---
title: "Get a Scorecard"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/operations/fetch-scorecard"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# Get a Scorecard

`GET` `/scorecards/{id}`

Operation ID: `fetch-scorecard`

Fetches a scorecard.

## Path parameters

- `id` (string, uuid, required) - The `id` of the scorecard.

## Responses

- `200` - A response containing a single scorecard.
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
paths:
  /scorecards/{id}:
    parameters:
      - schema:
          type: string
          format: uuid
          example: f3704e4c-104d-4f21-998a-20d4364c893f
        name: id
        in: path
        required: true
        description: The `id` of the scorecard.
    get:
      summary: Get a Scorecard
      description: Fetches a scorecard.
      operationId: fetch-scorecard
      responses:
        "200":
          $ref: "#/components/responses/ScorecardResponse"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
        "404":
          $ref: "#/components/responses/NotFound"
      tags:
        - Scorecards
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  responses:
    ScorecardResponse:
      description: A response containing a single scorecard.
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/ScorecardWithCriteria"
          examples:
            Scorecard:
              $ref: "#/components/examples/FetchScorecardResponse"
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/UnauthorizedExample"
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/ForbiddenExample"
    NotFound:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
          examples:
            NotFoundExample:
              $ref: "#/components/examples/NotFoundExample"
  schemas:
    ScorecardWithCriteria:
      type: object
      description: Representation of a scorecard.
      required:
        - id
        - name
        - description
        - score
        - entity_selector
        - scorecard_template
        - created_at
        - updated_at
        - criteria
      properties:
        id:
          type: string
          format: uuid
          example: f3704e4c-104d-4f21-998a-20d4364c893f
        name:
          type: string
          description: The human-readable name of the scorecard.
          example: Incident Response
        description:
          type: string
          nullable: true
          example: Governs key metrics pertaining to teams' incident response practices.
        score:
          $ref: "#/components/schemas/ScorecardScore"
        entity_selector:
          $ref: "#/components/schemas/ScorecardEntitySelector"
        scorecard_template:
          type: string
          description: |
            The name of the scorecard template used to create the scorecard.
            Otherwise, `null`.
          enum:
            - kong_best_practices
            - service_documentation
            - service_maturity
            - security_and_compliance
          example: kong_best_practices
          nullable: true
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        updated_at:
          $ref: "#/components/schemas/UpdatedAt"
        criteria:
          type: array
          items:
            $ref: "#/components/schemas/ScorecardCriteria"
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 401
            title:
              example: Unauthorized
            type:
              example: https://httpstatuses.com/401
            instance:
              example: kong:trace:1234567890
            detail:
              example: Invalid credentials
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 403
            title:
              example: Forbidden
            type:
              example: https://httpstatuses.com/403
            instance:
              example: kong:trace:1234567890
            detail:
              example: Forbidden
    NotFoundError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 404
            title:
              example: Not Found
            type:
              example: https://httpstatuses.com/404
            instance:
              example: kong:trace:1234567890
            detail:
              example: Not found
    ScorecardScore:
      type: object
      description: >
        The current score for the given Scorecard.

        A `null` value indicates the scorecard has not yet been evaluated and
        therefore no score has been computed.
      nullable: true
      required:
        - value
        - raw_value
      properties:
        value:
          type: string
          description: The human-readable score value coverted to the Scorecard's assigned
            grading system.
          example: 88%
        raw_value:
          type: number
          description: >
            The raw, numeric score calculated during evaluation of the
            scorecard.

            Rounded to 3 decimal places.
          minimum: 0
          maximum: 100
          example: 87.5
    ScorecardEntitySelector:
      title: ScorecardEntitySelector
      description: |
        Selector used to dynamically target catalog entities that will be
        included in the given scorecard's evaluated score.
      oneOf:
        - $ref: "#/components/schemas/ServiceSelector"
      example:
        selector: label
        selector_parameters:
          label_key: product_area
          operator: eq
          value: cloud_platform
      type: object
      nullable: true
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    UpdatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity update date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    ScorecardCriteria:
      type: object
      required:
        - id
        - name
        - scorecard_id
        - integration
        - enabled
        - template_name
        - template_parameters
        - section_name
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          example: 5c1121f9-3f3a-47c7-9bb6-c81a51128714
        name:
          type: string
          nullable: true
          description: Override display name for the criteria, for greater contextual
            clarity within a given scorecard.
          example: Time to restore service is less than 6 hours over the last 3 months.
        scorecard_id:
          type: string
          format: uuid
          example: f3704e4c-104d-4f21-998a-20d4364c893f
        integration:
          type: string
          nullable: true
          description: The integration `name` when it provides the criteria template.
            Otherwise `null`.
          example: null
        enabled:
          type: boolean
          description: Whether the criteria is enabled for the given scorecard.
          example: true
        template_name:
          $ref: "#/components/schemas/CriteriaTemplateName"
        template_parameters:
          $ref: "#/components/schemas/CriteriaParameters"
        section_name:
          type: string
          nullable: true
          minLength: 1
          maxLength: 120
          example: Documentation
          description: Organizational section name for the criteria within the scorecard.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        updated_at:
          $ref: "#/components/schemas/UpdatedAt"
    BaseError:
      type: object
      title: Error
      description: standard error
      required:
        - status
        - title
        - instance
        - detail
      properties:
        status:
          type: integer
          description: >
            The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an
            integer.
          readOnly: true
        title:
          type: string
          description: |
            A short, human-readable summary of the problem. It should not
            change between occurences of a problem, except for localization.
            Should be provided as "Sentence case" for direct use in the UI.
          readOnly: true
        type:
          type: string
          description: The error type.
          readOnly: true
        instance:
          type: string
          description: |
            Used to return the correlation ID back to the user, in the format
            kong:trace:<correlation_id>. This helps us find the relevant logs
            when a customer reports an issue.
          readOnly: true
        detail:
          type: string
          description: >
            A human readable explanation specific to this occurence of the
            problem.

