> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ocean.security/llms.txt
> Use this file to discover all available pages before exploring further.

# List recent threats

> Returns a paginated list of recent threats, optionally filtered by the number of days to look back.



## OpenAPI

````yaml get /api/v1/threats
openapi: 3.0.0
info:
  contact: {}
  title: Ocean Security API
  version: 1.0.0
  description: Ocean Security API for threat detection and security metrics
servers:
  - url: https://api.ocean.security
    description: Production server
security:
  - ApiKeyAuth: []
tags:
  - name: Threats
    description: Operations for retrieving threat information
  - name: Metrics
    description: Security metrics and analytics endpoints
paths:
  /api/v1/threats:
    get:
      tags:
        - Threats
      summary: List recent threats
      description: >-
        Returns a paginated list of recent threats, optionally filtered by the
        number of days to look back.
      parameters:
        - description: Authentication API Key
          in: header
          name: X-Api-Key
          required: true
          schema:
            type: string
        - description: Number of minutes to look back (default 7 * 24 * 60)
          in: query
          name: minutes_ago
          schema:
            type: integer
        - description: Page number for pagination (default 1)
          in: query
          name: page
          schema:
            type: integer
      responses:
        '200':
          description: A paginated list of threats
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/common.PaginatedResponse'
                  - properties:
                      results:
                        $ref: '#/components/schemas/controllers_threats.threatsResult'
                    type: object
        '400':
          description: Invalid input parameters (e.g., invalid days_ago)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/types.ErrorResponse'
        '401':
          description: Unauthorized (invalid or missing API Key)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/types.ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/types.ErrorResponse'
components:
  schemas:
    common.PaginatedResponse:
      properties:
        pagination:
          allOf:
            - $ref: '#/components/schemas/common.PaginationParams'
          description: Pagination information
        results:
          description: The actual data
        status:
          description: HTTP status code
          type: integer
      type: object
    controllers_threats.threatsResult:
      properties:
        items:
          items:
            $ref: '#/components/schemas/controllers_threats.ThreatItem'
          type: array
      type: object
    types.ErrorResponse:
      properties:
        error:
          type: string
      type: object
    common.PaginationParams:
      properties:
        page:
          description: Current page number (1-based)
          type: integer
        page_size:
          description: Number of items on this page (max 100)
          type: integer
        total:
          description: Total number of items
          type: integer
      type: object
    controllers_threats.ThreatItem:
      properties:
        action_taken:
          enum:
            - moved_to_trash
            - moved_to_spam
            - moved_to_graymail
            - moved_to_promotions
            - quarantined
            - released_from_quarantine
            - restored
            - none
          example: quarantined
          type: string
        detection_time:
          example: '1970-01-01T11:59:59.000Z'
          format: date-time
          type: string
        id:
          type: string
        recipient_email:
          type: string
        recipient_name:
          type: string
        remediation_time:
          example: '1970-01-01T11:59:59.000Z'
          format: date-time
          type: string
        sender_email:
          type: string
        sender_name:
          type: string
        source:
          type: string
        subject:
          type: string
        threat_indicators:
          items:
            $ref: '#/components/schemas/controllers_threats.ThreatIndicator'
          type: array
        threat_type:
          type: string
        time:
          example: '1970-01-01T11:59:59.000Z'
          format: date-time
          type: string
      type: object
    controllers_threats.ThreatIndicator:
      properties:
        indicator_type:
          type: string
      type: object
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-Api-Key
      description: API key for authentication

````