Generating reports

Trigger org-wide reports via the API: audit/due diligence reports and global issue CSV exports.

3 min readUpdated Sep 22, 2026

Enterprise feature

Available on: Business, Enterprise.

Overview

These recipes show how to trigger the global org-wide reports available from the Reports dashboard. For project-level attribution reports, see Downloading attribution reports.

Note

  • A FOSSA API token with Full access. See Authentication.
  • Organization Report or Team Report create permission.

Generating an audit / due diligence report

The audit report provides an org-wide summary of issues and project changes. It is generated as a background job and delivered by email.

Shell
curl 'https://app.fossa.com/api/organization/summary' \  -H 'Authorization: Bearer YOUR_API_KEY'

The response includes a jobToken you can use to poll the job status. When the job completes, the report is emailed to the requesting user's address.

Scope to a team

Pass teamId to limit the report to projects belonging to a specific team:

Shell
curl -G 'https://app.fossa.com/api/organization/summary' \  -d 'teamId=42' \  -H 'Authorization: Bearer YOUR_API_KEY'

Generating a global issue CSV export

GET /api/v2/issues/csv/global exports your organization's active issues as a ZIP file with a separate CSV for licensing, security, and quality issues. The security and quality CSVs are included only when those products are enabled for your organization. For every file the ZIP can contain, see Global Issue CSV Export.

Download immediately

Shell
curl -G 'https://app.fossa.com/api/v2/issues/csv/global' \  -H 'Authorization: Bearer YOUR_API_KEY' \  --output fossa-issues.zip

Email the report

For large organizations, request email delivery instead:

Shell
curl -G 'https://app.fossa.com/api/v2/issues/csv/global' \  -d 'email=true' \  -H 'Authorization: Bearer YOUR_API_KEY'

The response includes a jobToken that resolves when the report has been sent.

Scope to a team

Shell
curl -G 'https://app.fossa.com/api/v2/issues/csv/global' \  -d 'teamIds[]=42' \  -H 'Authorization: Bearer YOUR_API_KEY' \  --output fossa-issues-team42.zip

Scope to a release group

Pass releaseGroupId to export a single release group's latest release. teamIds is ignored when releaseGroupId is set, and you need view access to the release group.

Shell
curl -G 'https://app.fossa.com/api/v2/issues/csv/global' \  -d 'releaseGroupId=17' \  -H 'Authorization: Bearer YOUR_API_KEY' \  --output fossa-issues-release-group17.zip

Include issue counts

Two parameters choose which files the ZIP contains:

ParameterDefaultEffect
includeIssuesListtrueInclude the per-category issue CSVs
includeDailyCountsfalseInclude a counts CSV: issue_counts.csv (issue counts over the last 30 days), or release_counts.csv (changes across the 10 most recent releases) when releaseGroupId is set

Setting includeIssuesList=false without includeDailyCounts=true selects no files and returns a 400. Issue counts require access to the Global Issue Summary; without it the request returns a 403.

This example exports only the issue counts for one team:

Shell
curl -G 'https://app.fossa.com/api/v2/issues/csv/global' \  -d 'teamIds[]=42' \  -d 'includeIssuesList=false' \  -d 'includeDailyCounts=true' \  -H 'Authorization: Bearer YOUR_API_KEY' \  --output fossa-issue-counts-team42.zip

Polling job status

Both the audit report and the emailed CSV export return a job token. Poll the token to track completion:

Shell
curl -G 'https://app.fossa.com/api/jobs/status' \  -d 'jobs[]=YOUR_JOB_TOKEN' \  -H 'Authorization: Bearer YOUR_API_KEY'

The response nests each token under jobs:

JSON
{ "jobs": { "YOUR_JOB_TOKEN": { "status": "finished" } } }

A status of finished means the report has been sent. The other values are running, created, and failed; on failed, retry or contact support.

© 2026 FOSSA, Inc.support@fossa.com