> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Praxis Shield threat incidents for the caller's managed institutions

> Returns Security-Watcher incidents scoped to the institutions the caller administers (super sees all). Mounted under the admin gate (isAdmin) and additionally scoped per-institution inside the handler via the `institutions.list` entitlement (super bypasses) — so a Digital Twin admin (global accountType 'admin') sees only the institutions they manage. Heavy evidence/LLM payloads are omitted; returned text is attacker- influenced and MUST be rendered inert by the client.




## OpenAPI

````yaml /mdx/api-reference/admin/admin-api.json get /api/admin/security/threats
openapi: 3.0.0
info:
  title: Pria Admin API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Admin Memory
    description: Admin inspection and editing of user/instance memory parameters.
  - name: Admin Usage Limits
    description: Per-user usage-vs-cap reporting and account-wide at-limit counts.
paths:
  /api/admin/security/threats:
    get:
      tags:
        - Admin
        - Security
      summary: >-
        List Praxis Shield threat incidents for the caller's managed
        institutions
      description: >
        Returns Security-Watcher incidents scoped to the institutions the caller
        administers (super sees all). Mounted under the admin gate (isAdmin) and
        additionally scoped per-institution inside the handler via the
        `institutions.list` entitlement (super bypasses) — so a Digital Twin
        admin (global accountType 'admin') sees only the institutions they
        manage. Heavy evidence/LLM payloads are omitted; returned text is
        attacker- influenced and MUST be rendered inert by the client.
      parameters:
        - in: query
          name: accountId
          schema:
            type: string
          description: >
            Filter incidents to the institutions belonging to this account. For
            non-super callers the account's institutions are intersected with
            the caller's managed (RAP-scoped) set — no overlap returns 403. For
            super callers the account's institutions are used directly (no
            overlap → empty result, not 403).
        - in: query
          name: institutionId
          schema:
            type: string
          description: >
            Narrow to one institution (must be one the caller manages, else
            403). When combined with `accountId`, the institution must belong to
            that account (else 403).
        - in: query
          name: status
          schema:
            type: string
            enum:
              - all
              - open
              - reviewing
              - resolved
              - false_positive
              - escalated
          description: >
            Filter by incident status. `all` shows everything (incl. terminal
            statuses); a specific status matches exactly; omitted hides terminal
            statuses (resolved, false_positive) by default.
        - in: query
          name: severityMin
          schema:
            type: integer
            minimum: 0
            maximum: 4
          description: Minimum severity (0-4)
        - in: query
          name: page
          schema:
            type: integer
            default: 0
        - in: query
          name: limit
          schema:
            type: integer
            default: 50
            minimum: 1
            maximum: 200
      responses:
        '200':
          description: Paginated incident list
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  total:
                    type: integer
                  page:
                    type: integer
                  limit:
                    type: integer
                  incidents:
                    type: array
                    items:
                      $ref: '#/components/schemas/ThreatIncidentSummary'
        '400':
          description: Invalid query parameter (accountId, institutionId, status)
        '403':
          description: >-
            Not authorized to view threats (or for the requested
            account/institution)
        '500':
          description: Server error
      security:
        - apiKeyAuth: []
components:
  schemas:
    ThreatIncidentSummary:
      type: object
      description: >
        Lightweight incident projection (heavy `evidence`/`llmAssessments`
        payloads stripped). Attacker-influenced text (`title`, `summary`,
        `categories`, `userEmail`, name fields) is returned verbatim and MUST be
        rendered INERT by the client (no HTML/markdown/auto-link).
      properties:
        _id:
          type: string
        status:
          type: string
          enum:
            - open
            - reviewing
            - resolved
            - false_positive
            - escalated
        severity:
          type: integer
          minimum: 0
          maximum: 4
        categories:
          type: array
          items:
            type: string
        title:
          type: string
        summary:
          type: string
        user:
          type: string
          description: Flagged user id
        userEmail:
          type: string
          description: Attached from the user record (inert)
        userFname:
          type: string
          description: Attached from the user record (inert)
        userLname:
          type: string
          description: Attached from the user record (inert)
        institutionIds:
          type: array
          items:
            type: string
        institutions:
          type: array
          description: Resolved institution names for the incident's institutionIds
          items:
            type: object
            properties:
              _id:
                type: string
              name:
                type: string
        firstSeenAt:
          type: string
          format: date-time
        lastSeenAt:
          type: string
          format: date-time
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-access-token
      description: JWT token passed in x-access-token header

````