> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve evidence

## Scope and credits

| Requirement     | Value                 |
| --------------- | --------------------- |
| Required scopes | `read:evidence`       |
| Credits         | 3 credits per request |


## OpenAPI

````yaml POST /v2/evidence
openapi: 3.1.0
info:
  description: Deterministic, evidence-backed threat assessment API for machine consumers.
  title: Threat Investigator API v2
  version: 0.1.0
servers: []
security: []
paths:
  /v2/evidence:
    post:
      tags:
        - Evidence
      summary: Claim-based evidence retrieval (LLM-free)
      operationId: claim_evidence_v2_evidence_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ClaimEvidenceRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClaimEvidenceResponse'
          description: Successful Response
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
      security:
        - ApiKeyAuth: []
components:
  schemas:
    ClaimEvidenceRequest:
      additionalProperties: false
      properties:
        agent_context:
          anyOf:
            - $ref: '#/components/schemas/AgentContext'
            - type: 'null'
        claim_type:
          enum:
            - active_exploitation
            - sector_targeting
            - actor_association
            - campaign_association
            - malware_association
            - relevance_to_environment
            - observed_in_the_wild
          title: Claim Type
          type: string
        context:
          anyOf:
            - $ref: '#/components/schemas/ClaimEvidenceContext'
            - type: 'null'
        cursor:
          anyOf:
            - maxLength: 512
              type: string
            - type: 'null'
          title: Cursor
        expected_types:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Expected Types
        max_results:
          default: 10
          maximum: 50
          minimum: 1
          title: Max Results
          type: integer
        query:
          anyOf:
            - maxLength: 1024
              type: string
            - type: 'null'
          title: Query
        resolution:
          anyOf:
            - $ref: '#/components/schemas/ResolutionOptions'
            - type: 'null'
        subject:
          anyOf:
            - $ref: '#/components/schemas/AssessmentSubject'
            - type: 'null'
      required:
        - claim_type
      title: ClaimEvidenceRequest
      type: object
    ClaimEvidenceResponse:
      properties:
        claim_type:
          enum:
            - active_exploitation
            - sector_targeting
            - actor_association
            - campaign_association
            - malware_association
            - relevance_to_environment
            - observed_in_the_wild
          title: Claim Type
          type: string
        context:
          $ref: '#/components/schemas/ClaimEvidenceContext'
        input_mode:
          enum:
            - subject
            - query
          title: Input Mode
          type: string
        items:
          items:
            $ref: '#/components/schemas/ClaimEvidenceItem'
          title: Items
          type: array
        max_results:
          title: Max Results
          type: integer
        metadata:
          additionalProperties: true
          title: Metadata
          type: object
        next_cursor:
          anyOf:
            - type: string
            - type: 'null'
          title: Next Cursor
        resolution:
          $ref: '#/components/schemas/ResolutionResult'
        status:
          enum:
            - ok
            - no_evidence
          title: Status
          type: string
        subject:
          anyOf:
            - $ref: '#/components/schemas/AssessmentSubject'
            - type: 'null'
      required:
        - status
        - input_mode
        - resolution
        - claim_type
        - context
        - max_results
        - items
        - metadata
      title: ClaimEvidenceResponse
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    AgentContext:
      additionalProperties: false
      properties:
        client:
          anyOf:
            - $ref: '#/components/schemas/AgentClientInfo'
            - type: 'null'
        constraints:
          anyOf:
            - $ref: '#/components/schemas/AgentConstraints'
            - type: 'null'
        objective:
          maxLength: 280
          minLength: 8
          title: Objective
          type: string
        parent_step_id:
          anyOf:
            - maxLength: 64
              type: string
            - type: 'null'
          title: Parent Step Id
        priority:
          anyOf:
            - enum:
                - low
                - normal
                - high
                - urgent
              type: string
            - type: 'null'
          title: Priority
        requested_outcome:
          maxLength: 280
          minLength: 3
          title: Requested Outcome
          type: string
        run_id:
          maxLength: 64
          minLength: 4
          title: Run Id
          type: string
        step_id:
          maxLength: 64
          minLength: 1
          title: Step Id
          type: string
        tags:
          anyOf:
            - items:
                type: string
              maxItems: 12
              type: array
            - type: 'null'
          title: Tags
        workflow_stage:
          enum:
            - resolve
            - evidence
            - relationships
            - assessment
            - hunt
            - hydrate
            - batch
            - finalize
            - other
          title: Workflow Stage
          type: string
      required:
        - objective
        - requested_outcome
        - workflow_stage
        - run_id
        - step_id
      title: AgentContext
      type: object
    ClaimEvidenceContext:
      additionalProperties: false
