> ## Documentation Index
> Fetch the complete documentation index at: https://evalgate.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit an OpenAPI or tool connector manifest

> Requires scopes: admin:org



## OpenAPI

````yaml /api-reference/openapi.json post /api/agent-evidence/connector/audit
openapi: 3.1.0
info:
  title: EvalGate API
  version: 3.7.6
  description: EvalGate API. See docs/api-contract.md for stability commitments.
servers:
  - url: https://evalgate.com
    description: Production
  - url: http://localhost:3000
    description: Local
security: []
paths:
  /api/agent-evidence/connector/audit:
    post:
      tags:
        - agent evidence
      summary: Audit an OpenAPI or tool connector manifest
      description: 'Requires scopes: admin:org'
      operationId: post_agent_evidence_connector_audit
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PostApiAgentEvidenceConnectorAuditRequest'
      responses:
        '201':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/PostApiAgentEvidenceConnectorAuditResponse201ApplicationJson
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - bearerAuth:
            - admin:org
components:
  schemas:
    PostApiAgentEvidenceConnectorAuditRequest:
      type: object
      properties:
        connectorKey:
          type: string
        spec:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
        aiSystemId:
          type: number
        evidenceItemIds:
          type: array
          items:
            type: number
        connectorId:
          type: number
      additionalProperties: false
      required:
        - connectorKey
        - spec
    PostApiAgentEvidenceConnectorAuditResponse201ApplicationJson:
      type: object
      properties:
        audit:
          type: object
          properties:
            reportKey:
              type: string
            manifestHash:
              type: string
            status:
              oneOf:
                - type: string
                  enum:
                    - quarantined
                - type: string
                  enum:
                    - failed
                - type: string
                  enum:
                    - restricted
                - type: string
                  enum:
                    - ready
            score:
              type: number
            checks:
              type: object
              additionalProperties:
                oneOf:
                  - type: number
                  - type: boolean
                    enum:
                      - false
                  - type: boolean
                    enum:
                      - true
            findings:
              type: array
              items:
                type: object
                properties:
                  check:
                    type: string
                  severity:
                    oneOf:
                      - type: string
                        enum:
                          - low
                      - type: string
                        enum:
                          - medium
                      - type: string
                        enum:
                          - high
                      - type: string
                        enum:
                          - critical
                  message:
                    type: string
                  operation:
                    type: string
                additionalProperties: false
                required:
                  - check
                  - severity
                  - message
          additionalProperties: false
          required:
            - reportKey
            - manifestHash
            - status
            - score
            - checks
            - findings
        report:
          type: object
          properties:
            status:
              type: string
            id:
              type: number
            createdAt:
              type: string
              format: date-time
            updatedAt:
              type: string
              format: date-time
            organizationId:
              $ref: '#/components/schemas/OrganizationId'
            createdBy:
              oneOf:
                - type: 'null'
                - type: string
            metadata:
              allOf:
                - type: object
                  properties:
                    schemaVersion:
                      type: number
                  additionalProperties: false
                - type: object
                  additionalProperties:
                    $ref: '#/components/schemas/JsonValue'
            aiSystemId:
              oneOf:
                - type: 'null'
                - type: number
            manifestHash:
              oneOf:
                - type: 'null'
                - type: string
            score:
              type: number
            checks:
              allOf:
                - type: object
                  properties:
                    schemaVersion:
                      type: number
                    checks:
                      type: array
                      items:
                        allOf:
                          - type: object
                            properties:
                              name:
                                type: string
                              passed:
                                type: boolean
                              details:
                                type: string
                            additionalProperties: false
                            required:
                              - name
                              - passed
                          - type: object
                            additionalProperties:
                              $ref: '#/components/schemas/JsonValue'
                  additionalProperties: false
                - type: object
                  additionalProperties:
                    $ref: '#/components/schemas/JsonValue'
            evidenceItemIds:
              type: array
              items:
                type: number
            connectorId:
              oneOf:
                - type: 'null'
                - type: number
            findings:
              allOf:
                - type: object
                  properties:
                    schemaVersion:
                      type: number
                    findings:
                      type: array
                      items:
                        allOf:
                          - type: object
                            properties:
                              severity:
                                oneOf:
                                  - type: string
                                    enum:
                                      - low
                                  - type: string
                                    enum:
                                      - medium
                                  - type: string
                                    enum:
                                      - high
                                  - type: string
                                    enum:
                                      - critical
                              description:
                                type: string
                              recommendation:
                                type: string
                            additionalProperties: false
                          - type: object
                            additionalProperties:
                              $ref: '#/components/schemas/JsonValue'
                  additionalProperties: false
                - type: object
                  additionalProperties:
                    $ref: '#/components/schemas/JsonValue'
            reportKey:
              type: string
          additionalProperties: false
          required:
            - status
            - id
            - createdAt
            - updatedAt
            - organizationId
            - createdBy
            - metadata
            - aiSystemId
            - manifestHash
            - score
            - checks
            - evidenceItemIds
            - connectorId
            - findings
            - reportKey
      additionalProperties: false
      required:
        - audit
        - report
    JsonValue:
      oneOf:
        - type: 'null'
        - type: boolean
        - type: number
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    OrganizationId:
      type: string
      format: uuid
    ApiError:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - UNAUTHORIZED
                - FORBIDDEN
                - NOT_FOUND
                - VALIDATION_ERROR
                - RATE_LIMITED
                - CONFLICT
                - INTERNAL_ERROR
                - SERVICE_UNAVAILABLE
                - QUOTA_EXCEEDED
                - NO_ORG_MEMBERSHIP
                - CROSS_ORG_REFERENCE
                - INCOMPLETE
                - MALFORMED
            message:
              type: string
            details: {}
            requestId:
              type: string
              format: uuid
          required:
            - code
            - message
      required:
        - error
  responses:
    ValidationError:
      description: Validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Conflict:
      description: Conflict
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    RateLimited:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    InternalError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key or Session Token

````