> ## Documentation Index
> Fetch the complete documentation index at: https://docs.endorlabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ListAgentCalls

> Returns one agent's recent captured calls, newest first.



## OpenAPI

````yaml /api-reference/openapi.v3.json get /v1/namespaces/{tenant_meta.namespace}/agent-telemetry/agents/{agent_id}/calls
openapi: 3.0.3
info:
  description: Integrate your application with Endor Labs using the REST API.
  title: Endor Labs REST API Reference
  version: '1.0'
servers:
  - description: US (default)
    url: https://api.endorlabs.com
  - description: EU (data residency)
    url: https://api.eu.endorlabs.com
security: []
tags:
  - name: AISastCustomerContextService
  - name: APIKeyService
  - name: APIKeyValidatorService
  - name: AgentTelemetryService
  - name: ArtifactSignatureService
  - name: AuditLogService
  - name: AuthenticationLogService
  - name: AuthenticationService
  - name: AuthorizationPolicyService
  - name: BatchFileSegmentsService
  - name: BatchNotificationService
  - name: CallGraphDataService
  - name: CodeOwnersService
  - name: DependencyMetadataService
  - name: EndorIgnoreEntryService
  - name: ExporterService
  - name: FindingLogService
  - name: FindingService
  - name: HuggingFaceModelService
  - name: HuggingFaceOrganizationService
  - name: IPAddressPolicyService
  - name: IdentityProviderService
  - name: InstallationService
  - name: InvitationService
  - name: LicenseDependencyService
  - name: LicenseNoticesReportService
  - name: LicenseSummaryService
  - name: LinterResultService
  - name: MalwareExposureQueryService
  - name: MalwareExposureService
  - name: MalwareService
  - name: MetricService
  - name: NamespaceService
  - name: NotificationService
  - name: NotificationTargetService
  - name: OnPremSchedulerService
  - name: PRCommentConfigService
  - name: PackageFirewallLogService
  - name: PackageLicenseOverrideService
  - name: PackageLicenseQueryService
  - name: PackageLicenseService
  - name: PackageManagerService
  - name: PackageVersionService
  - name: PluginBinaryService
  - name: PolicyService
  - name: PolicyTemplateService
  - name: ProjectService
  - name: ProvisioningResultService
  - name: QueryMalwareService
  - name: QueryService
  - name: QuerySimilarPackagesService
  - name: QueryVulnerabilityService
  - name: RegistryIngestionCheckpointService
  - name: RepositoryService
  - name: RepositoryVersionService
  - name: RuleSetImportService
  - name: SBOMExportService
  - name: SBOMImportService
  - name: SCMCredentialService
  - name: SavedQueryService
  - name: ScanCreditUsageService
  - name: ScanLogRequestService
  - name: ScanProfileService
  - name: ScanResultService
  - name: ScanWorkflowResultService
  - name: ScanWorkflowService
  - name: SecretRuleService
  - name: SemgrepRuleService
  - name: SystemConfigService
  - name: TenantService
  - name: VEXExportService
  - name: VectorStoreService
  - name: VersionUpgradeService
  - name: VulnerabilityService
paths:
  /v1/namespaces/{tenant_meta.namespace}/agent-telemetry/agents/{agent_id}/calls:
    get:
      tags:
        - AgentTelemetryService
      summary: ListAgentCalls
      description: Returns one agent's recent captured calls, newest first.
      operationId: AgentTelemetryService_ListAgentCalls
      parameters:
        - description: >-
            Namespaces are a way to organize organizational units into virtual

            groupings of resources. Namespaces must be a fully qualified name,

            for example, the child namespace of namespace "endor.prod" called
            "app"

            is called "endor.prod.app".
          in: path
          name: tenant_meta.namespace
          required: true
          schema:
            type: string
          x-endor-name: Namespace
        - description: >-
            The agent whose calls to return; matches EndorAgent.id in the
            catalog.
          in: path
          name: agent_id
          required: true
          schema:
            type: string
        - description: Max rows to return. Defaults to 100 when zero.
          in: query
          name: page_size
          schema:
            format: int32
            type: integer
        - description: Opaque continuation token from a prior response.
          in: query
          name: page_token
          schema:
            type: string
        - description: >-
            Optional exact-match filter on decision. Accepted values: allowed,
            denied

            (case-sensitive); any other value is rejected.
          in: query
          name: decision
          schema:
            type: string
        - description: >-
            Optional exact-match filter on operation. Accepted values: READ,
            LIST,

            CREATE, UPDATE, DELETE, UPSERT, EXECUTE (case-sensitive); any other
            value

            is rejected.
          in: query
          name: operation
          schema:
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1ListAgentCallsResponse'
          description: A successful response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
          description: An unexpected error response.
components:
  schemas:
    v1ListAgentCallsResponse:
      description: >-
        ListAgentCallsResponse is served at

        GET
        /v1/namespaces/{tenant_meta.namespace}/agent-telemetry/agents/{agent_id}/calls.


        Cursor-only pagination: there is intentionally NO exact `total`. An
        exact

        COUNT over a filtered event scan is a per-open cost trap with no product

        value; this surface returns recent calls, not a precise count. The

        pre-aggregated per-agent count is AgentActivity.calls. More pages remain
        when

        next_page_token is non-empty; it is an opaque keyset cursor, never an
        offset.
      properties:
        agent_id:
          description: Echo of the requested agent id.
          type: string
        agent_identity:
          description: >-
            The agent's {name}@{version} identity; unset for an unregistered
            agent.
          type: string
        calls:
          description: The calls, newest first.
          items:
            $ref: '#/components/schemas/v1AgentCall'
          type: array
        next_page_token:
          description: Opaque keyset cursor; empty when there are no more pages.
          type: string
        schema_version:
          description: Schema version of this response envelope.
          type: string
      type: object
    googlerpcStatus:
      description: >-
        The `Status` type defines a logical error model that is suitable for

        different programming environments, including REST APIs and RPC APIs. It
        is

        used by [gRPC](https://github.com/grpc). Each `Status` message contains

        three pieces of data: error code, error message, and error details.


        You can find out more about this error model and how to work with it in
        the

        [API Design Guide](https://cloud.google.com/apis/design/errors).