      properties:
        sector:
          anyOf:
            - type: string
            - type: 'null'
          title: Sector
      title: ClaimEvidenceContext
      type: object
    ResolutionOptions:
      additionalProperties: false
      properties:
        include_aliases:
          default: false
          title: Include Aliases
          type: boolean
        include_metadata:
          default: false
          title: Include Metadata
          type: boolean
        max_results:
          default: 5
          maximum: 25
          minimum: 1
          title: Max Results
          type: integer
      title: ResolutionOptions
      type: object
    AssessmentSubject:
      additionalProperties: false
      properties:
        canonical_id:
          title: Canonical Id
          type: string
        canonical_name:
          anyOf:
            - type: string
            - type: 'null'
          title: Canonical Name
        entity_type:
          title: Entity Type
          type: string
      required:
        - entity_type
        - canonical_id
      title: AssessmentSubject
      type: object
    ClaimEvidenceItem:
      properties:
        attributes:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Attributes
        evidence_id:
          title: Evidence Id
          type: string
        evidence_type:
          title: Evidence Type
          type: string
        published_date:
          anyOf:
            - type: string
            - type: 'null'
          title: Published Date
        source_url:
          anyOf:
            - type: string
            - type: 'null'
          title: Source Url
        stance:
          enum:
            - supports
            - contradicts
            - contextual
          title: Stance
          type: string
        summary_stub:
          anyOf:
            - type: string
            - type: 'null'
          title: Summary Stub
        support_score:
          title: Support Score
          type: number
        title:
          anyOf:
            - type: string
            - type: 'null'
          title: Title
      required:
        - evidence_type
        - evidence_id
        - stance
        - support_score
      title: ClaimEvidenceItem
      type: object
    ResolutionResult:
      properties:
        candidates:
          items:
            $ref: '#/components/schemas/EntityResolutionCandidate'
          title: Candidates
          type: array
        canonical_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Canonical Id
        canonical_name:
          anyOf:
            - type: string
            - type: 'null'
          title: Canonical Name
        entity_type:
          anyOf:
            - type: string
            - type: 'null'
          title: Entity Type
        input_mode:
          anyOf:
            - enum:
                - subject
                - query
              type: string
            - type: 'null'
          title: Input Mode
        resolution_confidence:
          anyOf:
            - type: number
            - type: 'null'
          title: Resolution Confidence
        status:
          enum:
            - resolved
            - ambiguous
            - not_found
            - not_applicable
          title: Status
          type: string
      required:
        - status
      title: ResolutionResult
      type: object
    ValidationError:
      properties:
        ctx:
          title: Context
          type: object
        input:
          title: Input
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
    AgentClientInfo:
      additionalProperties: false
      properties:
        agent_name:
          anyOf:
            - maxLength: 64
              type: string
            - type: 'null'
          title: Agent Name
        agent_version:
          anyOf:
            - maxLength: 32
              type: string
            - type: 'null'
          title: Agent Version
        framework:
          anyOf:
            - maxLength: 32
              type: string
            - type: 'null'
          title: Framework
      title: AgentClientInfo
      type: object
    AgentConstraints:
      additionalProperties: false
      properties:
        latency_budget_ms:
          anyOf:
            - maximum: 30000
              minimum: 50
              type: integer
            - type: 'null'
          title: Latency Budget Ms
        max_results_budget:
          anyOf:
            - maximum: 200
              minimum: 1
              type: integer
            - type: 'null'
          title: Max Results Budget
        min_resolution_confidence:
          anyOf:
            - maximum: 1
              minimum: 0
              type: number
            - type: 'null'
          title: Min Resolution Confidence
        strict_mode:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Strict Mode
      title: AgentConstraints
      type: object
    EntityResolutionCandidate:
      properties:
        aliases:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Aliases
        canonical_id:
          title: Canonical Id
          type: string
        canonical_name:
          title: Canonical Name
          type: string
        entity_type:
          title: Entity Type
          type: string
        match_type:
          title: Match Type
          type: string
        matched_on:
          anyOf:
            - type: string
            - type: 'null'
          title: Matched On
        metadata:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Metadata
        score:
          title: Score
          type: number
      required:
        - entity_type
        - canonical_id
        - canonical_name
        - match_type
        - score
      title: EntityResolutionCandidate
      type: object
  securitySchemes:
    ApiKeyAuth:
      description: ApiKey <key_id>:<secret>
      in: header
      name: Authorization
      type: apiKey

````