---
title: List passport snapshots
description: "Paginated list of immutability snapshots for a passport, newest first. Re-verifies the content hash on read — hashValid: false flags at-rest tampering."
canonical: "https://www.tracepass.eu/docs/list-passport-snapshots"
locale: en
source: "https://www.tracepass.eu/docs/list-passport-snapshots"
---

# List passport snapshots

> Paginated list of immutability snapshots for a passport, newest first. Re-verifies the content hash on read — hashValid: false flags at-rest tampering.

```http
GET /api/v1/passports/{id}/snapshots
```

Returns a paginated list of immutability **snapshots** for a passport, newest first. A snapshot is written on publish and after every change to a published, suspended, expired or archived passport — field values, translations, parties, status transitions, supplier answers, AI writes, restores — whenever what the passport asserts actually changed (EN 18221:2026 4.2). Each entry includes the snapshot id, version number, reason (e.g. `published`, `field_edit`, `status_change`, `baseline`), who caused it (`actor`, when known), timestamp, content hash, and whether the hash still verifies — `hashValid: false` indicates at-rest tampering.

Snapshots also carry `restorable` (whether `rawFields` was captured so a field-level restore is possible) and `fieldCount` (number of fields in `rawFields`, or `null` for evidence-only snapshots taken before `rawFields` existed). Passports that predated snapshots have a `baseline` snapshot from the first nightly sweep; history before that point was never captured.

**Point in time:** add `?at=<ISO 8601>` to get the one snapshot valid at that instant — the full record plus `validFrom` and `validUntil` (null while current) — instead of the list. Returns 404 when the time predates the passport's first snapshot.

Tenant-scoped: only your company's passports are visible. Counts as one v1 passport read against the daily cap. Paginate with `?page` (1-based, default 1) and `?limit` (1–100, default 20).

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `Authorization` | header | string | yes | `Bearer <token>` — either a `tp_` API key (Developer → API Keys; simplest, for server-to-server) or an OAuth 2.0 access token (Developer → OAuth Apps; for user-authorized apps, scoped + revocable). The Authentication page has the full OAuth flow and scope list. |
| `id` | path | ObjectId | yes | Passport ID. |
| `page` | query | integer | no | Page number (1-based, default 1). |
| `at` | query | string (ISO 8601) | no | Return the snapshot valid at this instant instead of the list. |
| `limit` | query | integer | no | Page size (1–100, default 20). |

## Examples

```bash
curl -sS "https://app.tracepass.eu/api/v1/passports/6650b2c3d4e5f6a7b8c9d0e1/snapshots?limit=5" \
  -H "Authorization: Bearer tp_REDACTED_xxxxxxxxxxxx"
```

```typescript
const res = await fetch(
  `https://app.tracepass.eu/api/v1/passports/${passportId}/snapshots?limit=5`,
  { headers: { Authorization: `Bearer ${process.env.TRACEPASS_API_KEY}` } },
);
const { entries, total, page, totalPages } = await res.json();
```

```python
import os, requests
res = requests.get(
    f"https://app.tracepass.eu/api/v1/passports/{passport_id}/snapshots",
    headers={"Authorization": f"Bearer {os.environ['TRACEPASS_API_KEY']}"},
    params={"limit": 5},
)
res.raise_for_status()
data = res.json()  # { entries, total, page, limit, totalPages }
```

## Responses

### 200 — Success

```json
{
  "entries": [
    {
      "id": "65a0f1b2c3d4e5f6a7b8c9d1",
      "version": 3,
      "reason": "republished",
      "snapshotAt": "2026-09-15T14:32:00.000Z",
      "contentHash": "a3f1c2d4e5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2",
      "hashValid": true,
      "restorable": true,
      "fieldCount": 124
    },
    {
      "id": "65a0f1b2c3d4e5f6a7b8c9d0",
      "version": 1,
      "reason": "published",
      "snapshotAt": "2026-08-01T09:00:00.000Z",
      "contentHash": "b4e2d3c5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3",
      "hashValid": true,
      "restorable": false,
      "fieldCount": null
    }
  ],
  "total": 2,
  "page": 1,
  "limit": 20,
  "totalPages": 1
}
```

### 404 — Not found

```json
{ "error": "Passport not found" }
```

## Related

- [Get passport](https://www.tracepass.eu/docs/get-passport.md)
- [Get snapshot](https://www.tracepass.eu/docs/get-passport-snapshot.md)
