> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List Transaction Validations

> Use this endpoint to list transaction validation records with cursor-based pagination and filters. Useful for compliance reporting and trend analysis.



## OpenAPI

````yaml en/openapi/v3-current/tracer.yaml get /v1/validations
openapi: 3.1.0
info:
  title: Tracer API
  description: >-
    Complete API reference for Tracer services including transaction validation,
    rules management, spending limits, and audit events for SOX/GLBA compliance.
  version: 1.0.1
servers:
  - url: https://tracer.sandbox.lerian.net
security:
  - ApiKeyAuth: []
  - BearerAuth: []
tags:
  - name: Health API
    description: >-
      Health check endpoints for liveness and readiness probes. These endpoints
      do not require authentication.
  - name: Validations API
    description: >-
      Transaction validation endpoints. Performance target is under 80ms (p99).
      Validations are idempotent by `requestId` — a duplicate request returns
      the cached result with HTTP 200, while a new request returns HTTP 201. No
      idempotency header is required.
  - name: Rules API
    description: >-
      Validation rule management endpoints. Rules use CEL (Common Expression
      Language) expressions.
  - name: Limits API
    description: >-
      Spending limit management endpoints. Limits control transaction amounts by
      scope and period.
  - name: Reservations API
    description: >-
      Two-phase transaction-capacity reservation endpoints. A reserve holds
      capacity against spending limits; a confirm commits it and a release
      returns it. Confirm and release are idempotent.
  - name: Audit Events API
    description: >-
      Audit trail endpoints for SOX/GLBA compliance. All validation decisions
      and configuration changes are recorded.
paths:
  /v1/validations:
    get:
      tags:
        - Validations API
      summary: List Transaction Validations
      description: >-
        Use this endpoint to list transaction validation records with
        cursor-based pagination and filters. Useful for compliance reporting and
        trend analysis.
      operationId: listValidations
      parameters:
        - $ref: '#/components/parameters/ContentType'
        - $ref: '#/components/parameters/XApiKey'
        - $ref: '#/components/parameters/XRequestId'
        - name: limit
          in: query
          description: >-
            The maximum number of items to include in the response. Default:
            100, Max: 1000
          required: false
          example: 100
          schema:
            type: integer
            minimum: 1
            maximum: 1000
            default: 100
        - name: cursor
          in: query
          description: >-
            Pagination cursor from previous response. When using cursor, sortBy
            and sortOrder cannot be changed.
          required: false
          schema:
            type: string
        - name: sort_by
          in: query
          description: The field used to sort the results.
          required: false
          example: created_at
          schema:
            type: string
            enum:
              - created_at
              - processing_time_ms
            default: created_at
        - name: sort_order
          in: query
          description: The order used to sort the results.
          required: false
          example: DESC
          schema:
            type: string
            enum:
              - ASC
              - DESC
            default: DESC
        - name: start_date
          in: query
          description: >-
            Filter from this date (inclusive). Must be RFC3339 format with
            timezone. Defaults to 90 days before current time.
          required: false
          example: '2026-01-01T00:00:00Z'
          schema:
            type: string
            format: date-time
        - name: end_date
          in: query
          description: >-
            Filter to this date (exclusive). Must be RFC3339 format with
            timezone. Defaults to current time.
          required: false
          example: '2026-01-31T23:59:59Z'
          schema:
            type: string
            format: date-time
        - name: decision
          in: query
          description: Filter by decision (ALLOW, DENY, REVIEW).
          required: false
          schema:
            type: string
            enum:
              - ALLOW
              - DENY
              - REVIEW
        - name: account_id
          in: query
          description: Filter by account ID (UUID).
          required: false
          schema:
            type: string
            format: uuid
        - name: matched_rule_id
          in: query
          description: Filter by matched rule ID (UUID).
          required: false
          schema:
            type: string
            format: uuid
        - name: exceeded_limit_id
          in: query
          description: Filter by exceeded limit ID (UUID).