      properties:
        code:
          description: |-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
          type: integer
        details:
          description: >-
            A list of messages that carry the error details.  There is a common
            set of

            message types for APIs to use.
          items:
            $ref: '#/components/schemas/googleprotobufAny'
          type: array
        message:
          description: >-
            A developer-facing error message, which should be in English. Any

            user-facing error message should be localized and sent in the

            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized

            by the client.
          type: string
      type: object
    v1AgentCall:
      description: >-
        AgentCall is one captured call in an agent's recent history — a
        tenant-safe

        projection of AgentAuditEvent.
      properties:
        decision:
          description: allowed | denied.
          type: string
        on_behalf_of:
          description: The human principal the agent acted on behalf of; unset when none.
          type: string
        operation:
          description: >-
            Coarse verb: READ | LIST | CREATE | UPDATE | DELETE | UPSERT |
            EXECUTE.

            Unset when the operation could not be derived, distinct from a
            recorded

            empty verb.
          type: string
        resource_kind:
          description: The Endor resource the call operated on (e.g. Project).
          type: string
        rpc_method:
          description: Full gRPC method, for engineers who want the exact RPC.
          type: string
        scopes:
          description: >-
            The scope the call ran under, e.g. customer-full; comma-joined when
            more than

            one. Unset when none were recorded.
          type: string
        session:
          description: >-
            The agent-run session this call belongs to; unset for a call with no
            session.
          type: string
        status_code:
          description: gRPC status code name (e.g. OK, PermissionDenied).
          type: string
        timestamp:
          description: When the edge observed the call.
          format: date-time
          type: string
      type: object
    googleprotobufAny:
      additionalProperties: {}
      description: >-
        `Any` contains an arbitrary serialized protocol buffer message along
        with a

        URL that describes the type of the serialized message.


        Protobuf library provides support to pack/unpack Any values in the form

        of utility functions or additional generated methods of the Any type.


        Example 1: Pack and unpack a message in C++.

            Foo foo = ...;
            Any any;
            any.PackFrom(foo);
            ...
            if (any.UnpackTo(&foo)) {
              ...
            }

        Example 2: Pack and unpack a message in Java.

            Foo foo = ...;
            Any any = Any.pack(foo);
            ...
            if (any.is(Foo.class)) {
              foo = any.unpack(Foo.class);
            }
            // or ...
            if (any.isSameTypeAs(Foo.getDefaultInstance())) {
              foo = any.unpack(Foo.getDefaultInstance());
            }

         Example 3: Pack and unpack a message in Python.

            foo = Foo(...)
            any = Any()
            any.Pack(foo)
            ...
            if any.Is(Foo.DESCRIPTOR):
              any.Unpack(foo)
              ...

         Example 4: Pack and unpack a message in Go

             foo := &pb.Foo{...}
             any, err := anypb.New(foo)
             if err != nil {
               ...
             }
             ...
             foo := &pb.Foo{}
             if err := any.UnmarshalTo(foo); err != nil {
               ...
             }

        The pack methods provided by protobuf library will by default use

        'type.googleapis.com/full.type.name' as the type URL and the unpack

        methods only use the fully qualified type name after the last '/'

        in the type URL, for example "foo.bar.com/x/y.z" will yield type

        name "y.z".


        JSON

        ====

        The JSON representation of an `Any` value uses the regular

        representation of the deserialized, embedded message, with an

        additional field `@type` which contains the type URL. Example:

            package google.profile;
            message Person {
              string first_name = 1;
              string last_name = 2;
            }

            {
              "@type": "type.googleapis.com/google.profile.Person",
              "firstName": <string>,
              "lastName": <string>
            }

        If the embedded message type is well-known and has a custom JSON

        representation, that representation will be embedded adding a field

        `value` which holds the custom JSON in addition to the `@type`

        field. Example (for message [google.protobuf.Duration][]):

            {
              "@type": "type.googleapis.com/google.protobuf.Duration",
              "value": "1.212s"
            }
      properties:
        '@type':
          description: >-
            A URL/resource name that uniquely identifies the type of the
            serialized

            protocol buffer message. This string must contain at least

            one "/" character. The last segment of the URL's path must represent

            the fully qualified name of the type (as in

            `path/google.protobuf.Duration`). The name should be in a canonical
            form

            (e.g., leading "." is not accepted).


            In practice, teams usually precompile into the binary all types that
            they

            expect it to use in the context of Any. However, for URLs which use
            the

            scheme `http`, `https`, or no scheme, one can optionally set up a
            type

            server that maps type URLs to message definitions as follows:


            * If no scheme is provided, `https` is assumed.

            * An HTTP GET on the URL must yield a [google.protobuf.Type][]
              value in binary format, or produce an error.
            * Applications are allowed to cache lookup results based on the
              URL, or have them precompiled into a binary to avoid any
              lookup. Therefore, binary compatibility needs to be preserved
              on changes to types. (Use versioned type names to manage
              breaking changes.)

            Note: this functionality is not currently available in the official

            protobuf release, and it is not used for type URLs beginning with

            type.googleapis.com. As of May 2023, there are no widely used type
            server

            implementations and no plans to implement one.


            Schemes other than `http`, `https` (or the empty scheme) might be

            used with implementation specific semantics.
          type: string
      type: object

````