Find the insights and best practices about our product.
Documents

This endpoint returns metadata for the compliance documents uploaded to your tenant, so you can track what has been uploaded and whether it is ready to use as evidence.

List Documents

Returns a paginated list of compliance documents for your tenant. This feed is metadata only; it does not serve file content. There is no download URL, content field, or size field, and there is currently no Public API path to retrieve a document's bytes. Use the Cranium portal to retrieve a document.

Request:

GET /api/public/documents

Authentication:

Bearer token. See Authentication & Generating Credentials.

Required Permission

Api_Documents_Read

Query Parameters

Parameter

Type

Value

limit

integer

Results per page. Maximum 200.

cursor

string

Sync cursor. Omit on the first call to begin from the beginning. Pass nextCursor from the previous response on subsequent calls.

updatedAfter

ISO 8601 timestamp

Return only records updated at or after this timestamp. Use to recover a lost cursor or reset to a known point in time.

Response Fields

Field

Type

Rules

fileId

GUID

Unique, stable identifier for the document. filename is not unique, so use this field to key downstream records.

filename

string

User-supplied file name. Two documents can share the same filename.

uploadStatus

string or null

Completed, Published, or null. null is a real state meaning no status has been recorded, distinct from Processing. Do not treat null as Completed; a document that is not Completed may not yet be usable as compliance evidence.

createdAt

ISO 8601 timestamp

When the document was uploaded.

updatedAt

ISO 8601 timestamp or null

When the document was last modified. null if it has never been modified since upload; treat updatedAt ?? createdAt as the effective last-changed time.

Sample Response

json

{
"data": [
{
"fileId": "b9c67f3a-1d8e-4a0b-bc3d-6c7d8e9f0a1b",
"filename": "AI-Governance-Policy-v3.pdf",
"uploadStatus": "Completed",
"createdAt": "2026-01-10T08:00:00Z",
"updatedAt": "2026-06-01T20:11:09Z"
},
{
"fileId": "c0d78a4b-2e9f-4b1c-cd4e-7d8e9f0a1b2c",
"filename": "Model-Risk-Assessment-Q2.docx",
"uploadStatus": "Processing",
"createdAt": "2026-07-02T09:15:33Z",
"updatedAt": null
},
{
"fileId": "d1e89b5c-3f0a-4c2d-de5f-8e9f0a1b2c3d",
"filename": "third-party-audit-report.pdf",
"uploadStatus": null,
"createdAt": "2026-07-28T11:02:00Z",
"updatedAt": null
}
],
"pagination": {
"limit": 100,
"nextCursor": "eyJ1cGRhdGVkQXQiOiIyMDI2LTA3LTI4VDExOjAyOjAwWiIsImlkIjoiZDFlODliNWMifQ==",
"hasMore": false
},
"error": null,
"meta": {
"requestId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"timestamp": "2026-08-13T10:55:00Z"
}
}


Record 2 is mid-ingestion. Documents are embedded asynchronously for compliance question answering, so a freshly uploaded file can appear in this feed before it is queryable. There is no link from a document to a compliance framework response on this record; the two cannot be correlated through this feed along. hasMore: false with a non-null nextCursor is the normal end-of-feed state. Store the cursor and replay it on your next poll.

Error Responses

  • 400 VALIDATION_FAILED: the cursor is invalid, or cursor and updatedAfter were supplied together.
  • 401 UNAUTHORIZED: the request is missing a token, or the token lacks Api_Documents_Read.
  • 500 INTERNAL_ERROR: an unexpected server error.
Did this answer your question?