            This field may contain request/entity data to help the user
            understand

            what went wrong. Enclose variable values in square brackets. Should
            be

            provided as "Sentence case" for direct use in the UI.
          readOnly: true
    ServiceSelector:
      oneOf:
        - $ref: "#/components/schemas/AllEntitiesSelector"
        - $ref: "#/components/schemas/ByIDsSelector"
        - $ref: "#/components/schemas/ByNameSelector"
        - $ref: "#/components/schemas/ByDisplayNameSelector"
        - $ref: "#/components/schemas/ByCustomFieldSelector"
        - $ref: "#/components/schemas/ByLabelSelector"
        - $ref: "#/components/schemas/HasLabelKeySelector"
        - $ref: "#/components/schemas/HasDocsSelector"
        - $ref: "#/components/schemas/HasApisSelector"
        - $ref: "#/components/schemas/HasResourcesSelector"
    CriteriaTemplateName:
      type: string
      description: Reference to the unique `name` of the criteria template.
      example: time_to_merge
    CriteriaParameters:
      type: object
      description: >
        Input parameters for the given criteria template.

        The available parameters, and its schema, are found on the criteria
        template definition via

        the `schema` property. Criteria template definitions are determined by
        the `/v1/criteria-templates`

        endpoint.
      nullable: true
      additionalProperties: true
      example:
        measure: median
        threshold:
          unit: hours
          value: 6
        window:
          unit: months
          value: 3
    AllEntitiesSelector:
      type: object
      description: Entity selector that includes all entities of the given type within
        the catalog.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - all
        selector_parameters:
          type: string
          enum:
            - null
          nullable: true
    ByIDsSelector:
      type: object
      description: Entity selector that includes entities contained within a list of IDs.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - ids
        selector_parameters:
          type: object
          required:
            - ids
          properties:
            ids:
              type: array
              items:
                type: string
                format: uuid
    ByNameSelector:
      type: object
      description: Entity selector that includes entities by `name`.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - name
        selector_parameters:
          $ref: "#/components/schemas/StringFieldSelectorParams"
    ByDisplayNameSelector:
      type: object
      description: Entity selector that includes entities by `display_name`.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - display_name
        selector_parameters:
          $ref: "#/components/schemas/StringFieldSelectorParams"
    ByCustomFieldSelector:
      type: object
      description: Entity selector that include entities by a custom field.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - custom_field
        selector_parameters:
          oneOf:
            - type: object
              title: StringCustomFieldSelectorParams
              required:
                - field
                - value
                - operator
              properties:
                field:
                  type: string
                  description: Name of the custom field.
                value:
                  type: string
                operator:
                  $ref: "#/components/schemas/StringSelectorOperator"
            - type: object
              title: NumberCustomFieldSelectorParams
              required:
                - field
                - value
                - operator
              properties:
                field:
                  type: string
                  description: Name of the custom field.
                value:
                  type: number
                operator:
                  $ref: "#/components/schemas/NumberSelectorOperator"
            - type: object
              title: BooleanCustomFieldSelectorParams
              required:
                - field
                - value
                - operator
              properties:
                field:
                  type: string
                  description: Name of the custom field.
                value:
                  type: boolean
                operator:
                  $ref: "#/components/schemas/BooleanSelectorOperator"
            - type: object
              title: UrlCustomFieldSelectorParams
              required:
                - field
                - subfield
                - value
                - operator
              properties:
                field:
                  type: string
                  description: Name of the custom field.
                subfield:
                  type: string
                  enum:
                    - name
                    - link
                  description: Specify which subfield of the `url` custom field value to use for
                    selection.
                value:
                  type: string
                operator:
                  $ref: "#/components/schemas/StringSelectorOperator"
    ByLabelSelector:
      type: object
      description: Entity selector that includes entities by `label` value.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - label
        selector_parameters:
          type: object
          required:
            - operator
            - value
            - label_key
          properties:
            operator:
              $ref: "#/components/schemas/StringSelectorOperator"
            value:
              type: string
            label_key:
              type: string
          title: LabelSelectorParams
    HasLabelKeySelector:
      type: object
      description: Entity selector that includes entities by inclusion of a `label` key.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - has_label_key
        selector_parameters:
          type: object
          title: HasLabelKeySelectorParams
