curl --request GET \
--url https://{subdomain}.conveyour.com/api/reports/shared/{pid}const options = {method: 'GET'};
fetch('https://{subdomain}.conveyour.com/api/reports/shared/{pid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET'};
fetch('https://{subdomain}.conveyour.com/api/reports/shared/{pid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/reports/shared/{pid}"
response = requests.get(url)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/reports/shared/{pid}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "<string>",
"data": {
"id": "<string>",
"title": "<string>",
"desc": "<string>",
"folder": "<string>",
"parent": "<string>",
"visual": "<string>",
"fields": {},
"controls": {},
"child_reports": [
{}
],
"actions": {},
"row_key": "<string>",
"exportable": true,
"shareable": true,
"params": {},
"data": {},
"retrieved_at": 123,
"visual_props": {},
"debug": {}
}
}{
"status": "failed",
"message": "Token is either expired or does not have the correct permissions",
"data": []
}Get a shared report
Returns a shared report without requiring authentication. Access is granted by the pid (a capability URL). For secure shared reports, pass a token query parameter containing the JWT generated by POST /api/custom-reports/:id/share. Shared reports have actions stripped and locked controls hidden — only the data and editable controls are returned.
The report_id segment is optional — /api/reports/shared/{pid} returns the shared report directly, and /api/reports/shared/{pid}/{report_id} selects a specific report within a shared bundle.
Get a shared report (no auth required)
This endpoint requires no authentication. Anyone who has the shared-report pid can read the report.
A missing record does not return 404. This handler reports the failure without a status code, and the error envelope defaults to HTTP 200 — you get 200 with status: "failed". Branch on status, not on the HTTP code.
curl --request GET \
--url https://{subdomain}.conveyour.com/api/reports/shared/{pid}const options = {method: 'GET'};
fetch('https://{subdomain}.conveyour.com/api/reports/shared/{pid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET'};
fetch('https://{subdomain}.conveyour.com/api/reports/shared/{pid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/reports/shared/{pid}"
response = requests.get(url)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/reports/shared/{pid}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "<string>",
"data": {
"id": "<string>",
"title": "<string>",
"desc": "<string>",
"folder": "<string>",
"parent": "<string>",
"visual": "<string>",
"fields": {},
"controls": {},
"child_reports": [
{}
],
"actions": {},
"row_key": "<string>",
"exportable": true,
"shareable": true,
"params": {},
"data": {},
"retrieved_at": 123,
"visual_props": {},
"debug": {}
}
}{
"status": "failed",
"message": "Token is either expired or does not have the correct permissions",
"data": []
}Path Parameters
The pid identifier.
Query Parameters
JWT token encoding the locked parameter values. Required when the shared report is configured with secure=true.
Pass data=1 to include report rows in the response.
Team scope for the request, as one or more team ObjectIds. The brackets are required: PHP keeps only the last value for a repeated plain key, so teams=A&teams=B silently resolves to B alone. On requests with a JSON body you may send teams (no brackets) in the body instead.
Values that are not valid ObjectIds are silently ignored — a mistyped team ID behaves as if no team was sent. See the teams section of the API conventions guide.
Override the reports provider used to resolve the shared report.
Response
Success.