> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List anomaly feed

> Paginated, filterable feed of detected anomalies ordered by severity then cost impact, with active and new-since-yesterday aggregates. resource_id scopes the feed and its aggregates to anomalies whose resource matches a given id exactly or by its provider resource key (the trailing id segment, case-insensitive), so aws:///us-east-1d/i-0abc and i-0abc match each other. filter scopes the feed and its aggregates to a cost box: an anomaly is in the box when its resource had cost in the last 31 days matching every filter, or, when every filter is on provider, region, service or resource, when its own provider (required, case-insensitive), region and service (case-insensitive, matched when set) and resource match. A not: filter on those dimensions inverts the value test and keeps the same blank handling.



## OpenAPI

````yaml /api-reference/costgraph/openapi.json get /api/v1/tenant/anomalies
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/tenant/anomalies:
    get:
      tags:
        - anomalies
      summary: List anomaly feed
      description: >-
        Paginated, filterable feed of detected anomalies ordered by severity
        then cost impact, with active and new-since-yesterday aggregates.
        resource_id scopes the feed and its aggregates to anomalies whose
        resource matches a given id exactly or by its provider resource key (the
        trailing id segment, case-insensitive), so aws:///us-east-1d/i-0abc and
        i-0abc match each other. filter scopes the feed and its aggregates to a
        cost box: an anomaly is in the box when its resource had cost in the
        last 31 days matching every filter, or, when every filter is on
        provider, region, service or resource, when its own provider (required,
        case-insensitive), region and service (case-insensitive, matched when
        set) and resource match. A not: filter on those dimensions inverts the
        value test and keeps the same blank handling.
      parameters:
        - description: Filter by status
          name: status
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Filter by severity
          name: severity
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Filter by category
          name: category
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Filter by anomaly type
          name: anomaly_type
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Filter by resource type
          name: resource_type
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Filter by provider
          name: provider
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: >-
            Filter by resource id (up to 50, non-empty); equivalent to
            filter=resource:<id>
          name: resource_id
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: >-
            Repeated key:value cost box filter, in the same syntax as the cost
            query's filter, repeat a key to match any of its values, e.g.
            filter=provider:aws&filter=region:us-east-2. Keys are the cost query
            dimensions: provider, resource_type, service_category,
            service_subcategory, service, region, availability_zone, resource,
            sku_id, sku_meter, charge_category, charge_description,
            pricing_category, pricing_unit, usage_unit, billing_account_id,
            sub_account, sub_account_type, invoice_id, invoice_issuer,
            publisher, plus filter=tag:<key>:<value> and
            filter=extension:<key>:<value>, with the has:, no: and not:
            prefixes, e.g. filter=no:region or filter=not:provider:aws. A
            filter_<dimension>=<value> query parameter is equivalent
          name: filter
          in: query
          style: form
          explode: false
          schema:
            type: array
            items:
              type: string
        - description: Full-text search across title, description, resource, and service
          name: search
          in: query
          schema:
            type: string
        - description: Page size
          name: limit
          in: query
          schema:
            type: integer
        - description: Page offset
          name: offset
          in: query
          schema:
            type: integer
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/responses.SuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/anomalies.ListView'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    responses.SuccessResponse:
      type: object
      required:
        - message
        - status
      properties:
        data: {}
        message:
          type: string
          example: some message
        status:
          type: string
          example: success
    anomalies.ListView:
      type: object
      required:
        - active_count
        - items
        - new_since_yesterday
        - total
      properties:
        active_count:
          type: integer
        items:
          type: array
          items:
            $ref: '#/components/schemas/anomalies.AnomalyView'
        new_since_yesterday:
          type: integer
        total:
          type: integer
    responses.ErrorResponse:
      type: object
      required:
        - message
        - status
      properties:
        message:
          type: string
          example: some message
        status:
          type: string
          example: error
    anomalies.AnomalyView:
      type: object
      properties:
        activated_at:
          description: >-
            When the anomaly last became active: set on insert and again
            whenever a

            resolved anomaly reopens. NULL for anomalies already active before
            activation

            tracking existed, which never alert.
