
"is_compliant": true,
"attestation_name": "<string>",
"control_version": 123,
"artifact_fingerprint": "<string>",
"artifact_name": "<string>",
"flow_name": "<string>",
"trail_name": "<string>"
}
],
"_links": {}
}{
"message": "You don't have permission to access this resource"
}{
"message": "Control not found"
}List decisions for a control
Beta — the Controls feature is in beta. Requests from organizations without it enabled receive 403 Forbidden.
GET
/
controls
/
{org}
/
{identifier}
/
decisions
List decisions for a control
curl --request GET \
--url https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.kosli.com/api/v2/controls/{org}/{identifier}/decisions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"page": 123,
"per_page": 123,
"total_pages": 123,
"total_count": 123,
"decisions": [
{
"attestation_id": "<string>",
"created_at": 123,
"is_compliant": true,
"attestation_name": "<string>",
"control_version": 123,
"artifact_fingerprint": "<string>",
"artifact_name": "<string>",
"flow_name": "<string>",
"trail_name": "<string>"
}
],
"_links": {}
}{
"message": "You don't have permission to access this resource"
}{
"message": "Control not found"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Query Parameters
Page number
Required range:
x >= 1Number of decisions per page
Required range:
1 <= x <= 100Filter by compliance status
Filter decisions recorded at or after this Unix timestamp
Filter decisions recorded at or before this Unix timestamp
Filter decisions to these flows. Can be repeated, e.g. flow_id=&flow_id=
Sort by decision time: desc (newest first) or asc (oldest first)
Available options:
asc, desc Last modified on September 2, 2026