Skip to content

List RSKs (the canonical risk register).

GET
/v1/risks
curl --request GET \
--url 'https://api.adversarial.com/api/v1/risks?created_after=2026-01-01T00%3A00%3A00Z&created_before=2026-12-31T23%3A59%3A59Z&updated_after=2026-01-01T00%3A00%3A00Z&updated_before=2026-12-31T23%3A59%3A59Z&discovered_after=2026-01-01T00%3A00%3A00Z&discovered_before=2026-12-31T23%3A59%3A59Z&in_report_period_after=2026-01-01T00%3A00%3A00Z&in_report_period_before=2026-12-31T23%3A59%3A59Z&overdue_as_of=2026-12-31T23%3A59%3A59Z&due_after=2026-01-01T00%3A00%3A00Z&due_before=2026-12-31T23%3A59%3A59Z&expected_after=2026-01-01T00%3A00%3A00Z&expected_before=2026-12-31T23%3A59%3A59Z&closed_after=2026-01-01T00%3A00%3A00Z&closed_before=2026-12-31T23%3A59%3A59Z&page=1&page_size=50'
id
Array<string> | null

Return only these risks. Accepts RSK-<n> or a bare number, matching parent_id / child_id and the incident register’s id.

title_contains
string | null
description_contains
string | null
opened_by
Array | null
updated_by
Array | null
impact
Array | null
likelihood
Array | null
initially_reported_urgency
Array | null
type
Array<string> | null
Allowed values: Code Configuration Control Deficiency Policy Procedural Vulnerability Third-party
status
Array<string> | null
Allowed values: New Urgency Proposed Remediation Closure Proposed Closed
source
Array<string> | null
threat_objectives
Array | null
urgency
Array | null
created_after
string | null format: date-time

Inclusive lower bound on created_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
created_before
string | null format: date-time

Inclusive upper bound on created_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
updated_after
string | null format: date-time

Inclusive lower bound on updated_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
updated_before
string | null format: date-time

Inclusive upper bound on updated_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
discovered_after
string | null format: date-time

Inclusive lower bound on discovered_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
discovered_before
string | null format: date-time

Inclusive upper bound on discovered_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
in_report_period_after
string | null format: date-time

Start of a report window: with in_report_period_before, restrict to the risks a deck report over that window describes — discovered within it, closed within it, or past a due date falling within it. Not the standing backlog: an open risk with no due date, or one due after the window, is outside it. Supply both bounds or neither. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
in_report_period_before
string | null format: date-time

End of a report window. See in_report_period_after.

Example
2026-12-31T23:59:59Z
overdue_as_of
string | null format: date-time

Overdue as of this instant: due on or before it and not closed by it. overdue=true stays “overdue right now”. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
due_after
string | null format: date-time

Inclusive lower bound on due_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
due_before
string | null format: date-time

Inclusive upper bound on due_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
due_is_null
boolean | null

Match only risks whose due_date is unset. Mutually exclusive with due_after/due_before.

expected_after
string | null format: date-time

Inclusive lower bound on expected_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
expected_before
string | null format: date-time

Inclusive upper bound on expected_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
expected_is_null
boolean | null

Match only risks whose expected_date is unset. Mutually exclusive with expected_after/expected_before.

closed_after
string | null format: date-time

Inclusive lower bound on closed_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
closed_before
string | null format: date-time

Inclusive upper bound on closed_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
closed_is_null
boolean | null

Match only risks whose closed_date is unset. Mutually exclusive with closed_after/closed_before.

assigned_to
Array | null

Accepts UUIDs, the literal null (unassigned), and the sentinel me (the calling user, resolved server-side). Multiple values union — e.g. assigned_to=me&assigned_to=<uuid> returns rows assigned to either.

mentioned
Array | null

Risks with at least one live comment that @-mentions the given user. Accepts UUIDs, the sentinel me (the calling user, resolved server-side), and the literal null (no comment mentions anyone). Multiple values union — e.g. mentioned=me&mentioned=null returns risks that mention you plus risks that mention nobody.

tags
Array | null
page
integer format: int64
default: 1 >= 1 <= 1000000

1-indexed page number. Defaults to 1 (explicit null reads as the default); zero is rejected.

page_size
integer format: int64
default: 50 >= 1 <= 500

Rows per page. Defaults to 50 (explicit null reads as the default); zero is rejected.

order_by
string | null
free_text_contains
string | null
id_contains
string | null
overdue
boolean | null

Filter to overdue (true) or non-overdue (false) risks. Overdue means open and past due_date.

parent_id
Array | null

Filter on what a risk is linked under. Accepts the literal null (top-level risks), the literal any (only risks linked under a parent), or a parent id as RSK-<n> or a bare number. Repeat the parameter to union — ?parent_id=null&parent_id=any is every risk.

