> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Get scan results (Summaries)

GET https://api.hiddenlayer.ai/scan/v3/results

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/results/list

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Query parameters

- `model_version_ids` (list of string, optional) — Model Version IDs
- `model_ids` (list of string, optional) — Model ID
- `start_time` (datetime, optional) — Start Time
- `end_time` (datetime, optional) — End Time
- `severity` (ScanV3ResultsGetParametersSeverity, optional) — Severities
- `status` (list of string, optional) — Statuses
- `request_source` (list of enum, optional) — Filter by request source using a comma-separated list
  - Allowed values: `Hybrid Upload`, `API Upload`, `Integration`, `UI Upload`, `AI Asset Discovery`
- `region` (list of string, optional) — Filter by region of the discovered asset
- `provider` (list of string, optional) — Filter by model provider name
- `limit` (integer, optional, default: 25)
- `offset` (integer, optional, default: 0)
- `sort` (string, optional, default: -start_time) — allow sorting by model name, status, severity, scan start time, asset region, or model provider ascending (+) or the default descending (-)
- `latest_per_model_version_only` (boolean, optional, default: false) — only return latest result per model version
- `source` (ScanV3ResultsGetParametersSource, optional) — source of model related to scans
- `scanner_version` (string, optional) — filter by version of the scanner
- `detection_category` (string, optional) — filter by a single detection category
- `model_name` (ScanV3ResultsGetParametersModelName, optional) — filter by the model name
- `compliance_status` (list of enum, optional) — A comma separated list of rule set evaluation statuses to include
  - Allowed values: `COMPLIANT`, `NONCOMPLIANT`
- `deep_scan` (boolean, optional) — When true, returns only scans that with files. When false, returns only scans without files. When not provided, returns all scans.

## Response

### 200

Successful response

- `items` (list of ScanReportOfRecordV3Summary, required) — List of items. If no matching items are found, then `[]` will be returned.
- `total` (double, required) — Total number of items available based on the query criteria.
- `limit` (integer, required, default: 25) — Maximum number of items to return
- `offset` (integer, required, default: 0) — Begin returning the results from this offset

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 404 Not Found Error

The specified resource was not found.

- `any`

## Types

### ScanV3ResultsGetParametersSeverity

### ScanV3ResultsGetParametersSource

- `eq` (enum, optional)
  - Allowed values: `adhoc`

### ScanV3ResultsGetParametersModelName

- `eq` (string, optional)
- `contains` (string, optional)

### ScanReportOfRecordV3Summary

A scan report without any file results.

- `version` (string, required) — scanner version
- `scan_id` (string, required) — unique identifier for the scan
- `start_time` (datetime, required) — time the scan started
- `status` (enum, required) — status of the scan
  - Allowed values: `pending`, `running`, `done`, `failed`, `canceled`
- `inventory` (ScanModelInventoryComboV3, required)
- `summary` (ScanReportOfRecordV3SummarySummary, required)
- `file_count` (integer, required, deprecated) — number of files scanned; use `.summary.file_count` instead
- `files_with_detections_count` (integer, required, deprecated) — number of files with detections found; use `.summary.files_with_detections_count` instead
- `detection_count` (integer, required, deprecated) — number of detections found; use `.summary.detection_count` instead
- `has_genealogy` (boolean, optional) — if there is model geneaology info available
- `$schema_version` (string, optional) — version of the scan report schema format
- `end_time` (datetime, optional) — time the scan ended
- `compliance` (ScanReportOfRecordV3SummaryCompliance, optional)
- `severity` (enum, optional) — The highest severity of any detections on the scan, including "safe". Use `.summary.highest_severity` instead.
  - Allowed values: `critical`, `high`, `medium`, `low`, `unknown`, `safe`
- `detection_categories` (list of string, optional, deprecated) — list of detection categories found; use `.summary.detection_categories` instead

### ScanModelInventoryComboV3

- `model_name` (string, required) — name of the model
- `requested_scan_location` (string, required) — Location to be scanned
- `model_id` (string, required) — Unique identifier for the model
- `model_version_id` (string, required) — unique identifier for the model version
- `model_version` (string, optional) — version of the model
- `model_source` (string, optional) — source (provider) info
- `file_location` (string, optional) — URL or path to the model files, if available
- `provider_details` (ProviderDetails, optional)
- `asset_region` (string, optional) — Region of discovered asset
- `requesting_entity` (string, optional) — Entity that requested the scan
- `request_source` (enum, optional) — Identifies the system that requested the scan
  - Allowed values: `Hybrid Upload`, `API Upload`, `Integration`, `UI Upload`, `AI Asset Discovery`
- `origin` (string, optional) — Specifies the platform or service where the model originated before being scanned

