> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Get scan results

GET https://api.hiddenlayer.ai/scan/v3/results/{scan_id}

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/results/retrieve

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Path parameters

- `scan_id` (string, required)

## Response

### 200

Successful response

- `version` (string, required) — scanner version
- `scan_id` (string, required) — unique identifier for the scan
- `start_time` (datetime, required) — time the scan started
- `status` (enum, required) — status of the scan
  - Allowed values: `pending`, `running`, `done`, `failed`, `canceled`
- `inventory` (ScanModelInventoryComboV3, required)
- `summary` (ScanReportOfRecordV3Summary, required) — A scan report without any file results.
- `file_count` (integer, required, deprecated) — number of files scanned; use `.summary.file_count` instead
- `files_with_detections_count` (integer, required, deprecated) — number of files with detections found; use `.summary.files_with_detections_count` instead
- `detection_count` (integer, required, deprecated) — number of detections found; use `.summary.detection_count` instead
- `has_genealogy` (boolean, optional) — if there is model geneaology info available
- `$schema_version` (string, optional) — version of the scan report schema format
- `end_time` (datetime, optional) — time the scan ended
- `intelligence` (ModelIntelligence, optional) — Intelligence metadata about a model including origin, licensing, and usage policies
- `compliance` (ScanReportOfRecordV3Compliance, optional)
- `file_results` (list of ScanFileResultV3, optional)
- `severity` (enum, optional) — The highest severity of any detections on the scan, including "safe". Use `.summary.highest_severity` instead.
  - Allowed values: `critical`, `high`, `medium`, `low`, `unknown`, `safe`
- `detection_categories` (list of string, optional, deprecated) — list of detection categories found; use `.summary.detection_categories` instead

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 404 Not Found Error

The specified resource was not found.

- `any`

## Types

### ScanModelInventoryComboV3

- `model_name` (string, required) — name of the model
- `requested_scan_location` (string, required) — Location to be scanned
- `model_id` (string, required) — Unique identifier for the model
- `model_version_id` (string, required) — unique identifier for the model version
- `model_version` (string, optional) — version of the model
- `model_source` (string, optional) — source (provider) info
- `file_location` (string, optional) — URL or path to the model files, if available
- `provider_details` (ProviderDetails, optional)
- `asset_region` (string, optional) — Region of discovered asset
- `requesting_entity` (string, optional) — Entity that requested the scan
- `request_source` (enum, optional) — Identifies the system that requested the scan
  - Allowed values: `Hybrid Upload`, `API Upload`, `Integration`, `UI Upload`, `AI Asset Discovery`
- `origin` (string, optional) — Specifies the platform or service where the model originated before being scanned

### ScanReportOfRecordV3Summary

A scan report without any file results.

- `version` (string, required) — scanner version
- `scan_id` (string, required) — unique identifier for the scan
- `start_time` (datetime, required) — time the scan started
- `status` (enum, required) — status of the scan
  - Allowed values: `pending`, `running`, `done`, `failed`, `canceled`
- `inventory` (ScanModelInventoryComboV3, required)
- `summary` (ScanReportOfRecordV3SummarySummary, required)
- `file_count` (integer, required, deprecated) — number of files scanned; use `.summary.file_count` instead
- `files_with_detections_count` (integer, required, deprecated) — number of files with detections found; use `.summary.files_with_detections_count` instead
- `detection_count` (integer, required, deprecated) — number of detections found; use `.summary.detection_count` instead
- `has_genealogy` (boolean, optional) — if there is model geneaology info available
- `$schema_version` (string, optional) — version of the scan report schema format
- `end_time` (datetime, optional) — time the scan ended
- `compliance` (ScanReportOfRecordV3SummaryCompliance, optional)
- `severity` (enum, optional) — The highest severity of any detections on the scan, including "safe". Use `.summary.highest_severity` instead.
  - Allowed values: `critical`, `high`, `medium`, `low`, `unknown`, `safe`
- `detection_categories` (list of string, optional, deprecated) — list of detection categories found; use `.summary.detection_categories` instead

