# API to get all Waivers (Application & Repository)

**URL:** <https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976>\
**Category:** Sonatype Lifecycle & Firewall\
**Created:** [January 20, 2023, 1:18pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976 "2023-01-20T13:18:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![m588](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/m588/32/2010_2.png) [@m588](https://community.sonatype.com/u/m588)\
**Post date:** [January 20, 2023, 1:18pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/1 "2023-01-20T13:18:19Z")

</div>

Hi,

i have seen in the new Version the possibility, to show all waiver in the new dashboard and to export these waivers as CSV.

Our Security-Team want to load this data over an API with a nightly batch.  
Is there a API to get the same data as we get out of the export?

When not, can you create something like this in a future release?  
I think everything needed should be there 🙂

Greets,  
Marcus

---

<div class="post-metadata">

**Author:** ![jeff.wise](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jeff.wise/32/2421_2.png) [@jeff.wise](https://community.sonatype.com/u/jeff.wise)\
**Post date:** [January 20, 2023, 5:07pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/2 "2023-01-20T17:07:27Z")

</div>

I think you can get what you need with multiple API calls. See the GET for [Policy Waiver REST API - v2](https://help.sonatype.com/iqserver/automating/rest-apis/policy-waiver-rest-api---v2). You may need to make a call per ownerType.

---

<div class="post-metadata">

**Author:** ![m588](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/m588/32/2010_2.png) [@m588](https://community.sonatype.com/u/m588)\
**Post date:** [January 23, 2023, 10:18am UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/3 "2023-01-23T10:18:26Z")

</div>

Hi,

we have a 4-digit number of projects, which would make querying the waivers of each application very time consuming.  
Is there a hard link to the export that would be called from the UI?

---

<div class="post-metadata">

**Author:** ![jeff.wise](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jeff.wise/32/2421_2.png) [@jeff.wise](https://community.sonatype.com/u/jeff.wise)\
**Post date:** [January 23, 2023, 3:35pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/4 "2023-01-23T15:35:11Z")

</div>

You don’t have to query per application. The policy waiver rest API allows querying by organization, repository, and repository\_container as well.

---

<div class="post-metadata">

**Author:** ![m588](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/m588/32/2010_2.png) [@m588](https://community.sonatype.com/u/m588)\
**Post date:** [February 3, 2023, 12:30pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/5 "2023-02-03T12:30:44Z")

</div>

Perhaps i understand something not right, but the Waivers where made on Application Level. When i try to get the waivers from the API for an organization (ROOT or the specific organization where the appliaction lives) i dont get any entries. Only when i call the API for the specific application i get the entries. But this is not what i want to do. I will call the API once and get every Waiver who was made.

EDIT:  
i just started the IQ and saw that he prints out the REST APIs and found the following:

POST /rest/dashboard/export/policyWaivers (com.sonatype.insight.brain.dashboard.DashboardResource)

It seems that there is a API for my need. Is there more information for that API? I saw that it is also possible to set the filter over API.

Greets, Marcus

---

<div class="post-metadata">

**Author:** ![jeff.wise](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jeff.wise/32/2421_2.png) [@jeff.wise](https://community.sonatype.com/u/jeff.wise)\
**Post date:** [February 6, 2023, 4:15pm UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/6 "2023-02-06T16:15:55Z")

</div>

@m588,

I misunderstood and thought the organization level queries were recursive. They are not. You would need to make API calls for all of your applications – time consuming indeed for thousands of applications.

A Sonatyper will need to respond to your query about the policy waivers export API you mentioned as I don’t see any documentation for it.

---

<div class="post-metadata">

**Author:** ![m588](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/m588/32/2010_2.png) [@m588](https://community.sonatype.com/u/m588)\
**Post date:** [February 7, 2023, 11:47am UTC](https://community.sonatype.com/t/api-to-get-all-waivers-application-repository/9976/7 "2023-02-07T11:47:56Z")

</div>

I digging a bit deeper…

```auto
https://{HOST}/iq/rest/dashboard/export/policyWaivers

```

When i call this API and put the CSRF Token in header, i get the following reponse:

`"Entity is empty."`

Do i have to set some filter criterion first?
