Reports
HTTP API routes for reports.
Reports are markdown documents your organization writes together.
{reportId} is the report's UUID from the list route. Bodies travel as
bodyMarkdown in the report document format
and are returned whole; there is no block tree.
| Route | Use | CLI equivalent |
|---|---|---|
GET /reports | List reports without bodies. | ax report list |
POST /reports | Create a report. | ax report create |
GET /reports/{reportId} | One report and its body. | ax report get |
PATCH /reports/{reportId} | Change title, description or body. | ax report edit |
POST /reports/{reportId}/blocks | Append markdown to the body. | ax report append |
DELETE /reports/{reportId} | Delete a report. | ax report delete |
Every route takes org_id (required only when the key can see several orgs).
Parameters are optional unless marked required. Request bodies accept
lowerCamelCase or snake_case field names. A report row carries id, orgId,
title, description, createdBy, updatedBy, createdAt and updatedAt;
empty fields are omitted. updatedAt is the conflict stamp the write routes
take back.
GET /api/v1/reports
List reports, most recently changed first.
curl -H "Authorization: Bearer $AX_API_KEY" \
"https://app.514.ax/api/v1/reports?limit=20"| Parameter | What it does |
|---|---|
limit | Reports per page (default 50, max 200; page_size is an alias). |
cursor | Opaque nextCursor from the previous page (page_token is an alias). |
The response is {reports, nextCursor}; nextCursor is omitted on the last
page.
POST /api/v1/reports
Create a report.
curl -X POST \
-H "Authorization: Bearer $AX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"title":"Checkout latency","description":"Where the p95 went","bodyMarkdown":"# Summary\n"}' \
"https://app.514.ax/api/v1/reports"| Body field | What it does |
|---|---|
title | Required. Surrounding whitespace is trimmed; blank is refused. |
description | One-paragraph summary shown under the title. |
bodyMarkdown | Initial body. Normalized in the document format before it is stored, so the response holds the canonical form of what was sent. |
Returns {report, bodyMarkdown}. Actor and org come from authentication.
GET /api/v1/reports/{reportId}
One report and its body as markdown.
curl -H "Authorization: Bearer $AX_API_KEY" \
"https://app.514.ax/api/v1/reports/$REPORT_ID"Returns {report, bodyMarkdown}; an empty report omits bodyMarkdown. Keep
report.updatedAt for PATCH.
PATCH /api/v1/reports/{reportId}
Change the title, the description and/or the whole body.
curl -X PATCH \
-H "Authorization: Bearer $AX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"title":"Checkout latency, week 2","expectedUpdatedAt":"2026-09-02T11:30:00.000Z"}' \
"https://app.514.ax/api/v1/reports/$REPORT_ID"| Body field | What it does |
|---|---|
expectedUpdatedAt | Required. The updatedAt you last read. |
title | New title; blank is refused. |
description | New description; an empty string clears it. |
bodyMarkdown | Replacement for the whole body; an empty string clears it. |
The route is presence-aware: a field you send changes, a field you leave out
stays. Sending none of the three is a 400. When the report changed since
expectedUpdatedAt, the route answers 409 with {error, message} and
writes nothing; read the report again and retry with its new stamp. Returns
{report, bodyMarkdown}.
POST /api/v1/reports/{reportId}/blocks
Append markdown to the end of the body, after a blank line, leaving what is there untouched.
curl -X POST \
-H "Authorization: Bearer $AX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"markdown":"> [!FINDING] Slower on Fridays\n> The p95 doubles after 16:00 UTC."}' \
"https://app.514.ax/api/v1/reports/$REPORT_ID/blocks"| Body field | What it does |
|---|---|
markdown | Required. Prose, headings, callouts, ax:// mentions or ax-block fences. Blank is refused. |
expectedUpdatedAt | Refuse the append with 409 when the report changed since this stamp. Omit to append to the body as it stands. |
Returns {report, bodyMarkdown} with the whole body after the append.
DELETE /api/v1/reports/{reportId}
Delete a report and its body. Links from findings to it are removed; the findings and the Context objects it cited stay.
curl -X DELETE -H "Authorization: Bearer $AX_API_KEY" \
"https://app.514.ax/api/v1/reports/$REPORT_ID"Returns {reportId, findingLinksRemoved}; findingLinksRemoved is omitted
when it is zero.