### ModelIntelligence

Intelligence metadata about a model including origin, licensing, and usage policies

- `geographic_footprint` (list of string, optional) — List of countries where the model originated
- `country_of_origin` (string, optional) — ISO 3166-1 alpha-2 country code of the model's primary origin
- `contributor_trust_level` (string, optional) — Trust level of the model contributor
- `licenses` (list of ModelLicense, optional) — List of licenses associated with the model
- `usage_policies` (list of ModelUsagePolicy, optional) — List of usage policies associated with the model

### ScanReportOfRecordV3Compliance

- `status` (enum, optional)
  - Allowed values: `COMPLIANT`, `NONCOMPLIANT`
- `evaluated_at` (datetime, optional) — The datetime when the rule set was evaluated against the scan result
- `rule_set_ids` (list of string, optional) — A list of non-default rule sets that were used when evaluating the scan result

### ScanFileResultV3

- `file_instance_id` (string, required) — unique ID of the file
- `file_location` (string, required) — full file path
- `start_time` (datetime, required) — time the scan started
- `end_time` (datetime, required) — time the scan ended
- `details` (FileDetailsV3, required)
- `status` (enum, required) — status of the scan
  - Allowed values: `skipped`, `pending`, `running`, `done`, `failed`, `canceled`
- `seen` (datetime, required) — time the scan was seen at
- `detections` (list of ScanDetectionV3, required)
- `advisories` (list of ScanAdvisoryV3, optional) — informational advisories associated with this file (e.g. tokenizer family)
- `file_error` (list of string, optional) — Error messages returned by the scanner

### ProviderDetails

- `provider` (enum, required)
  - Allowed values: `AWS_BEDROCK`, `AWS_SAGEMAKER`, `AZURE_AI_FOUNDRY`, `AZURE_ML`, `DATABRICKS`
- `provider_model_id` (string, required) — The provider's unique identifier for the model. Examples: - AWS Bedrock: "anthropic.claude-3-5-sonnet-20241022-v2:0" - Azure AI Foundry: "Claude-3-5-Sonnet"
- `model_arn` (string, optional) — Optional full ARN or resource identifier for the model. Used for provisioned models, custom deployments, or cross-account access.
- `country` (string, optional) — Optional country code (ISO 3166-1 alpha-2) for the location where the model provider is primarily based.

### ScanReportOfRecordV3SummarySummary

- `severity` (enum, optional) — The highest severity of any detections on the scan, including "safe". Use `.summary.highest_severity` instead.
  - Allowed values: `critical`, `high`, `medium`, `low`, `unknown`, `safe`
- `highest_severity` (enum, optional) — The highest severity of any detections on the scan.
  - Allowed values: `critical`, `high`, `medium`, `low`, `none`, `unknown`
- `detection_count` (integer, optional) — total number of detections found
- `advisory_count` (integer, optional) — total number of advisories found
- `file_count` (integer, optional) — total number of files scanned
- `files_with_detections_count` (integer, optional) — number of files that contain detections
- `detection_categories` (list of string, optional) — list of unique detection categories found
- `advisory_categories` (list of string, optional) — list of unique advisory categories found
- `files_failed_to_scan` (integer, optional) — number of files that failed during scanning
- `unknown_files` (integer, optional) — number of files with unknown file type

### ScanReportOfRecordV3SummaryCompliance

- `status` (enum, optional)
  - Allowed values: `COMPLIANT`, `NONCOMPLIANT`
- `evaluated_at` (datetime, optional) — The datetime when the rule set was evaluated against the scan result
- `rule_set_ids` (list of string, optional) — A list of non-default rule sets that were used when evaluating the scan result

### ModelLicense

License information for a model

- `name` (string, required) — Name of the license
- `sha256` (string, required) — SHA256 hash of the license file

### ModelUsagePolicy

Usage policy information for a model

- `name` (string, required) — Name of the usage policy
- `sha256` (string, required) — SHA256 hash of the policy document

