> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List open cloud waste findings

> The organisation's open waste findings from the latest scan, with the credentials whose sweep failed so an incomplete scan never reads as zero waste. Bearer-PAT twin of the browser route of the same name under /org; the console's session cookie is not accepted here and the browser route answers a token with a login redirect.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/cloud-cost/waste
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: Pipeline definitions and the approval of the authority they declare.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/cloud-cost/waste:
    get:
      tags:
        - Cost
      summary: List open cloud waste findings
      description: >-
        The organisation's open waste findings from the latest scan, with the
        credentials whose sweep failed so an incomplete scan never reads as zero
        waste. Bearer-PAT twin of the browser route of the same name under /org;
        the console's session cookie is not accepted here and the browser route
        answers a token with a login redirect.
      operationId: cloud_waste_api_v1_org_cloud_cost_get
      parameters:
        - description: PAT organisation override.
          in: header
          name: x-ankra-organisation-id
          required: false
          schema:
            type: string
        - description: Narrow the findings to one cluster.
          in: query
          name: cluster_id
          required: false
          schema:
            type: string
            format: uuid
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CloudWasteResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: >-
            Missing or malformed Authorization header, or business validation
            error
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Unknown, expired, or revoked API token
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: >-
            Token may not use this surface (MCP-scoped token or service account
            restriction)
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Internal server error
      security:
        - BearerAuth: []
components:
  schemas:
    CloudWasteResponse:
      properties:
        credential_errors:
          items:
            $ref: '#/components/schemas/CloudWasteCredentialError'
          type: array
        currency:
          type: string
        findings:
          items:
            $ref: '#/components/schemas/CloudWasteFinding'
          type: array
        has_data:
          type: boolean
        scanned_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
        total_monthly_cost_cents:
          type: integer
        unpriced_finding_count:
          type: integer
        shared_not_counted_monthly_cost_cents:
          type: integer
          description: >-
            The priced monthly cost of the listed findings whose cost counts in
            another organisation or in none (counts_toward_savings false); it is
            not in total_monthly_cost_cents.
        shared_not_counted_finding_count:
          type: integer
          description: >-
            How many listed findings have counts_toward_savings false, priced or
            not; none of them is in unpriced_finding_count.
        consent:
          $ref: '#/components/schemas/CloudWasteConsentPolicy'
      required:
        - has_data
        - scanned_at
        - currency
        - total_monthly_cost_cents
        - unpriced_finding_count
        - shared_not_counted_monthly_cost_cents
        - shared_not_counted_finding_count
        - credential_errors
        - findings
        - consent
      title: CloudWasteResponse
      type: object
    ContractDetailError:
      example:
        detail: Cluster not found
      properties:
        detail:
          oneOf:
            - type: string
            - additionalProperties: true
              properties: {}
              type: object
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    CloudWasteCredentialError:
      properties:
        credential_name:
          type: string
        error:
          type: string
        provider:
          type: string
        scanned_at:
          type: string
          format: date-time
      required:
        - provider
        - credential_name
        - error
        - scanned_at
      title: CloudWasteCredentialError
      type: object
    CloudWasteFinding:
      properties:
        cluster_id:
          anyOf:
            - type: string
              format: uuid
            - type: 'null'
        cluster_name:
          anyOf:
            - type: string
            - type: 'null'
        credential_name:
          type: string
        details:
          type: object
        external_id:
          type: string
        first_seen_at:
          type: string
          format: date-time
        id:
          type: string
          format: uuid
        kind:
          type: string
        last_seen_at:
          type: string
          format: date-time
        monthly_cost_cents:
          anyOf:
            - type: integer
            - type: 'null'
        provider:
          type: string
        region:
          type: string
        resource_name:
          type: string
        origin_namespace:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            The namespace whose claim created the volume, from the claim
            reference of the PersistentVolume of the same name while the synced
            inventory still holds it; null is unknown, not no namespace.
        shared_with_org_count:
          type: integer
          description: >-
            How many other Ankra organisations see the same provider resource,
            because their credentials sweep the same provider project; 0 is a
            resource only this organisation sees. Every organisation that sees
            it lists it.
        counts_toward_savings:
          type: boolean
          description: >-
            Whether the finding's cost counts in this organisation's waste
            totals. A resource several organisations see counts only in the one
            its Ankra cluster label names, and in none when no label names one
            of their clusters. Any organisation that sees it may still clean it
            up.
      required:
        - id
        - provider
        - kind
        - external_id
        - resource_name
        - region
        - credential_name
        - cluster_id
        - cluster_name
        - details
        - monthly_cost_cents
        - first_seen_at
        - last_seen_at
        - origin_namespace
        - shared_with_org_count
        - counts_toward_savings
      title: CloudWasteFinding
      type: object
    CloudWasteConsentPolicy:
      description: >-
        The kinds this platform deletes only with written consent (no snapshot
        exists), and the minimum age a finding must have been seen before it may
        be deleted.
      properties:
        kinds:
          type: array
          items:
            type: string
        min_unattached_days:
          type: integer
      required:
        - kinds
        - min_unattached_days
      title: CloudWasteConsentPolicy
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````