> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# List compliance periods

> The audit windows this organization has opened, latest window first: the name, the framework, the range an export speaks for, whether the bundle has been exported and the hash it was stamped with. The evidence itself is not here; it stays in the source tables until an export freezes it. Needs the compliance feature.



## OpenAPI

````yaml /api-reference/openapi.json get /compliance_periods
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /compliance_periods:
    get:
      tags:
        - compliance_periods
      summary: List compliance periods
      description: >-
        The audit windows this organization has opened, latest window first: the
        name, the framework, the range an export speaks for, whether the bundle
        has been exported and the hash it was stamped with. The evidence itself
        is not here; it stays in the source tables until an export freezes it.
        Needs the compliance feature.
      operationId: list_compliance_periods
      parameters: []
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  data:
                    items:
                      $ref: '#/components/schemas/compliance_periods_row'
                    type: array
                  organization:
                    type: object
                  truncated:
                    type: boolean
                type: object
          description: The organization's rows.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    compliance_periods_row:
      properties:
        ends_on:
          type: string
        export_top_hash:
          type:
            - string
            - 'null'
        framework:
          enum:
            - iso27001_2022
            - soc2
            - cis_aws
            - nist_csf_2
          type: string
        id:
          type: string
        inserted_at:
          type: string
        name:
          type: string
        starts_on:
          type: string
        status:
          type: string
      required:
        - name
        - framework
        - starts_on
        - ends_on
        - export_top_hash
        - id
        - inserted_at
        - status
      type: object
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.