          required:
            - label_key
          properties:
            label_key:
              type: string
    HasDocsSelector:
      type: object
      description: Entity selector to include entities by attached documentation.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - has_docs
        selector_parameters:
          type: string
          enum:
            - null
          nullable: true
    HasApisSelector:
      type: object
      description: Entity selector that includes services by attached APIs.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - api_count
        selector_parameters:
          $ref: "#/components/schemas/HasSelectorParams"
    HasResourcesSelector:
      type: object
      description: Entity selector that includes services by mapped resources.
      required:
        - selector
        - selector_parameters
      properties:
        selector:
          type: string
          enum:
            - resource_count
        selector_parameters:
          type: object
          required:
            - operator
            - value
            - resource_type
            - integration
          properties:
            operator:
              $ref: "#/components/schemas/HasRelationshipSelectorOperator"
            value:
              type: number
            resource_type:
              $ref: "#/components/schemas/CatalogResourceType"
            integration:
              type: string
              description: The machine name of the integration that uniquely identifies it
                within the catalog.
              example: gateway-manager
          title: HasResourcesSelectorParams
    StringFieldSelectorParams:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/StringSelectorOperator"
        value:
          type: string
    StringSelectorOperator:
      type: string
      enum:
        - eq
        - contains
    NumberSelectorOperator:
      type: string
      enum:
        - eq
        - lt
        - gt
    BooleanSelectorOperator:
      type: string
      enum:
        - eq
    HasSelectorParams:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/HasRelationshipSelectorOperator"
        value:
          type: number
    HasRelationshipSelectorOperator:
      type: string
      enum:
        - eq
        - gte
        - lte
    CatalogResourceType:
      type: string
      description: >
        The resource type. Available resource types are compiled from the
        integrations installed within the catalog.
      minLength: 1
      maxLength: 120
      example: gateway_svc
  examples:
    FetchScorecardResponse:
      value:
        id: 4e74159d-3d56-435a-920e-6ddb9ffce829
        name: Kong Best Practices
        description: Best practices that we encourage users to follow when using other
          Konnect applications.
        score: null
        entity_selector:
          selector: all
          selector_parameters: null
        scorecard_template: kong_best_practices
        created_at: 2022-11-04T20:10:06.927Z
        updated_at: 2022-11-04T20:10:06.927Z
        criteria:
          - id: be228fb7-c492-4d5f-b933-6666a33373a8
            name: null
            scorecard_id: 4e74159d-3d56-435a-920e-6ddb9ffce829
            integration: gateway-manager
            enabled: true
            template_name: gateway_manager_error_rate
            template_parameters:
              threshold: 10
              relative_window: 30d
            section_name: Gateway Observability
            created_at: 2022-11-04T20:10:06.927Z
            updated_at: 2022-11-04T20:10:06.927Z
          - id: 5ea2ec85-73a1-46ed-9c2c-6f2b7a66c716
            name: null
            scorecard_id: 4e74159d-3d56-435a-920e-6ddb9ffce829
            integration: gateway-manager
            enabled: true
            template_name: gateway_manager_response_latency
            template_parameters:
              metric: response_latency_p95
              threshold: 30
              relative_window: 30d
            section_name: Gateway Observability
            created_at: 2022-11-04T20:10:06.927Z
            updated_at: 2022-11-04T20:10:06.927Z
          - id: ff262fb9-2493-4c8a-9288-211ce0802be6
            name: null
            scorecard_id: 4e74159d-3d56-435a-920e-6ddb9ffce829
            integration: gateway-manager
            enabled: true
            template_name: gateway_manager_has_plugin
            template_parameters:
              category: Authentication
            section_name: Plugin Enforcement
            created_at: 2022-11-04T20:10:06.927Z
            updated_at: 2022-11-04T20:10:06.927Z
    UnauthorizedExample:
      value:
        status: 401
        title: Unauthorized
        instance: kong:trace:8347343766220159418
        detail: Unauthorized
    ForbiddenExample:
      value:
        status: 403
        title: Forbidden
        instance: kong:trace:2723154947768991354
        detail: You do not have permission to perform this action
    NotFoundExample:
      value:
        status: 404
        title: Not Found
        instance: kong:trace:6816496025408232265
        detail: Not Found
  securitySchemes:
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        The Konnect access token is meant to be used by the Konnect dashboard
        and the decK CLI authenticate with.
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The personal access token is meant to be used as an alternative to
        basic-auth when accessing Konnect via APIs.

        You can generate a Personal Access Token (PAT) from the [personal access
        token page](https://cloud.konghq.com/global/account/tokens/) in the
        Konnect dashboard.

        The PAT token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer kpat_xgfT...'`
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The system account access token is meant for automations and
        integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system
        account and then obtaining a system account access token for that
        account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer spat_i2Ej...'`
```
