Skip to content
These docs describe staging.zkao.io and the @zksecurity/zkao-cli@next release. For production, see docs.zkao.io.

Get a repository's guidance

GET
/projects/{projectId}/repositories/{repositoryId}/guidance
curl --request GET \
--url https://zkao.io/api/v1/projects/example/repositories/example/guidance \
--header 'Authorization: Bearer <token>'

Requires scope: read. Returns the per-repo guidance configured for this repository. Guidance is layered on top of any zkao.md committed in the repo at scan time; a per-scan guidance on launch replaces this layer for that one scan only.

projectId
required
string
repositoryId
required
string

OK

Media typeapplication/json
object
repositoryId
required
string
content
required

The configured guidance, or null when none is set.

string | null
updatedAt
required

When the guidance last changed. Null when the repo has no revision history (guidance never set, or set before revisions were tracked).

string | null format: date-time
Examplegenerated
{
"repositoryId": "example",
"content": "example",
"updatedAt": "2026-04-15T12:00:00Z"
}

Missing, malformed, expired, or revoked token

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

The token lacks the required scope

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

Resource not in this token’s project or repo allowlist

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}