Search documentation

Search the Fumadocs-backed documentation index.

Reports

HTTP API routes for reports.

Reports are markdown documents your organization writes together. {reportId} is the report's UUID from the list route. Bodies travel as bodyMarkdown in the report document format and are returned whole; there is no block tree.

RouteUseCLI equivalent
GET /reportsList reports without bodies.ax report list
POST /reportsCreate a report.ax report create
GET /reports/{reportId}One report and its body.ax report get
PATCH /reports/{reportId}Change title, description or body.ax report edit
POST /reports/{reportId}/blocksAppend markdown to the body.ax report append
DELETE /reports/{reportId}Delete a report.ax report delete

Every route takes org_id (required only when the key can see several orgs). Parameters are optional unless marked required. Request bodies accept lowerCamelCase or snake_case field names. A report row carries id, orgId, title, description, createdBy, updatedBy, createdAt and updatedAt; empty fields are omitted. updatedAt is the conflict stamp the write routes take back.

GET /api/v1/reports

List reports, most recently changed first.

curl -H "Authorization: Bearer $AX_API_KEY" \
  "https://app.514.ax/api/v1/reports?limit=20"
ParameterWhat it does
limitReports per page (default 50, max 200; page_size is an alias).
cursorOpaque nextCursor from the previous page (page_token is an alias).

The response is {reports, nextCursor}; nextCursor is omitted on the last page.

POST /api/v1/reports

Create a report.

curl -X POST \
  -H "Authorization: Bearer $AX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"Checkout latency","description":"Where the p95 went","bodyMarkdown":"# Summary\n"}' \
  "https://app.514.ax/api/v1/reports"
Body fieldWhat it does
titleRequired. Surrounding whitespace is trimmed; blank is refused.
descriptionOne-paragraph summary shown under the title.
bodyMarkdownInitial body. Normalized in the document format before it is stored, so the response holds the canonical form of what was sent.

Returns {report, bodyMarkdown}. Actor and org come from authentication.

GET /api/v1/reports/{reportId}

One report and its body as markdown.

curl -H "Authorization: Bearer $AX_API_KEY" \
  "https://app.514.ax/api/v1/reports/$REPORT_ID"

Returns {report, bodyMarkdown}; an empty report omits bodyMarkdown. Keep report.updatedAt for PATCH.

PATCH /api/v1/reports/{reportId}

Change the title, the description and/or the whole body.

curl -X PATCH \
  -H "Authorization: Bearer $AX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"Checkout latency, week 2","expectedUpdatedAt":"2026-09-02T11:30:00.000Z"}' \
  "https://app.514.ax/api/v1/reports/$REPORT_ID"
Body fieldWhat it does
expectedUpdatedAtRequired. The updatedAt you last read.
titleNew title; blank is refused.
descriptionNew description; an empty string clears it.
bodyMarkdownReplacement for the whole body; an empty string clears it.

The route is presence-aware: a field you send changes, a field you leave out stays. Sending none of the three is a 400. When the report changed since expectedUpdatedAt, the route answers 409 with {error, message} and writes nothing; read the report again and retry with its new stamp. Returns {report, bodyMarkdown}.

POST /api/v1/reports/{reportId}/blocks

Append markdown to the end of the body, after a blank line, leaving what is there untouched.

curl -X POST \
  -H "Authorization: Bearer $AX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"markdown":"> [!FINDING] Slower on Fridays\n> The p95 doubles after 16:00 UTC."}' \
  "https://app.514.ax/api/v1/reports/$REPORT_ID/blocks"
Body fieldWhat it does
markdownRequired. Prose, headings, callouts, ax:// mentions or ax-block fences. Blank is refused.
expectedUpdatedAtRefuse the append with 409 when the report changed since this stamp. Omit to append to the body as it stands.

Returns {report, bodyMarkdown} with the whole body after the append.

DELETE /api/v1/reports/{reportId}

Delete a report and its body. Links from findings to it are removed; the findings and the Context objects it cited stay.

curl -X DELETE -H "Authorization: Bearer $AX_API_KEY" \
  "https://app.514.ax/api/v1/reports/$REPORT_ID"

Returns {reportId, findingLinksRemoved}; findingLinksRemoved is omitted when it is zero.