# List Compliance Forms

Retrieve a list of Compliance Form resources.

## Endpoint

GET /compliance_forms

## Security

BasicAuth

## Query parameters:

- `linked_to` (string)  
  Filter by the Merchant the Compliance Form resource is linked to.  
  Example: "MUwfZPNW3r4EqLMzwgr6txw4"

- `state` (string)  
  Filter by the Compliance Form's state. Use comma-separated values to filter for multiple states (for example, you can specify ?state=INCOMPLETE,EXPIRED).  
  Enum: "INCOMPLETE", "OVERDUE", "COMPLETE", "EXPIRED", "INVALID"

- `after_cursor` (string)  
  Return every resource created after the cursor value.

- `before_cursor` (string)  
  Return every resource created before the cursor value.

- `created_at.gte` (string)  
  Filter where created_at is after the given date.  
  Example: "2022-09-27T11:21:23"

- `created_at.lte` (string)  
  Filter where created_at is before the given date.  
  Example: "2026-09-27T11:21:23"

- `limit` (integer)  
  The numbers of items to return.  
  Example: 10

- `tags.key` (string)  
  Filter by the tag's key. For more information, see Tags.  
  Example: "card_type"

- `tags.value` (string)  
  Filter by the tag's value. For more information, see Tags.  
  Example: "business_card"

- `updated_at.gte` (string)  
  Filter where updated_at is after the given date.  
  Example: "2022-09-27T11:21:23"

- `updated_at.lte` (string)  
  Filter where updated_at is before the given date.  
  Example: "2026-09-27T11:21:23"

## Header parameters:

- `Finix-Version` (string)  
  Specify the API version of your request. For more details, see Versioning.  
  Example: "2022-02-01"

## Response 200 fields (application/json):

- `page` (object)  
  Details the page that's returned.

- `page.limit` (integer)  
  The number of entries to return.

- `page.next_cursor` (string,null)  
  The cursor to use for the next page of results.

- `_embedded` (object)

- `_embedded.compliance_forms` (array)

- `_embedded.compliance_forms.id` (string)  
  The ID of the resource.

- `_embedded.compliance_forms.created_at` (string)  
  Timestamp of when the object was created.

- `_embedded.compliance_forms.updated_at` (string)  
  Timestamp of when the object was last updated.

- `_embedded.compliance_forms.application` (string)  
  ID of the Application to which the Compliance Form belongs.

- `_embedded.compliance_forms.compliance_form_template` (string)  
  The ID of the template used to create the Compliance Form.

- `_embedded.compliance_forms.due_at` (string)  
  Timestamp of when the Compliance Form is due. By default, this is 3 months after the form was created.

- `_embedded.compliance_forms.files` (object)  
  IDs of the File resources for the signed and unsigned Compliance Form PDFs.

- `_embedded.compliance_forms.files.signed_file` (string,null)  
  The ID of the File resource for the signed Compliance Form PDF.

- `_embedded.compliance_forms.files.unsigned_file` (string)  
  The ID of the File resource for the unsigned Compliance Form PDF.

- `_embedded.compliance_forms.linked_to` (string)  
  The ID of the resource to which the Compliance Form belongs.

- `_embedded.compliance_forms.linked_type` (string)  
  Type of the resource to which the Compliance Form belongs.  
  Enum: "MERCHANT"

- `_embedded.compliance_forms.pci_saq_a` (object)  
  Details about the signee's digital signature

- `_embedded.compliance_forms.pci_saq_a.ip_address` (string,null)  
  The IP address of the signee.

- `_embedded.compliance_forms.pci_saq_a.is_accepted` (boolean)  
  Whether the signee has signed the form.

- `_embedded.compliance_forms.pci_saq_a.name` (string,null)  
  The full name of the signee.

- `_embedded.compliance_forms.pci_saq_a.signed_at` (string,null)  
  The timestamp of the signee's signature.

- `_embedded.compliance_forms.pci_saq_a.title` (string,null)  
  The job title of the signee.

- `_embedded.compliance_forms.pci_saq_a.user_agent` (string,null)  
  The User-Agent string of the signee's device.