### FileDetailsV3

- `estimated_time` (string, required) — estimated time to scan the file
- `sha256` (string, required) — hexadecimal sha256 hash of file
- `file_type` (string, required) — type of the file
- `md5` (string, optional) — hexadecimal md5 hash of file
- `tlsh` (string, optional) — TLSH hash of file
- `file_size` (string, optional) — size of the file in human readable format
- `file_size_bytes` (integer, optional) — size of the file in bytes
- `file_type_details` (FileDetailsV3FileTypeDetails, optional)

### ScanDetectionV3

- `detection_id` (string, required) — unique identifier for the detection
- `rule_id` (string, required) — unique identifier for the rule that sourced the detection
- `risk` (enum, required) — detection risk
  - Allowed values: `MALICIOUS`, `SUSPICIOUS`
- `category` (string, required) — Vulnerability category for the detection
- `description` (string, required) — detection description
- `likelihood` (string, required) — detection likelihood
- `impact` (string, required) — detection impact
- `severity` (enum, required) — The severity of the detection.
  - Allowed values: `critical`, `high`, `medium`, `low`
- `mitre_atlas` (list of ScanDetectionV3MitreAtlasItems, required)
- `owasp` (list of string, required)
- `cve` (list of string, required)
- `cwe` (string, required)
- `cwe_href` (string, required) — CWE URL for the detection
- `rule_details` (list of ScanDetectionV3RuleDetailsItems, optional)
- `technical_blog_hrefs` (list of string, optional) — Hiddenlayer Technical Blog URLs for the detection
- `technical_blog_href` (string, optional, deprecated) — Hiddenlayer Technical Blog URL for the detection

### ScanAdvisoryV3

An informational advisory associated with a file. Advisories carry guidance about a property of the model (e.g. tokenizer family) that may matter to a downstream consumer, but do not represent a concrete detection.

- `advisory_id` (string, required) — unique identifier for the advisory
- `rule_id` (string, required) — unique identifier for the rule that sourced the advisory
- `category` (string, required) — category for the advisory
- `description` (string, required) — advisory description

### FileDetailsV3FileTypeDetails

### ScanDetectionV3MitreAtlasItems

- `technique` (string, optional) — MITRE Atlas Technique
- `tactic` (string, optional) — MITRE Atlas Tactic

### ScanDetectionV3RuleDetailsItems

- `status` (enum, optional) — status
  - Allowed values: `created`, `deprecated`, `updated`, `superseded`
- `status_at` (datetime, optional) — date-time when the details entry was created
- `description` (string, optional) — description of the deprecation

### GGUFFileAttributes

- `subtype` (list of string, required)

### KerasFileAttributes

- `subtype` (list of string, required)
- `pickle_modules` (list of string, required)
- `keras_version` (string, optional) — version of the Keras file
- `keras_class_name` (string, optional)
- `keras_date_saved_at` (string, optional)
- `keras_module` (string, optional)

### NumpyFileAttributes

- `subtype` (list of string, required)
- `numpy_arrays` (string, required)
- `numpy_shape` (list of string, required)

### RDSFileAttributes

- `subtype` (list of string, required)
- `rds_encoding` (string, required) — encoding of the RDS file
- `rds_min_reader_version` (string, required) — minimum reader version for the RDS file
- `rds_version` (string, required) — version of the RDS file
- `rds_writer_version` (string, required) — version of the RDS writer