          required: false
          schema:
            type: string
            format: uuid
        - name: segment_id
          in: query
          description: Filter by segment ID (UUID).
          required: false
          schema:
            type: string
            format: uuid
        - name: portfolio_id
          in: query
          description: Filter by portfolio ID (UUID).
          required: false
          schema:
            type: string
            format: uuid
        - name: transaction_type
          in: query
          description: Filter by transaction type.
          required: false
          schema:
            type: string
            enum:
              - CARD
              - WIRE
              - PIX
              - CRYPTO
      responses:
        '200':
          description: >-
            Indicates that the request was successful and the response contains
            the expected data.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListValidationsResponse'
              example:
                transactionValidations:
                  - validationId: 019c96a0-10d2-7193-8841-0d7347efd09a
                    accountId: 019c96a0-0c0c-7221-8cf3-13313fb60081
                    segmentId: 019c96a0-0b4e-7079-8be0-ab6bdccf975f
                    transactionType: CARD
                    amount: '1500.00'
                    currency: BRL
                    decision: ALLOW
                    reason: Transaction approved
                    matchedRuleIds: []
                    exceededLimitIds: []
                    processingTimeMs: 23
                    createdAt: '2026-01-30T10:30:00Z'
                hasMore: true
                nextCursor: eyJpZCI6IjEyMzQifQ==
        '400':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorFormat'
              examples:
                Error0006:
                  $ref: '#/components/examples/Error0006'
                Error0020:
                  $ref: '#/components/examples/Error0020'
                Error0044:
                  $ref: '#/components/examples/Error0044'
                Error0045:
                  $ref: '#/components/examples/Error0045'
                Error0250:
                  $ref: '#/components/examples/Error0250'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorFormat'
              examples:
                ErrorUnauthenticated:
                  $ref: '#/components/examples/ErrorUnauthenticated'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorFormat'
              examples:
                Error0004:
                  $ref: '#/components/examples/Error0004'
        '504':
          description: >-
            Gateway Timeout — emitted only when the query exceeds its
            server-side deadline (typically only under fault injection or
            extreme database latency; not commonly seen in normal operation).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorFormat'
              examples:
                Error0252:
                  $ref: '#/components/examples/Error0252'
components:
  parameters:
    ContentType:
      name: Content-Type
      in: header
      description: The type of media of the resource. Must be `application/json`.
      required: true
      example: application/json
      schema:
        type: string
    XApiKey:
      name: X-API-Key
      in: header
      description: >-
        The API Key for authentication. **This header is required for all
        endpoints except health checks**.
      required: true
      schema:
        type: string
    XRequestId:
      name: X-Request-Id
      in: header
      description: A unique identifier used to trace and track each request.
      required: false
      example: 019c96a0-10ce-75fc-a273-dc799079a99c
      schema:
        type: string
        format: uuid
  schemas:
    ListValidationsResponse:
      type: object
      description: >-
        Paginated list of transaction validations (returns `ValidationSummary` —
        a flat, list-optimized shape with fewer fields than
        `TransactionValidation`).
      properties:
        transactionValidations:
          type: array
          items:
            $ref: '#/components/schemas/ValidationSummary'
          description: List of transaction validation records.
        hasMore:
          type: boolean
          description: Whether there are more results available.
        nextCursor:
          type:
            - string
            - 'null'
          description: Cursor for fetching the next page. Null if no more results.
    ErrorFormat:
      type: object
      description: The response message error.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          description: A unique, stable identifier for the error.
        title:
          type: string
          description: A brief summary of the issue.
        message:
          type: string
          description: Detailed guidance for resolving the error.
        fields:
          type: object
          additionalProperties: true
          description: Additional information about the fields that caused the error.
    ValidationSummary:
      type: object
      description: >-
        Flattened, list-optimized representation of a transaction validation.
