Admin abuse report queue
const url = 'https://api.deploybase.eu/api/v1/api/v1/admin/abuse-reports';const options = {method: 'GET', headers: {Authorization: '<Authorization>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.deploybase.eu/api/v1/api/v1/admin/abuse-reports \ --header 'Authorization: <Authorization>'Notices submitted through the public /report-abuse channel (DSA Art. 16), newest first. Defaults to the open queue (new and reviewing). Reported URLs are returned as plain strings and must be rendered as text, never as links; deploybase never fetches them.
Authorizations
Section titled “ Authorizations ”Parameters
Section titled “ Parameters ”Query Parameters
Section titled “ Query Parameters ”New, reviewing, actioned, rejected, or open (default open)
Page number (default 1)
Page size, 1-100 (default 20)
Responses
Section titled “ Responses ”OK
object
object
object
object
ClosedAt is set exactly when Status is terminal (a CHECK constraint enforces the pair) and starts the 12-month retention clock.
GoodFaithDeclared is the Art. 16(2)(d) declaration. Always true on a stored row, kept so the record shows the declaration was actually made rather than assumed.
HandledBy is the Zitadel subject of the admin who last moved the row. Text, not uuid: there is no users table (same reasoning as notices.created_by).
ReportedURLs are the flagged URLs, 1 to 10, deduplicated case-insensitively at submission. NEVER fetched by us — see the service’s validation comment. The admin UI renders them as plain text, never as links.
ReporterEmail is where the acknowledgement and the statement of reasons go. Personal data: it is never written to a log line.
ReporterName is optional and empty when not given: Art. 16(2)(c) requires a name only for notices that are not about certain offences, so a blank is a lawful notice.
Resolution is what we did and why, in the operator’s own words. It is the raw material for the Art. 17 statement of reasons, so it should name the acceptable-use clause that was breached, or say plainly why the notice was rejected.
ResolvedTeamID is the team the notice turned out to be about. ON DELETE SET NULL in the schema: an account erasure must neither be blocked by this record nor destroy it.
Example generated
{ "data": { "page": 1, "page_size": 1, "reports": [ { "category": "example", "closed_at": "example", "created_at": "example", "description": "example", "good_faith_declared": true, "handled_at": "example", "handled_by": "example", "id": "example", "reported_urls": [ "example" ], "reporter_email": "example", "reporter_name": "example", "resolution": "example", "resolved_team_id": "example", "status": "example" } ], "total": 1 }, "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Bad Request
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Unauthorized
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Forbidden
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Internal Server Error
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Service Unavailable
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}