## Examples

**Response**

```json
{
  "version": "string",
  "scan_id": "string",
  "start_time": "2024-01-15T09:30:00Z",
  "status": "pending",
  "inventory": {
    "model_name": "keras-tf-2025-05-27",
    "requested_scan_location": "/files-to-scan",
    "model_id": "00000000-0000-0000-0000-000000000000",
    "model_version_id": "00000000-0000-0000-0000-000000000000",
    "model_version": "1.0.0",
    "model_source": "adhoc",
    "file_location": "https://huggingface.co/meta-llama/Llama-3.1-8B",
    "provider_details": {
      "provider": "AWS_BEDROCK",
      "provider_model_id": "anthropic.claude-3-5-sonnet-20241022-v2:0"
    },
    "asset_region": "string",
    "requesting_entity": "string",
    "request_source": "Hybrid Upload",
    "origin": "Hugging Face"
  },
  "summary": {
    "file_count": 1,
    "files_with_detections_count": 1,
    "detection_count": 1,
    "severity": "critical",
    "detection_categories": [
      "string"
    ],
    "highest_severity": "critical",
    "advisory_count": 1,
    "advisory_categories": [
      "string"
    ],
    "files_failed_to_scan": 1,
    "unknown_files": 1
  },
  "file_count": 1,
  "files_with_detections_count": 1,
  "detection_count": 1,
  "has_genealogy": true,
  "$schema_version": "string",
  "end_time": "2024-01-15T09:30:00Z",
  "intelligence": {
    "geographic_footprint": [
      "US",
      "GB"
    ],
    "country_of_origin": "US",
    "contributor_trust_level": "high",
    "licenses": [
      {
        "name": "Apache-2.0",
        "sha256": "abc123..."
      }
    ],
    "usage_policies": [
      {
        "name": "Commercial Use Allowed",
        "sha256": "def456..."
      }
    ]
  },
  "compliance": {
    "status": "COMPLIANT",
    "evaluated_at": "2024-01-15T09:30:00Z",
    "rule_set_ids": [
      "string"
    ]
  },
  "file_results": [
    {
      "file_instance_id": "string",
      "file_location": "string",
      "start_time": "2024-10-16T23:38:32.278Z",
      "end_time": "2024-10-16T23:38:32.354Z",
      "details": {
        "estimated_time": "string",
        "sha256": "a54d88e06612d820bc3be72877c74f257b561b19",
        "file_type": "safetensors",
        "md5": "ce114e4501d2f4e2dcea3e17b546f339",
        "tlsh": "T1C50757F93C74D00C05B70C0793A1D5A9DF3F6D3A2F7AD940F3BFBF07B3BDF5A1D293",
        "file_size": "9 GB",
        "file_size_bytes": 9663676416,
        "file_type_details": {
          "subtype": [
            "string"
          ]
        }
      },
      "status": "skipped",
      "seen": "2024-10-22T17:59:12.431Z",
      "detections": [
        {
          "detection_id": "00000000-0000-0000-0000-000000000000",
          "rule_id": "PICKLE_0055_202408",
          "risk": "MALICIOUS",
          "category": "Arbitrary Code Execution",
          "description": "Found lambda embedded in keras model allowing custom layers that support  arbitrary expression execution",
          "likelihood": "medium",
          "impact": "critical",
          "severity": "critical",
          "mitre_atlas": [
            {
              "technique": "string",
              "tactic": "string"
            }
          ],
          "owasp": [
            "string"
          ],
          "cve": [
            "string"
          ],
          "cwe": "string",
          "cwe_href": "string",
          "rule_details": [
            {
              "status": "created",
              "status_at": "2024-01-15T09:30:00Z",
              "description": "string"
            }
          ],
          "technical_blog_hrefs": [
            "string"
          ],
          "technical_blog_href": "string"
        }
      ],
      "advisories": [
        {
          "advisory_id": "00000000-0000-0000-0000-000000000000",
          "rule_id": "SAFETENSORS_0001_202512",
          "category": "TokenBreak",
          "description": "Models using the BPE and WordPiece tokenization strategies are vulnerable to TokenBreak"
        }
      ],
      "file_error": [
        "File not found"
      ]
    }
  ],
  "severity": "critical",
  "detection_categories": [
    "string"
  ]
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/scan/v3/results/scan_id"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/scan/v3/results/scan_id';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/scan/v3/results/scan_id"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/scan/v3/results/scan_id")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.hiddenlayer.ai/scan/v3/results/scan_id")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.hiddenlayer.ai/scan/v3/results/scan_id', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/scan/v3/results/scan_id");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/scan/v3/results/scan_id")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```