# Discovery inventory

Source: https://immiscible.fly.dev/docs/api/get-api-w-wid-discovery

`GET /api/w/:wid/discovery`

Owners, admins and analysts. The vendor connections (never their credentials), a summary, every discovered item and the open revocation proposals. Filter with `status` (`unmanaged`, `managed`, `ignored`, `revoked`, `gone`) and `vendor` (`openai`, `anthropic`, `openrouter`).

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery?status=unmanaged&vendor=openai" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery?status=unmanaged&vendor=openai', {
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.get(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery",
    params={
        "status": "unmanaged",
        "vendor": "openai",
    },
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
    },
)
print(res.status_code, res.json())
```

## Response

```json
{
  "connections": [{ "vendor": "openai", "connected": true, "fingerprint": "sk-a...9f2c", "policy": "alert", "syncHours": 6, "lastSyncAt": "2026-10-04T09:00:00Z", "lastSyncStatus": "ok" }],
  "summary": { "unmanagedKeys": 2, "unmanagedSpendMicros": 44750000, "managedKeys": 1, "revokedKeys": 0, "projects": 1, "spendDays": 30 },
  "items": [{ "id": "dsc_4f2c91a7d0e3b6a81c55", "vendor": "openai", "kind": "api_key", "externalId": "key_abc", "name": "ana laptop", "redacted": "sk-proj-abc...wxyz", "owner": { "kind": "user", "email": "ana@acme.example", "userId": "usr_21b7" }, "status": "unmanaged", "firstSeenAt": "2026-10-04T09:00:00Z", "lastSeenAt": "2026-10-04T15:00:00Z", "spendMicros": 41500000, "spendBasis": "vendor_cost_30d", "revocable": true }],
  "proposals": [],
  "alone": false
}
```