- `_embedded.compliance_forms.state` (string)  
  The state of the Compliance Form.  
  Enum: "INCOMPLETE", "OVERDUE", "COMPLETE", "EXPIRED", "INVALID"

- `_embedded.compliance_forms.tags` (object,null)  
  Include up to 50 key: value pairs to annotate requests with custom metadata.
  - Maximum character length for individual keys is 40.
  - Maximum character length for individual values is 500.
  (For example, order_number: 25, item_type: produce, department: sales)

- `_embedded.compliance_forms.type` (string)  
  The type of the Compliance Form.  
  Enum: "PCI_SAQ_A"

- `_embedded.compliance_forms.valid_from` (string,null)  
  The timestamp of when the Compliance Form is valid from. This is set to the form's signed_at timestamp upon signature.

- `_embedded.compliance_forms.valid_until` (string,null)  
  The timestamp of when the Compliance Form is valid until. This is set to one year after the form's signed_at timestamp upon signature.

- `_embedded.compliance_forms.version` (string)  
  The version of the Compliance Form.

- `_links` (object)

- `_links.self` (object)  
  Link to the resource that was used in the request.

- `_links.self.href` (string)

- `_links.next` (object)  
  Link to the next page of entries.

- `_links.next.href` (string)

## Response 401 fields (application/json):

- `total` (integer, required)  
  Total number of errors returned.

- `_embedded` (object, required)  
  Container for embedded error objects.

- `_embedded.errors` (array)  
  List of individual error objects.

- `_embedded.errors.code` (string)  
  The error code. The UNKNOWN error code is returned for a 401 Unauthorized or 403 Forbidden request.

- `_embedded.errors.logref` (string)  
  A log reference identifier for the error, useful for debugging and support purposes.

- `_embedded.errors.message` (string)  
  A human-friendly error message.

- `_embedded.errors._links` (object)  
  Links related to this error.

- `_embedded.errors._links.self` (object)  
  Link to the resource related to the error.

- `_embedded.errors._links.self.href` (string)  
  URL of the related resource.

## Response 403 fields (application/json):

- `total` (integer, required)  
  Total number of errors returned.

- `_embedded` (object, required)  
  Container for embedded error objects.

- `_embedded.errors` (array)  
  List of individual error objects.

- `_embedded.errors.code` (string)  
  The error code. The UNKNOWN error code is returned for a 401 Unauthorized or 403 Forbidden request.

- `_embedded.errors.logref` (string)  
  A log reference identifier for the error, useful for debugging and support purposes.

- `_embedded.errors.message` (string)  
  A human-friendly error message.

- `_embedded.errors._links` (object)  
  Links related to this error.

- `_embedded.errors._links.self` (object)  
  Link to the resource related to the error.

- `_embedded.errors._links.self.href` (string)  
  URL of the related resource.

## Response 406 fields (application/json):

- `total` (integer, required)  
  Total number of errors returned.

- `_embedded` (object, required)  
  Container for embedded error objects.

- `_embedded.errors` (array)  
  List of individual error objects.

- `_embedded.errors.code` (string)  
  The error code. The UNKNOWN error code is returned for a 401 Unauthorized or 403 Forbidden request.

- `_embedded.errors.logref` (string)  
  A log reference identifier for the error, useful for debugging and support purposes.

- `_embedded.errors.message` (string)  
  A human-friendly error message.

- `_embedded.errors._links` (object)  
  Links related to this error.

- `_embedded.errors._links.self` (object)  
  Link to the resource related to the error.

- `_embedded.errors._links.self.href` (string)  
  URL of the related resource.

## Response 422 fields (application/json):

- `total` (integer, required)  
  Total number of errors returned.

- `_embedded` (object, required)  
  Container for embedded error objects.

- `_embedded.errors` (array)  
  List of individual error objects.

- `_embedded.errors.code` (string)  
  The error code. The UNKNOWN error code is returned for a 401 Unauthorized or 403 Forbidden request.

- `_embedded.errors.logref` (string)  
  A log reference identifier for the error, useful for debugging and support purposes.

- `_embedded.errors.message` (string)  
  A human-friendly error message.

- `_embedded.errors._links` (object)  
  Links related to this error.

- `_embedded.errors._links.self` (object)  
  Link to the resource related to the error.

- `_embedded.errors._links.self.href` (string)  
  URL of the related resource.
