> ## Documentation Index
> Fetch the complete documentation index at: https://chainpatrol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List Detection Configs

> List all threat detection sources for an organization. Each source includes its individual configurations with details like schedule, status, and source-specific settings.

## Overview

List all threat detection sources for an organization. Each source includes its
individual configurations with details such as schedule, status, and source-specific
settings.


## OpenAPI

````yaml POST /detection/configs/list
openapi: 3.0.3
info:
  title: ChainPatrol External API - OpenAPI 3.0
  description: ChainPatrol External API documentation
  version: 2.0.0
servers:
  - url: https://app.chainpatrol.io/api/v2
security: []
tags:
  - name: asset
  - name: report
externalDocs:
  url: https://chainpatrol.com/docs
paths:
  /detection/configs/list:
    post:
      tags:
        - detection
      summary: List threat detection configs for organization
      description: >-
        List all threat detection sources for an organization. Each source
        includes its individual configurations with details like schedule,
        status, and source-specific settings.
      operationId: detectionConfigsList
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                slug:
                  type: string
                  description: Organization slug
              required:
                - slug
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  properties:
                    source:
                      type: string
                      description: Detection source key (e.g. certstream, urlscan)
                    scope:
                      type: string
                      enum:
                        - global
                        - organization
                      description: >-
                        Whether this source runs globally for all orgs or is
                        configurable per-org
                    configs:
                      type: array
                      items:
                        type: object
                        properties:
                          id:
                            type: number
                          title:
                            type: string
                          description:
                            type: string
                            nullable: true
                            description: >-
                              Human-readable description of what the config
                              does. `null` when unset — most configs seeded
                              before this field existed do not have one.
                          status:
                            type: string
                          cron:
                            type: string
                            nullable: true
                          config:
                            type: object
                            additionalProperties: {}
                          brandId:
                            type: number
                            nullable: true
                          brand:
                            type: object
                            nullable: true
                            properties:
                              id:
                                type: number
                              name:
                                type: string
                              slug:
                                type: string
                            required:
                              - id
                              - name
                              - slug
                          createdAt:
                            type: string
                            description: When the config was first created
                          updatedAt:
                            type: string
                            description: >-
                              When the config was last updated — combine with
                              the drift healthcheck to spot silent configs that
                              haven't been touched in months
                          lastResultAt:
                            type: string
                            nullable: true
                            description: >-
                              When the most recent `ThreatDetectionResult` for
                              this config was created. `null` when the config
                              has never produced a hit. Surface for the same
                              signal the drift healthcheck computes internally —
                              a config with no recent `lastResultAt` is going
                              silent regardless of its `updatedAt`.
                        required:
                          - id
                          - title
                          - description
                          - status
                          - cron
                          - config
                          - brandId
                          - brand
                          - createdAt
                          - updatedAt
                          - lastResultAt
                      description: Individual detection configurations for this source
                  required:
                    - source
                    - scope
                    - configs
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - ApiKey: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Your API key. This is required by most endpoints to access our API
        programatically. Reach out to us at
        [support@chainpatrol.io](mailto:support@chainpatrol.io?subject=Re:%20API%20Key%20for%20SDK&body=Company:%20%0AName:%20%0APurpose:%20)
        to get an API key for your use.

````