TracePass
Passports

List passport snapshots

Returns a paginated list of immutability **snapshots** for a passport, newest first. A snapshot is written on publish and after every change to a published, suspended, expired or archived passport — field values, translations, parties, status transitions, supplier answers, AI writes, restores — whenever what the passport asserts actually changed (EN 18221:2026 4.2). Each entry includes the snapshot id, version number, reason (e.g. `published`, `field_edit`, `status_change`, `baseline`), who caused it (`actor`, when known), timestamp, content hash, and whether the hash still verifies — `hashValid: false` indicates at-rest tampering.

GET/api/v1/passports/{id}/snapshots
Download OpenAPI 3.1
GET/api/v1/passports/{id}/snapshots

List passport snapshots

Returns a paginated list of immutability **snapshots** for a passport, newest first. A snapshot is written on publish and after every change to a published, suspended, expired or archived passport — field values, translations, parties, status transitions, supplier answers, AI writes, restores — whenever what the passport asserts actually changed (EN 18221:2026 4.2). Each entry includes the snapshot id, version number, reason (e.g. `published`, `field_edit`, `status_change`, `baseline`), who caused it (`actor`, when known), timestamp, content hash, and whether the hash still verifies — `hashValid: false` indicates at-rest tampering.

Snapshots also carry `restorable` (whether `rawFields` was captured so a field-level restore is possible) and `fieldCount` (number of fields in `rawFields`, or `null` for evidence-only snapshots taken before `rawFields` existed). Passports that predated snapshots have a `baseline` snapshot from the first nightly sweep; history before that point was never captured.

**Point in time:** add `?at=<ISO 8601>` to get the one snapshot valid at that instant — the full record plus `validFrom` and `validUntil` (null while current) — instead of the list. Returns 404 when the time predates the passport's first snapshot.

Tenant-scoped: only your company's passports are visible. Counts as one v1 passport read against the daily cap. Paginate with `?page` (1-based, default 1) and `?limit` (1–100, default 20).

Path parameters

  • idrequired

    ObjectId

    Passport ID.

Query parameters

  • page

    integer

    Page number (1-based, default 1).

  • at

    string (ISO 8601)

    Return the snapshot valid at this instant instead of the list.

    e.g. 2026-09-29T12:00:00Z

  • limit

    integer

    Page size (1–100, default 20).

Headers

  • Authorizationrequired

    string

    `Bearer <token>` — either a `tp_` API key (Developer → API Keys; simplest, for server-to-server) or an OAuth 2.0 access token (Developer → OAuth Apps; for user-authorized apps, scoped + revocable). The Authentication page has the full OAuth flow and scope list.

    e.g. Bearer tp_REDACTED_xxxxxxxxxxxx

Request

curl -sS "https://app.tracepass.eu/api/v1/passports/6650b2c3d4e5f6a7b8c9d0e1/snapshots?limit=5" \
  -H "Authorization: Bearer tp_REDACTED_xxxxxxxxxxxx"

Response

{
  "entries": [
    {
      "id": "65a0f1b2c3d4e5f6a7b8c9d1",
      "version": 3,
      "reason": "republished",
      "snapshotAt": "2026-09-15T14:32:00.000Z",
      "contentHash": "a3f1c2d4e5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2",
      "hashValid": true,
      "restorable": true,
      "fieldCount": 124
    },
    {
      "id": "65a0f1b2c3d4e5f6a7b8c9d0",
      "version": 1,
      "reason": "published",
      "snapshotAt": "2026-08-01T09:00:00.000Z",
      "contentHash": "b4e2d3c5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3",
      "hashValid": true,
      "restorable": false,
      "fieldCount": null
    }
  ],
  "total": 2,
  "page": 1,
  "limit": 20,
  "totalPages": 1
}