Defaults to null, so registers and rollups list top-level records only. An explicit JSON null on the body path reads as that same default, not as “no filter”.

child_id
Array | null

Filter on what is linked under a risk. Accepts the literal any (risks with at least one non-deleted child — the “Parent Risks Only” quick filter), the literal null (risks with no children), or a child id as RSK-<n> or a bare number (that child’s parent). Repeat to union. Omit to leave the filter off.

Because links are single-layer, every parent is top-level, so this composes with the default parent_id=null register view.

urgency_shift
One of:
null

Return only risks whose current urgency has shifted from the urgency they were first reported at. Upgrade matches risks now at least one level more severe; Downgrade matches those now at least one level less severe. Omit to leave the filter off.

List RSKs with register-context fields

Media typeapplication/json

Paginated list envelope: { "results": [...], "pagination": {...} }.

object
pagination
required

Pagination metadata describing the slice.

object
page
required

1-indexed page number of this result slice.

integer format: int64
page_size
required

Number of items requested per page.

integer format: int64
total_items
required

Total number of matching items across all pages.

integer format: int64
total_pages
required

Total number of pages at this page size.

integer format: int64
results
required

The items on this page.

Array<object>

Register row for Organization Risks (RSKs). A Risk plus the relational data shown on the risk register: threat objectives, incident associations, tags, and comment count.

object
comments
required

Count of comments on this risk (not the comments themselves).

integer format: int64
incident_associations
required
Array<string>
linked_children_count
required

Number of risks linked under this risk (i.e. children pointing at it). A risk is itself a linked child when risk.parent_id is set.

integer format: int64
risk
required

The core view of an Organization Risk (RSK).

Relational data — threat objectives, comments, incident associations, and tags — is exposed on RiskRegisterEntry, not here.

object
assigned_to
One of:
null
closed_date
string | null format: date-time
control_statement
string | null
created_date
required
string format: date-time
deleted_date
string | null format: date-time
description
required
string
discovered_date
required
string format: date-time
due_date
string | null format: date-time
expected_date
string | null format: date-time
id
required
string
impact
One of:
null
impact_reasoning
string | null
initially_reported_urgency
One of:
null
likelihood
One of:
null
likelihood_reasoning
string | null
opened_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
parent_id

When set, this risk is linked under the named parent risk.

string | null
remediation_task
string | null
source
string | null
status
required

The status of a risk

string
Allowed values: New Urgency Proposed Remediation Closure Proposed Closed
title
required
string
type
required
string
Allowed values: Code Configuration Control Deficiency Policy Procedural Vulnerability Third-party
updated_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
updated_date
required
string format: date-time
urgency
One of:
null
tags
required
Array<object>
object
content
required
string
creator_id
required
string format: uuid
id
required
string format: uuid
org_id
string | null format: uuid
threat_objectives
required
Array<object>

A threat objective paired with how relevant it is to a risk.

Two relations are considered the same when the objective and its relevance match; created_date records when the relation was last changed and is not part of its identity.

object
created_date

The time that this relation was mutated

string | null format: date-time
relevance
One of:
null
threat_objective
required

The threat objective type

string
Allowed values: Sabotage Data Disclosure Extortion Customer Targeting Resource Hijacking Fraud
Example
{
"results": [
{
"incident_associations": "INC-00001",
"risk": {
"id": "RSK-00001",
"impact": "Very Low",
"initially_reported_urgency": "Critical",
"likelihood": "Remote",
"parent_id": "RSK-00001",
"status": "New",
"type": "Code",
"urgency": "Info"
},
"threat_objectives": [
{
"relevance": "Moderate",
"threat_objective": "Sabotage"
}
]
}
]
}