---
title: "Report Abuse"
method: POST
path: "/v1/teams/{team_id}/security/abuse"
tags: ["security"]
---

# Report Abuse

`POST /v1/teams/{team_id}/security/abuse`

Block whoever is talking to this workspace, and file what they asked for.

The target is the workspace's own people — resolved through
`account_block.resolve_targets`, which refuses a deployment owner and
refuses any shared identity (`Visitor` is in 405 workspaces; the owner is
in 429). So the worst a compromised desk can do here is block the one
customer already attacking it.

## Path parameters

- `team_id` string, uuid, required

## Headers

- `authorization` string, nullable
- `x-darwin-token` string, nullable

## Request body

- AbuseReport — What the desk saw. Free text on purpose — it is read by a person.
  - `detail` string, required
  - `kind` string
  - `block` boolean

## Response `200`

Successful Response

- object

## Other responses

- `422` — Validation Error

## Changes

> 33 revisions in range; 1 not diffed.

- **2026-09-23** `efbf913206ff` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/stormy/apis/stormy-control-plane/changes/v1/teams/:team_id/security/abuse/post.md)

---

[API](https://skmtc.dev/stormy/apis/stormy-control-plane.md) · [All operations](https://skmtc.dev/stormy/apis/stormy-control-plane/llms.txt) · [OpenAPI document](https://skmtc.dev/stormy/apis/stormy-control-plane/revisions/52151384d62a?raw)
