> ## Documentation Index
> Fetch the complete documentation index at: https://docs.watchdoc.sphinxhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get flag settings

> Lists every published flag code and whether it is enabled for this workspace.



## OpenAPI

````yaml /api_schema.yaml get /api/v1/flag-settings/
openapi: 3.0.3
info:
  title: Sphinx Document Fraud API
  version: 1.0.0
  description: >
    Detect forged, tampered, and AI-generated documents. Upload a PDF or image
    and get back a

    structured verdict with a defined set of fraud flags.


    **Quick Start:**

    1. **Create an API key**: sign up, then generate a key from Settings.

    2. **Submit a document**: `POST /api/v1/document-checks/` with a file or a
    URL.
       You get back an id with status `"processing"`.
    3. **Poll for the result**: `GET /api/v1/document-checks/{id}/` until status
    is
       `"completed"` or `"failed"`.

    Optionally pass `webhook_url` on submit to be notified when analysis
    finishes, or

    `?wait=true` to block the submit request for up to 55s.


    **Authentication:** `Authorization: Bearer <api_key>`


    **Decisions:** Every completed check returns a decision (`clear`, `pending`,
    `suspicious`, or

    `fraudulent`), a `risk_level`, a plain-language summary, structured flags,
    and any

    workspace rules that triggered. The four-value decision set is the v1
    contract.
servers:
  - url: /
    description: This environment
security: []
tags:
  - name: Document Checks
    description: |-
      Submit a document for fraud analysis and retrieve structured results.

      **Allowed file types:** PDF, PNG, JPG.
  - name: Rules
    description: >-
      Workspace rules that guide the fraud engine, plus the score cut lines that
      set the `action` field on each check.
paths:
  /api/v1/flag-settings/:
    get:
      tags:
        - Rules
      summary: Get flag settings
      description: >-
        Lists every published flag code and whether it is enabled for this
        workspace.
      operationId: v1_flag_settings_retrieve
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FlagSettingsResponse'
          description: Current flag settings.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Missing or invalid API key.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: The key's workspace role lacks the required permission.
      security:
        - ApiKeyAuth: []
components:
  schemas:
    FlagSettingsResponse:
      type: object
      properties:
        object:
          type: string
        disabled_flag_codes:
          type: array
          items:
            type: string
        flags:
          type: array
          items:
            $ref: '#/components/schemas/FlagSettingsFlag'
      required:
        - disabled_flag_codes
        - flags
        - object
    Error:
      type: object
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
      required:
        - error
    FlagSettingsFlag:
      type: object
      properties:
        code:
          type: string
        title:
          type: string
        category:
          type: string
        severity:
          type: string
        description:
          type: string
        enabled:
          type: boolean
      required:
        - category
        - code
        - description
        - enabled
        - severity
        - title
    ErrorDetail:
      type: object
      properties:
        type:
          $ref: '#/components/schemas/ErrorTypeEnum'
        code:
          type: string
          description: Machine-readable cause, e.g. `unsupported_document`.
        message:
          type: string
          description: Human-readable explanation. Safe to log; do not parse.
      required:
        - code
        - message
        - type
    ErrorTypeEnum:
      enum:
        - invalid_request_error
        - authentication_error
        - insufficient_credits_error
        - permission_error
        - not_found_error
        - rate_limit_error
        - api_error
      type: string
      description: |-
        * `invalid_request_error` - invalid_request_error
        * `authentication_error` - authentication_error
        * `insufficient_credits_error` - insufficient_credits_error
        * `permission_error` - permission_error
        * `not_found_error` - not_found_error
        * `rate_limit_error` - rate_limit_error
        * `api_error` - api_error
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: >-
        Paste your workspace API key from Settings. Sent as Authorization:
        Bearer <key>.

````