> ## Documentation Index
> Fetch the complete documentation index at: https://developers.conveyour.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Run an action on a shared report

> Runs a row action on a shared report **without authentication** — the `pid` in the URL is the only thing identifying the caller, exactly like `GET /api/reports/shared/{pid}`.

Run a shared report action

**No token required.** Treat the `pid` as a secret: anyone holding it can run any shared-safe action on that report.

**Only actions explicitly marked shared-safe can run.** An action that exists but is not flagged for sharing returns `403` with `Action is not available on shared reports`. An unknown action key returns `404 Action not found`; a report whose class cannot be resolved returns `404 Report not found`.

`row_keys` is required and must be non-empty — an empty array returns `400 No rows selected`. For a report marked secure, pass the share `token` so its saved params are applied.

The response shape depends on the action; only `message` is guaranteed.



## OpenAPI

````yaml /api-reference/specs/reports.json post /api/reports/shared/{pid}/{report_id}/action/{action_key}
openapi: 3.1.0
info:
  title: ConveYour API — Reports
  description: >-
    Retrieve report data, run report actions, access shared reports, and manage
    custom report templates.
  version: 1.0.0
servers:
  - url: https://{subdomain}.conveyour.com
    description: Your organization's ConveYour instance
    variables:
      subdomain:
        default: acme
        description: >-
          Your organization's slug — the subdomain you sign in on. Replace
          `acme` with yours: if you sign in at `bigco.conveyour.com`, enter
          `bigco`.
security:
  - conveyourToken: []
tags:
  - name: Reports
    description: >-
      Retrieve report data, run report actions, access shared reports, and
      manage custom report templates.
paths:
  /api/reports/shared/{pid}/{report_id}/action/{action_key}:
    post:
      tags:
        - Reports
      summary: Run an action on a shared report
      description: >-
        Runs a row action on a shared report **without authentication** — the
        `pid` in the URL is the only thing identifying the caller, exactly like
        `GET /api/reports/shared/{pid}`.


        Run a shared report action


        **No token required.** Treat the `pid` as a secret: anyone holding it
        can run any shared-safe action on that report.


        **Only actions explicitly marked shared-safe can run.** An action that
        exists but is not flagged for sharing returns `403` with `Action is not
        available on shared reports`. An unknown action key returns `404 Action
        not found`; a report whose class cannot be resolved returns `404 Report
        not found`.


        `row_keys` is required and must be non-empty — an empty array returns
        `400 No rows selected`. For a report marked secure, pass the share
        `token` so its saved params are applied.


        The response shape depends on the action; only `message` is guaranteed.
      parameters:
        - name: pid
          in: path
          required: true
          schema:
            type: string
          description: Public ID of the shared report.
        - name: report_id
          in: path
          required: true
          schema:
            type: string
          description: Report class ID. Defaults to the shared report's own class.
        - name: action_key
          in: path
          required: true
          schema:
            type: string
          description: Key of the action to run, as listed in the report's `actions` block.
        - name: token
          in: query
          required: false
          schema:
            type: string
          description: >-
            Share token. Required when the report is marked secure, so its saved
            params apply.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - row_keys
              properties:
                row_keys:
                  type: array
                  items:
                    type: string
                  description: >-
                    Row identifiers to act on, taken from the field named by the
                    report's `row_key`. Must be non-empty.
                params:
                  type: object
                  additionalProperties: true
                  description: Optional action parameters.
      responses:
        '200':
          description: >-
            Action executed. Only `message` is guaranteed; other keys depend on
            the action.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: string
                  message:
                    type: string
                  data:
                    type: object
        '400':
          description: >-
            `No rows selected`, or missing pid/action key, or report setup
            failed.
        '403':
          description: '`Access denied`, or `Action is not available on shared reports`.'
        '404':
          description: '`Report not found` or `Action not found`.'
        '501':
          description: '`Action method not implemented`.'
components:
  securitySchemes:
    conveyourToken:
      type: apiKey
      in: header
      name: x-conveyour-token
      description: >-
        Your API key token. Contacts endpoints require a **Server-only — Full
        API** key — see [Authentication](/quickstart).

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.