> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify the audit chain for an export job

> Replays the tamper-evident hash chain over the export job's date range and returns the verdict (`chain_valid`, `rows_checked`, first/last hash) alongside any integrity issues and the persisted daily merkle roots. This is the endpoint auditors hit to prove the exported rows match the chain anchored in WORM storage. Writes a `compliance.audit_export_verified` audit row. Owner/admin only. Responds 404 when the job id does not belong to the organization.



## OpenAPI

````yaml /openapi.yaml get /api/v1/compliance/audit-export/{jobId}/verify
openapi: 3.1.0
info:
  title: Devotel CPaaS API
  description: Orbit by Devotel — Communications Platform as a Service API
  version: 1.0.0
  contact:
    name: Devotel
    url: https://devotel.io
    email: support@devotel.io
  license:
    name: Proprietary
servers:
  - url: https://api.orbit.devotel.io
    description: Production
security:
  - Bearer: []
  - ApiKey: []
tags:
  - name: Messages
    description: >-
      Send and manage messages across all channels (SMS, WhatsApp, RCS, Email,
      Viber, etc.)
  - name: Fax
    description: >-
      List and track fax (MMS/T.38) transmissions on Telnyx-backed fax numbers
      (sending flows through the Messaging API)
  - name: Agents
    description: AI agent creation, configuration, and execution
  - name: Voice
    description: Voice calls, IVR, conferencing, and SIP trunking
  - name: OnCall
    description: On-call rotations and escalation policy planning for incident alerting
  - name: Webhooks
    description: Webhook endpoint management and delivery logs
  - name: Numbers
    description: Phone number search, provisioning, and configuration
  - name: Brand Identity
    description: >-
      Unified cross-channel brand trust posture (10DLC, toll-free, WhatsApp,
      RCS, branded calling, number KYC)
  - name: Contacts
    description: Contact management, segmentation, and lifecycle tracking
  - name: Campaigns
    description: Marketing campaign orchestration and analytics
  - name: Flows
    description: Automation flow builder and execution engine
  - name: Templates
    description: Message template management and approval workflows
  - name: Settings
    description: Organization, channel, and user preference settings
  - name: Verify
    description: OTP generation and verification across channels
  - name: Push
    description: Push notification delivery via FCM and APNs
  - name: Integrations
    description: Third-party service connections and OAuth management
  - name: CDP
    description: >-
      Customer Data Platform — activation surface (CRM object sync, streaming
      destinations, ad-audience activation)
  - name: Files
    description: >-
      Server-to-server media upload, listing, retrieval, and deletion
      (signed-URL backed)
  - name: Commerce
    description: >-
      Omnichannel conversational-commerce — persistent cart + checkout state
      machine, channel-agnostic hosted pay-by-link, native WhatsApp checkout,
      and AP2-style agent payment mandates.
  - name: Sync
    description: >-
      Real-time shared-state primitive (Twilio Sync parity) — Documents, Maps,
      Lists, and ephemeral Streams, with change events relayed over the
      /api/v1/ws/sync WebSocket gateway
  - name: Risk
    description: >-
      Unified cross-channel Trust & Fraud risk scoring — fuses SMS-pumping,
      URL-reputation, Verify Fraud Guard, and Voice Biometrics signals into one
      composite verdict queryable before a send or a call.
  - name: Orby
    description: >-
      In-dashboard Orby operator assistant: streamed assistant turns,
      conversation threads, product knowledge-base search, and the tool-action
      approval gate. Available to signed-in operators only (dashboard session
      auth — API-key requests are rejected).
paths:
  /api/v1/compliance/audit-export/{jobId}/verify:
    get:
      tags:
        - Compliance
      summary: Verify the audit chain for an export job
      description: >-
        Replays the tamper-evident hash chain over the export job's date range
        and returns the verdict (`chain_valid`, `rows_checked`, first/last hash)
        alongside any integrity issues and the persisted daily merkle roots.
        This is the endpoint auditors hit to prove the exported rows match the
        chain anchored in WORM storage. Writes a
        `compliance.audit_export_verified` audit row. Owner/admin only. Responds
        404 when the job id does not belong to the organization.
      parameters:
        - schema:
            type: string
          in: path
          name: jobId
          required: true
          description: The audit export job id whose range should be verified.
      responses:
        '200':
          description: The chain verification verdict plus daily merkle roots.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      organization_id:
                        type: string
                      from:
                        type: string
                        format: date-time
                      to:
                        type: string
                        format: date-time
                      rows_checked:
                        type: integer
                      chain_valid:
                        type: boolean
                      issues:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                            created_at:
                              type: string
                            reason:
                              type: string
                              enum:
                                - missing_current_hash
                                - prev_hash_mismatch
                                - current_hash_mismatch
                            expected:
                              type: string
                            actual:
                              type: string
                      first_hash:
                        type: string
                        nullable: true
                      last_hash:
                        type: string
                        nullable: true
                      daily_roots:
                        type: array
                        items:
                          type: object
                          properties:
                            day_utc:
                              type: string
                            merkle_root:
                              type: string
                            row_count:
                              type: integer
                            min_id:
                              type: string
                              nullable: true
                            max_id:
                              type: string
                              nullable: true
                            anchor_url:
                              type: string
                              nullable: true
                            created_at:
                              type: string
                  meta:
                    type: object
                    properties:
                      request_id:
                        type: string
                      timestamp:
                        type: string
                        format: date-time
              example:
                data:
                  organization_id: org_123
                  from: '2026-07-01T00:00:00.000Z'
                  to: '2026-07-31T23:59:59.999Z'
                  rows_checked: 40213
                  chain_valid: true
                  issues: []
                  first_hash: 9f2c...a10b
                  last_hash: 4d81...c3ee
                  daily_roots:
                    - day_utc: '2026-07-01'
                      merkle_root: 7a1e...f099
                      row_count: 1320
                      min_id: aud_01a
                      max_id: aud_01z
                      anchor_url: >-
                        https://storage.googleapis.com/orbit-audit/anchors/org_123/2026-07-01.json
                      created_at: '2026-07-02T00:05:00.000Z'
                meta:
                  request_id: req_9s8d7f6g5h4j
                  timestamp: '2026-08-03T12:34:56.000Z'
components:
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Dashboard JWT token from Clerk
    ApiKey:
      type: apiKey
      name: X-API-Key
      in: header
      description: Server-to-server API key (dv_live_sk_*)

````