> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# List scan result files

GET https://api.hiddenlayer.ai/scan/v3/results/{scan_id}/files

Returns a cursor-paginated list of file results for a given scan. Results are sorted by compliance status, then highest detection severity, then file path.

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/results/list-files

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Path parameters

- `scan_id` (string, required)

## Response

### 200

Paginated file results

- `items` (list of ScanFileResultWithComplianceV3, required) — Array of items for this page

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 404 Not Found Error

The specified resource was not found.

- `any`

## Types

### ScanFileResultWithComplianceV3

- `file_instance_id` (string, required) — unique ID of the file
- `file_location` (string, required) — full file path
- `start_time` (datetime, required) — time the scan started
- `end_time` (datetime, required) — time the scan ended
- `details` (FileDetailsV3, required)
- `status` (enum, required) — status of the scan
  - Allowed values: `skipped`, `pending`, `running`, `done`, `failed`, `canceled`
- `seen` (datetime, required) — time the scan was seen at
- `detections` (list of ScanDetectionV3, required)
- `advisories` (list of ScanAdvisoryV3, optional) — informational advisories associated with this file (e.g. tokenizer family)
- `file_error` (list of string, optional) — Error messages returned by the scanner
- `compliance` (ScanFileResultWithComplianceV3Compliance, optional)

### FileDetailsV3

- `estimated_time` (string, required) — estimated time to scan the file
- `sha256` (string, required) — hexadecimal sha256 hash of file
- `file_type` (string, required) — type of the file
- `md5` (string, optional) — hexadecimal md5 hash of file
- `tlsh` (string, optional) — TLSH hash of file
- `file_size` (string, optional) — size of the file in human readable format
- `file_size_bytes` (integer, optional) — size of the file in bytes
- `file_type_details` (FileDetailsV3FileTypeDetails, optional)

### ScanDetectionV3

- `detection_id` (string, required) — unique identifier for the detection
- `rule_id` (string, required) — unique identifier for the rule that sourced the detection
- `risk` (enum, required) — detection risk
  - Allowed values: `MALICIOUS`, `SUSPICIOUS`
- `category` (string, required) — Vulnerability category for the detection
- `description` (string, required) — detection description
- `likelihood` (string, required) — detection likelihood
- `impact` (string, required) — detection impact
- `severity` (enum, required) — The severity of the detection.
  - Allowed values: `critical`, `high`, `medium`, `low`
- `mitre_atlas` (list of ScanDetectionV3MitreAtlasItems, required)
- `owasp` (list of string, required)
- `cve` (list of string, required)
- `cwe` (string, required)
- `cwe_href` (string, required) — CWE URL for the detection
- `rule_details` (list of ScanDetectionV3RuleDetailsItems, optional)
- `technical_blog_hrefs` (list of string, optional) — Hiddenlayer Technical Blog URLs for the detection
- `technical_blog_href` (string, optional, deprecated) — Hiddenlayer Technical Blog URL for the detection

### ScanAdvisoryV3

An informational advisory associated with a file. Advisories carry guidance about a property of the model (e.g. tokenizer family) that may matter to a downstream consumer, but do not represent a concrete detection.

- `advisory_id` (string, required) — unique identifier for the advisory
- `rule_id` (string, required) — unique identifier for the rule that sourced the advisory
- `category` (string, required) — category for the advisory
- `description` (string, required) — advisory description

### ScanFileResultWithComplianceV3Compliance

- `status` (enum, optional)
  - Allowed values: `COMPLIANT`, `NONCOMPLIANT`
- `rationale` (list of string, optional)

### FileDetailsV3FileTypeDetails

### ScanDetectionV3MitreAtlasItems

- `technique` (string, optional) — MITRE Atlas Technique
- `tactic` (string, optional) — MITRE Atlas Tactic

### ScanDetectionV3RuleDetailsItems

- `status` (enum, optional) — status
  - Allowed values: `created`, `deprecated`, `updated`, `superseded`
- `status_at` (datetime, optional) — date-time when the details entry was created
- `description` (string, optional) — description of the deprecation

### GGUFFileAttributes

- `subtype` (list of string, required)

### KerasFileAttributes

- `subtype` (list of string, required)
- `pickle_modules` (list of string, required)
- `keras_version` (string, optional) — version of the Keras file
- `keras_class_name` (string, optional)
- `keras_date_saved_at` (string, optional)
- `keras_module` (string, optional)

### NumpyFileAttributes

- `subtype` (list of string, required)
- `numpy_arrays` (string, required)
- `numpy_shape` (list of string, required)

### RDSFileAttributes

- `subtype` (list of string, required)
- `rds_encoding` (string, required) — encoding of the RDS file
- `rds_min_reader_version` (string, required) — minimum reader version for the RDS file
- `rds_version` (string, required) — version of the RDS file
- `rds_writer_version` (string, required) — version of the RDS writer

## Examples

**Response**

```json
{
  "items": [
    {
      "file_instance_id": "string",
      "file_location": "string",
      "start_time": "2024-10-16T23:38:32.278Z",
      "end_time": "2024-10-16T23:38:32.354Z",
      "details": {
        "estimated_time": "string",
        "sha256": "a54d88e06612d820bc3be72877c74f257b561b19",
        "file_type": "safetensors",
        "md5": "ce114e4501d2f4e2dcea3e17b546f339",
        "tlsh": "T1C50757F93C74D00C05B70C0793A1D5A9DF3F6D3A2F7AD940F3BFBF07B3BDF5A1D293",
        "file_size": "9 GB",
        "file_size_bytes": 9663676416,
        "file_type_details": {
          "subtype": [
            "string"
          ]
        }
      },
      "status": "skipped",
      "seen": "2024-10-22T17:59:12.431Z",
      "detections": [
        {
          "detection_id": "00000000-0000-0000-0000-000000000000",
          "rule_id": "PICKLE_0055_202408",
          "risk": "MALICIOUS",
          "category": "Arbitrary Code Execution",
          "description": "Found lambda embedded in keras model allowing custom layers that support  arbitrary expression execution",
          "likelihood": "medium",
          "impact": "critical",
          "severity": "critical",
          "mitre_atlas": [
            {
              "technique": "string",
              "tactic": "string"
            }
          ],
          "owasp": [
            "string"
          ],
          "cve": [
            "string"
          ],
          "cwe": "string",
          "cwe_href": "string",
          "rule_details": [
            {
              "status": "created",
              "status_at": "2024-01-15T09:30:00Z",
              "description": "string"
            }
          ],
          "technical_blog_hrefs": [
            "string"
          ],
          "technical_blog_href": "string"
        }
      ],
      "advisories": [
        {
          "advisory_id": "00000000-0000-0000-0000-000000000000",
          "rule_id": "SAFETENSORS_0001_202512",
          "category": "TokenBreak",
          "description": "Models using the BPE and WordPiece tokenization strategies are vulnerable to TokenBreak"
        }
      ],
      "file_error": [
        "File not found"
      ],
      "compliance": {
        "status": "COMPLIANT",
        "rationale": [
          "string"
        ]
      }
    }
  ],
  "first": "string",
  "prev": "string",
  "next": "string",
  "last": "string"
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/scan/v3/results/scan_id/files"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/scan/v3/results/scan_id/files';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/scan/v3/results/scan_id/files"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/scan/v3/results/scan_id/files")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.hiddenlayer.ai/scan/v3/results/scan_id/files")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.hiddenlayer.ai/scan/v3/results/scan_id/files', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/scan/v3/results/scan_id/files");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/scan/v3/results/scan_id/files")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```