package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"github.com/conductorone/conductorone-sdk-go/pkg/models/operations"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.SpendInsights.GetDenial(ctx, operations.C1APISpendinsightsV1SpendInsightsServiceGetDenialRequest{
BlockID: "<id>",
})
if err != nil {
log.Fatal(err)
}
if res.GetDenialResponse != nil {
// handle response
}
}curl --request GET \
--url https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.get("https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"episode": {
"attemptCount": "<string>",
"authorityId": "<string>",
"authorityKind": "AUTHORITY_KIND_UNSPECIFIED",
"authorityVersion": "<string>",
"blockId": "<string>",
"budgetKey": "<string>",
"closedAt": "2023-11-07T05:31:56Z",
"firstDeniedAt": "2023-11-07T05:31:56Z",
"lastDeniedAt": "2023-11-07T05:31:56Z",
"periodEnd": "2023-11-07T05:31:56Z",
"periodKey": "<string>",
"periodKind": "PERIOD_KIND_UNSPECIFIED",
"periodStart": "2023-11-07T05:31:56Z",
"reason": "DENY_REASON_UNSPECIFIED",
"requestTaskId": "<string>",
"requestTaskState": "TICKET_STATE_UNSPECIFIED",
"scopeAppId": "<string>",
"scopeKind": "SPEND_BLOCK_SCOPE_KIND_UNSPECIFIED",
"scopeUserId": "<string>",
"state": "SPEND_BLOCK_STATE_UNSPECIFIED"
},
"firstDenialMoney": {
"consumedNano": "<string>",
"currencyCode": "<string>",
"limitNano": "<string>",
"requestedNano": "<string>",
"reservedNano": "<string>"
},
"historicalTrace": {
"allocations": [
{
"budgetKey": "<string>",
"limit": {
"amount": {
"amountNano": "<string>"
},
"unlimited": {}
},
"period": "PERIOD_KIND_UNSPECIFIED",
"source": {
"absent": true,
"appEntitlementId": "<string>",
"appId": "<string>",
"appUserId": "<string>",
"kind": "AUTHORITY_KIND_UNSPECIFIED",
"ruleId": "<string>",
"userId": "<string>",
"version": "<string>"
}
}
],
"authorityRefs": [
{
"absent": true,
"appEntitlementId": "<string>",
"appId": "<string>",
"appUserId": "<string>",
"kind": "AUTHORITY_KIND_UNSPECIFIED",
"ruleId": "<string>",
"userId": "<string>",
"version": "<string>"
}
]
}
}Get Denial
Get one budget-denial episode by its unique ID.
package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"github.com/conductorone/conductorone-sdk-go/pkg/models/operations"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.SpendInsights.GetDenial(ctx, operations.C1APISpendinsightsV1SpendInsightsServiceGetDenialRequest{
BlockID: "<id>",
})
if err != nil {
log.Fatal(err)
}
if res.GetDenialResponse != nil {
// handle response
}
}curl --request GET \
--url https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.get("https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/spend-insights/denials/{block_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"episode": {
"attemptCount": "<string>",
"authorityId": "<string>",
"authorityKind": "AUTHORITY_KIND_UNSPECIFIED",
"authorityVersion": "<string>",
"blockId": "<string>",
"budgetKey": "<string>",
"closedAt": "2023-11-07T05:31:56Z",
"firstDeniedAt": "2023-11-07T05:31:56Z",
"lastDeniedAt": "2023-11-07T05:31:56Z",
"periodEnd": "2023-11-07T05:31:56Z",
"periodKey": "<string>",
"periodKind": "PERIOD_KIND_UNSPECIFIED",
"periodStart": "2023-11-07T05:31:56Z",
"reason": "DENY_REASON_UNSPECIFIED",
"requestTaskId": "<string>",
"requestTaskState": "TICKET_STATE_UNSPECIFIED",
"scopeAppId": "<string>",
"scopeKind": "SPEND_BLOCK_SCOPE_KIND_UNSPECIFIED",
"scopeUserId": "<string>",
"state": "SPEND_BLOCK_STATE_UNSPECIFIED"
},
"firstDenialMoney": {
"consumedNano": "<string>",
"currencyCode": "<string>",
"limitNano": "<string>",
"requestedNano": "<string>",
"reservedNano": "<string>"
},
"historicalTrace": {
"allocations": [
{
"budgetKey": "<string>",
"limit": {
"amount": {
"amountNano": "<string>"
},
"unlimited": {}
},
"period": "PERIOD_KIND_UNSPECIFIED",
"source": {
"absent": true,
"appEntitlementId": "<string>",
"appId": "<string>",
"appUserId": "<string>",
"kind": "AUTHORITY_KIND_UNSPECIFIED",
"ruleId": "<string>",
"userId": "<string>",
"version": "<string>"
}
}
],
"authorityRefs": [
{
"absent": true,
"appEntitlementId": "<string>",
"appId": "<string>",
"appUserId": "<string>",
"kind": "AUTHORITY_KIND_UNSPECIFIED",
"ruleId": "<string>",
"userId": "<string>",
"version": "<string>"
}
]
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Path Parameters
Unique identifier for the denial episode.
Response
GetDenialResponse contains a denial episode and its first-refusal context.
GetDenialResponse contains a denial episode and its first-refusal context.
DenialEpisode represents repeated budget refusals for one scope and budget period.
Show child attributes
Show child attributes
DenialMoneySnapshot captures account amounts at the first refusal.
Show child attributes
Show child attributes
AdmissionTrace is the bounded authority decision committed with a reservation. It stores typed row references and resolved limits, never full authority rows. Relevant absences remain explicit because a row created between resolution and commit is the fail-open half of the pin set.
Reservation.expires_at is the Dynamo TTL attribute, so this trace supports in-flight atomicity and bounded operational diagnosis only. The durable copy belongs on M2's per-call usage record.
Show child attributes
Show child attributes
Was this page helpful?