---
title: "A shared report, by the link token in a header"
method: GET
path: "/shared/report"
tags: ["Reports"]
---

# A shared report, by the link token in a header

`GET /shared/report`

The published snapshot a customer share link points at. The token travels in the X-Greentally-Share-Token header, never in the URL (Cloud Run's request log records URLs). A missing, malformed, unknown, expired or revoked token is the same 404. No /shared/ route takes the token in its path (spec 2026-10-05).

## Headers

- `X-Greentally-Share-Token` string, required

## Response `200`

Shared report detail

- ReportDetailResponse
  - `data` ReportDetail, required
    - `accessReason` 'owned_by_me' | 'shared_with_me' | 'organization_access'
    - `createdAt` string, date-time, required
    - `draftVersionId` string
    - `framework` 'ghg_protocol' | 'csrd_esrs' | 'management' | 'vsme', required — csrd_esrs is retired: existing reports stay readable, editable and exportable, and no new one can be created (400 FRAMEWORK_RETIRED). vsme reports are made only by the report engine.
    - `id` string, required
    - `latestPublishedAt` string, date-time
    - `latestPublishedVersionId` string
    - `periodEnd` string — Last day the current draft covers (inclusive), YYYY-MM-DD; absent on earlier reports. Only in the list, and only while REPORTS_V2_ENABLED is on.
    - `periodStart` string — First day the current draft covers, YYYY-MM-DD; absent on earlier reports. Only in the list, and only while REPORTS_V2_ENABLED is on.
    - `sourceOrganizationName` string
    - `status` string — draft, incomplete or published (the list's Status column). Only in the list, and only while REPORTS_V2_ENABLED is on.
    - `template` 'executive_carbon_summary' | 'dashboard_snapshot_report'
    - `templateId` string — The report engine's template (ghg, vsme or management); absent on earlier reports. Only in the list, and only while REPORTS_V2_ENABLED is on.
    - `title` string, required
    - `tone` 'conservative' | 'consultant' | 'executive_narrative'
    - `updatedAt` string, date-time, required
    - `draft` object
    - `evidencePack` object — Report evidence pack. reportContext.emissionsUnit ("tCO2e") is the unit of every emissions value in the pack (metric values, chart/table "emissions" fields); packs without it predate the unit fix and hold kgCO2e sums labelled tCO2e. reportContext.period uses month granularity: startDate is the first day of the first month and endDate the first day of the LAST INCLUDED month; startMonth/endMonth ("YYYY-MM", inclusive) and endDateInclusive ("YYYY-MM-DD", the last covered day) spell that out on packs generated after they were added. A report-evidence-pack/v2 pack (report engine) freezes every resolved datapoint in datapoints[]: id, label, type, requirement, applicable, status, value, unit, source, quality, reason, display, origin and citation, plus caveat, which qualifies a reported figure (for example "excludes 2 energy bills with no kWh recorded"); figures derived from it carry the same caveat, and its display already includes it. A datapoint may also carry proseDisplay (optional): the text that model-written prose substitutes for the datapoint's token ("24.0 tCO2e of Scope 1 emissions"), which names the figure's subject where display, shown next to its own label in tables, does not; it may leave the caveat out to fit the prose fact limit. Absent when prose uses display, and on packs generated before it was added. A v2 pack's reportContext.emissionBasis (absent: calculated) records what its totals counted: basis ("calculated" or "supplier_figures/v1"), supplierProvidedT, replacedEstimateT, their prior-period twins, figures[] (figureId, supplierId, period start/end inclusive, basis, figureT, estimateT, factor, appliedT, replacedT, status applied|not_applied) and, on an update, previousVersion (versionNumber, basis, figuresIncluded: whether that version's totals counted an applied figure, and figuresChanged: whether the applied figures differ, set only when both versions count figures).
    - `organizationName` string — Display name of the organization the report was prepared by, resolved when the report is read (organization name, else its account name, else its slug). Prefer it over evidencePack.reportContext.organizationName, which reports generated before it was recorded do not carry.
    - `recipientLabel` string — Set only on the shared-link view (GET /shared/report): the recipient label the link was created with, e.g. "Acme Hotels (verifier)". Absent when the link has none.
    - `reviewAvailable` boolean — Report review (spec 2026-10-06 §12): present, and true, only when REPORT_REVIEW_ENABLED is on, the version is the report engine's and the caller may edit the draft (report.edit_draft). Absent otherwise, so earlier responses are unchanged byte for byte.
    - `validation` object
    - `versionId` string
    - `versionStatus` 'draft' | 'published' | 'archived'

## Other responses

- `404` — Not Found

## Changes

- **2026-10-07** `5c524454c847` — 1 info
  - added the optional property `data/allOf[subschema #2]/reviewAvailable` to the response with the `200` status
- **2026-10-06** `461a0ebc7731` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/greentally/apis/esgai-api/changes/shared/report/get.md)

---

[API](https://skmtc.dev/greentally/apis/esgai-api.md) · [All operations](https://skmtc.dev/greentally/apis/esgai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/greentally/apis/esgai-api/revisions/5c524454c847?raw)