          type: string
        anomaly_type:
          description: >-
            Detector type: overprovisioned_compute, vm_overprovisioned,

            unstable_workload, pvc_overprovisioned, pv_overprovisioned,

            new_costly_resource, cost_drop, crashloop, unattached_pv,
            oom_recurring,

            forecast_breach.
          type: string
        availability_zone:
          type: string
        category:
          type: string
        confidence:
          type: string
        contributors:
          type: array
          items:
            $ref: '#/components/schemas/anomalies.AnomalyContributor'
          nullable: true
        cost_impact_annual:
          type: number
          nullable: true
        cost_impact_basis:
          description: >-
            How to read cost_impact_monthly: savings | excess | new | drop |
            forecast |

            empty.
          type: string
        cost_impact_monthly:
          type: number
          nullable: true
        created_at:
          type: string
        description:
          type: string
        detector:
          type: string
        detector_version:
          type: string
        evidence:
          allOf:
            - $ref: '#/components/schemas/anomalies.AnomalyEvidence'
          nullable: true
        fingerprint:
          description: >-
            Stable dedup key (type:resource_type:hash:line_item_type); persists
            across

            runs; not strictly unique (active+resolved can share).
          type: string
        id:
          type: string
        labels:
          type: object
          nullable: true
        line_item_type:
          type: string
        magnitude:
          type: number
          nullable: true
        magnitude_bar:
          allOf:
            - $ref: '#/components/schemas/anomalies.MagnitudeBar'
          nullable: true
        magnitude_unit:
          type: string
        miss_count:
          type: number
        name:
          type: string
        num_recurring_events:
          type: number
        prompt_context:
          allOf:
            - $ref: '#/components/schemas/anomalies.AnomalyPromptContext'
          nullable: true
        provider:
          type: string
        region:
          type: string
        resolved_at:
          type: string
          nullable: true
        resource_id:
          type: string
        resource_name:
          type: string
        resource_type:
          type: string
        service:
          type: string
        severity:
          type: string
        status:
          description: active | resolved (resolved_at set only when resolved).
          type: string
        tenant_id:
          type: string
        title:
          type: string
        updated_at:
          type: string
    anomalies.AnomalyContributor:
      type: object
      required:
        - cost_monthly
        - dimension
        - share_pct
      properties:
        cost_monthly:
          type: number
        dimension:
          type: string
        share_pct:
          type: number
    anomalies.AnomalyEvidence:
      type: object
      properties:
        baseline_p50:
          type: number
          nullable: true
        baseline_p95:
          type: number
          nullable: true
        source:
          type: object
          additionalProperties: {}
          nullable: true
        stateful:
          type: boolean
        value:
          type: number
          nullable: true
        version:
          type: integer
        window_end:
          type: string
          nullable: true
        window_start:
          type: string
          nullable: true
    anomalies.MagnitudeBar:
      type: object
      required:
        - baseline_pct
        - unit
        - value
      properties:
        baseline:
          type: number
          nullable: true
        baseline_pct:
          type: number
        unit:
          type: string
        value:
          type: number
    anomalies.AnomalyPromptContext:
      type: object
      properties:
        explanation:
          type: string
        metadata:
          type: object
          additionalProperties: {}
          nullable: true
        observations:
          type: array
          items:
            $ref: '#/components/schemas/anomalies.AnomalyObservation'
          nullable: true
        resource:
          type: object
          additionalProperties:
            type: string
          nullable: true
        suggested_questions:
          type: array
          items:
            type: string
          nullable: true
        summary:
          type: string
        version:
          type: integer
    anomalies.AnomalyObservation:
      type: object
      required:
        - severity
        - text
      properties:
        severity:
          type: string
        text:
          type: string
  securitySchemes:
    BearerAuth:
      description: Enter "Bearer {token}"
      type: apiKey
      name: Authorization
      in: header

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.