### ScanReportOfRecordV3SummarySummary

- `severity` (enum, optional) — The highest severity of any detections on the scan, including "safe". Use `.summary.highest_severity` instead.
  - Allowed values: `critical`, `high`, `medium`, `low`, `unknown`, `safe`
- `highest_severity` (enum, optional) — The highest severity of any detections on the scan.
  - Allowed values: `critical`, `high`, `medium`, `low`, `none`, `unknown`
- `detection_count` (integer, optional) — total number of detections found
- `advisory_count` (integer, optional) — total number of advisories found
- `file_count` (integer, optional) — total number of files scanned
- `files_with_detections_count` (integer, optional) — number of files that contain detections
- `detection_categories` (list of string, optional) — list of unique detection categories found
- `advisory_categories` (list of string, optional) — list of unique advisory categories found
- `files_failed_to_scan` (integer, optional) — number of files that failed during scanning
- `unknown_files` (integer, optional) — number of files with unknown file type

### ScanReportOfRecordV3SummaryCompliance

- `status` (enum, optional)
  - Allowed values: `COMPLIANT`, `NONCOMPLIANT`
- `evaluated_at` (datetime, optional) — The datetime when the rule set was evaluated against the scan result
- `rule_set_ids` (list of string, optional) — A list of non-default rule sets that were used when evaluating the scan result

### ProviderDetails

- `provider` (enum, required)
  - Allowed values: `AWS_BEDROCK`, `AWS_SAGEMAKER`, `AZURE_AI_FOUNDRY`, `AZURE_ML`, `DATABRICKS`
- `provider_model_id` (string, required) — The provider's unique identifier for the model. Examples: - AWS Bedrock: "anthropic.claude-3-5-sonnet-20241022-v2:0" - Azure AI Foundry: "Claude-3-5-Sonnet"
- `model_arn` (string, optional) — Optional full ARN or resource identifier for the model. Used for provisioned models, custom deployments, or cross-account access.
- `country` (string, optional) — Optional country code (ISO 3166-1 alpha-2) for the location where the model provider is primarily based.

## Examples

**Response**

```json
{
  "items": [
    {
      "version": "string",
      "scan_id": "string",
      "start_time": "2024-01-15T09:30:00Z",
      "status": "pending",
      "inventory": {
        "model_name": "keras-tf-2025-05-27",
        "requested_scan_location": "/files-to-scan",
        "model_id": "00000000-0000-0000-0000-000000000000",
        "model_version_id": "00000000-0000-0000-0000-000000000000",
        "model_version": "1.0.0",
        "model_source": "adhoc",
        "file_location": "https://huggingface.co/meta-llama/Llama-3.1-8B",
        "provider_details": {
          "provider": "AWS_BEDROCK",
          "provider_model_id": "anthropic.claude-3-5-sonnet-20241022-v2:0"
        },
        "asset_region": "string",
        "requesting_entity": "string",
        "request_source": "Hybrid Upload",
        "origin": "Hugging Face"
      },
      "summary": {
        "severity": "critical",
        "highest_severity": "critical",
        "detection_count": 1,
        "advisory_count": 1,
        "file_count": 1,
        "files_with_detections_count": 1,
        "detection_categories": [
          "string"
        ],
        "advisory_categories": [
          "string"
        ],
        "files_failed_to_scan": 1,
        "unknown_files": 1
      },
      "file_count": 1,
      "files_with_detections_count": 1,
      "detection_count": 1,
      "has_genealogy": true,
      "$schema_version": "string",
      "end_time": "2024-01-15T09:30:00Z",
      "compliance": {
        "status": "COMPLIANT",
        "evaluated_at": "2024-01-15T09:30:00Z",
        "rule_set_ids": [
          "string"
        ]
      },
      "severity": "critical",
      "detection_categories": [
        "string"
      ]
    }
  ],
  "total": 1.1,
  "limit": 50,
  "offset": 250
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/scan/v3/results"

querystring = {"model_version_ids":"00fb9505-b9ac-4703-91a7-9d4859315a4b,0278fa73-4b08-47ca-bc23-33bc244719be","model_ids":"00fb9505-b9ac-4703-91a7-9d4859315a4b,2df09dc6-a0eb-4f67-9fe9-139ac3b75d11","start_time":"2025-05-27T00:00:00Z","end_time":"2025-05-27T23:59:59Z","severity":"critical","status":"done,failed","request_source":"Hybrid Upload","region":"[\"us-east-1,eu-west-1\"]","provider":"[\"AWS_BEDROCK,AZURE_AI_FOUNDRY\"]","scanner_version":"1.0.0","detection_category":"Embedded Payloads","model_name":"{\"eq\":\"tensorflow12\"}","compliance_status":"COMPLIANT","deep_scan":"true"}

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers, params=querystring)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/scan/v3/results?model_version_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C0278fa73-4b08-47ca-bc23-33bc244719be&model_ids=00fb9505-b9ac-4703-91a7-9d4859315a4b%2C2df09dc6-a0eb-4f67-9fe9-139ac3b75d11&start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&severity=critical&status=done%2Cfailed&request_source=Hybrid+Upload&region=%5B%22us-east-1%2Ceu-west-1%22%5D&provider=%5B%22AWS_BEDROCK%2CAZURE_AI_FOUNDRY%22%5D&scanner_version=1.0.0&detection_category=Embedded+Payloads&model_name=%7B%22eq%22%3A%22tensorflow12%22%7D&compliance_status=COMPLIANT&deep_scan=true")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```