        Returned by `GET /v1/validations` and contains a subset of
        `TransactionValidation` fields — request payload, audit details
        (`requestId`, `metadata`, `evaluatedRuleIds`, `limitUsageDetails`) are
        only available via `GET /v1/validations/{id}`.
      properties:
        validationId:
          type: string
          format: uuid
          description: Unique identifier for this validation.
        decision:
          type: string
          enum:
            - ALLOW
            - DENY
            - REVIEW
          description: The decision returned for the validated transaction.
        reason:
          type: string
          description: >-
            Human-readable explanation of the decision. For non-matching
            validations, the literal value is `No matching rules found`.
        amount:
          type: string
          description: Transaction amount as a decimal string (e.g., `"1500.00"`).
        currency:
          type: string
          description: ISO 4217 currency code (uppercase).
        transactionType:
          type: string
          enum:
            - CARD
            - WIRE
            - PIX
            - CRYPTO
          description: Type of transaction.
        accountId:
          type: string
          format: uuid
          description: The account that originated the transaction. Flat, not nested.
        segmentId:
          type:
            - string
            - 'null'
          format: uuid
          description: Segment scope of the transaction, if applicable. Omitted when nil.
        portfolioId:
          type:
            - string
            - 'null'
          format: uuid
          description: Portfolio scope of the transaction, if applicable. Omitted when nil.
        matchedRuleIds:
          type: array
          items:
            type: string
            format: uuid
          description: IDs of rules that matched and contributed to the decision.
        exceededLimitIds:
          type: array
          items:
            type: string
            format: uuid
          description: IDs of limits that were exceeded.
        processingTimeMs:
          type: number
          format: double
          description: Processing time in milliseconds.
        createdAt:
          type: string
          format: date-time
          description: When the validation record was created.
  examples:
    Error0006:
      summary: Invalid Query Parameters
      value:
        code: TRC-0006
        title: Invalid Query Parameters
        message: >-
          One or more query parameters are invalid. Please verify the parameters
          and try again.
    Error0020:
      summary: Invalid Date Format
      value:
        code: TRC-0020
        title: Invalid Date Format
        message: >-
          The date must be in RFC3339 format with timezone (e.g.,
          2026-01-28T10:30:00Z). Date-only format is not accepted.
    Error0044:
      summary: Invalid Pagination Cursor
      value:
        code: TRC-0044
        title: Invalid Pagination Cursor
        message: >-
          The provided pagination cursor is invalid or expired. Please start a
          new query without a cursor.
    Error0045:
      summary: Sort Parameters Locked
      value:
        code: TRC-0045
        title: Sort Parameters Locked
        message: >-
          Cannot change sortBy or sortOrder when using a pagination cursor.
          Please start a new query to change sort parameters.
    Error0250:
      summary: Invalid Transaction Validation Filters
      value:
        code: TRC-0250
        title: Invalid Filters
        message: >-
          One or more transaction validation filters are invalid. Please verify
          the filter values and try again.
    ErrorUnauthenticated:
      summary: Unauthorized
      value:
        code: Unauthenticated
        title: Unauthorized
        message: >-
          API Key missing or invalid. Provide a valid API Key in the X-API-Key
          header.
    Error0004:
      summary: Internal Server Error
      value:
        code: TRC-0004
        title: Internal Server Error
        message: >-
          An unexpected error occurred. Please try again later or contact
          support if the issue persists.
    Error0252:
      summary: Query Timeout
      value:
        code: TRC-0252
        title: Gateway Timeout
        message: >-
          The query exceeded the allowed timeout. Please refine the filters to
          reduce the query scope.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: >-
        API Key authentication. Used by single-tenant deployments
        (`MULTI_TENANT_ENABLED=false`). Sent on every `/v1/*` request.
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT bearer authentication. Used by multi-tenant deployments
        (`MULTI_TENANT_ENABLED=true`). The JWT is issued by Access Manager and
        must carry the `tenantId` claim — Tracer resolves the tenant from the
        token, not from any header or body field.

````