/api/v1/passports/{id}/snapshotsList passport snapshots
Returns a paginated list of immutability **snapshots** for a passport, newest first. A snapshot is written on publish and after every change to a published, suspended, expired or archived passport — field values, translations, parties, status transitions, supplier answers, AI writes, restores — whenever what the passport asserts actually changed (EN 18221:2026 4.2). Each entry includes the snapshot id, version number, reason (e.g. `published`, `field_edit`, `status_change`, `baseline`), who caused it (`actor`, when known), timestamp, content hash, and whether the hash still verifies — `hashValid: false` indicates at-rest tampering.
Snapshots also carry `restorable` (whether `rawFields` was captured so a field-level restore is possible) and `fieldCount` (number of fields in `rawFields`, or `null` for evidence-only snapshots taken before `rawFields` existed). Passports that predated snapshots have a `baseline` snapshot from the first nightly sweep; history before that point was never captured.
**Point in time:** add `?at=<ISO 8601>` to get the one snapshot valid at that instant — the full record plus `validFrom` and `validUntil` (null while current) — instead of the list. Returns 404 when the time predates the passport's first snapshot.
Tenant-scoped: only your company's passports are visible. Counts as one v1 passport read against the daily cap. Paginate with `?page` (1-based, default 1) and `?limit` (1–100, default 20).
Path parameters
- idrequired
ObjectId
Passport ID.
Query parameters
- page
integer
Page number (1-based, default 1).
- at
string (ISO 8601)
Return the snapshot valid at this instant instead of the list.
e.g. 2026-09-29T12:00:00Z
- limit
integer
Page size (1–100, default 20).
Headers
- Authorizationrequired
string
`Bearer <token>` — either a `tp_` API key (Developer → API Keys; simplest, for server-to-server) or an OAuth 2.0 access token (Developer → OAuth Apps; for user-authorized apps, scoped + revocable). The Authentication page has the full OAuth flow and scope list.
e.g. Bearer tp_REDACTED_xxxxxxxxxxxx
Request
curl -sS "https://app.tracepass.eu/api/v1/passports/6650b2c3d4e5f6a7b8c9d0e1/snapshots?limit=5" \
-H "Authorization: Bearer tp_REDACTED_xxxxxxxxxxxx"Response
{
"entries": [
{
"id": "65a0f1b2c3d4e5f6a7b8c9d1",
"version": 3,
"reason": "republished",
"snapshotAt": "2026-09-15T14:32:00.000Z",
"contentHash": "a3f1c2d4e5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2",
"hashValid": true,
"restorable": true,
"fieldCount": 124
},
{
"id": "65a0f1b2c3d4e5f6a7b8c9d0",
"version": 1,
"reason": "published",
"snapshotAt": "2026-08-01T09:00:00.000Z",
"contentHash": "b4e2d3c5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3",
"hashValid": true,
"restorable": false,
"fieldCount": null
}
],
"total": 2,
"page": 1,
"limit": 20,
"totalPages": 1
}