> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# File an adverse report

> File a typed, severity-graded adverse report (illness / injury / allergic reaction / foreign object / spoilage / packaging defect) for the brand behind a scanned product. Requires an authenticated (social-auth) consumer. Returns a receipt carrying an immutable ``reference_id``, the delivery record, and a prefilled handoff to the appropriate regulator — Closient files with nobody on your behalf, and never gives medical advice.

Rate-limited per identity and per IP (same tight feedback caps as signals). A banned identity is rejected with ``403``; an oversized body returns ``422``.



## OpenAPI

````yaml /openapi/openapi-signals.json post /signals/api/v1/adverse-reports/
openapi: 3.1.0
info:
  title: Signals API
  version: 1.0.0
  description: >
    Private product feedback signals — consumer submission/retrieval and the
    brand inbox. A one-way pipe: capture and disclose, never relay. No content
    analysis, no hosted visual media.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Signals
    description: Consumer-facing signal submission, retrieval, edit, and revoke.
  - name: Brand Signals
    description: Brand inbox — list and detail of signals on owned-and-claimed products.
  - name: Signal Review
    description: >-
      Internal-review (staff-only) abuse queue and suppress/ban actions
      (C-3316).
  - name: Adverse Reports
    description: >-
      Typed consumer harm reporting (C-3908) — consumer filing with a reference
      receipt and prefilled regulator handoff, plus the brand inbox and
      lot-level early-warning alerts.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /signals/api/v1/adverse-reports/:
    post:
      tags:
        - Adverse Reports
      summary: File an adverse report
      description: >-
        File a typed, severity-graded adverse report (illness / injury /
        allergic reaction / foreign object / spoilage / packaging defect) for
        the brand behind a scanned product. Requires an authenticated
        (social-auth) consumer. Returns a receipt carrying an immutable
        ``reference_id``, the delivery record, and a prefilled handoff to the
        appropriate regulator — Closient files with nobody on your behalf, and
        never gives medical advice.


        Rate-limited per identity and per IP (same tight feedback caps as
        signals). A banned identity is rejected with ``403``; an oversized body
        returns ``422``.
      operationId: apps_signals_api_adverse_file_adverse_report_endpoint
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AdverseReportCreate'
        required: true
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdverseReportReceiptOut'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - SessionAuth: []
components:
  schemas:
    AdverseReportCreate:
      description: Payload to file a new adverse report (consumer-facing).
      examples:
        - batch: LOT-2026-04
          body: Two of us were unwell a few hours after eating this.
          contact_consent: true
          contact_email: shopper@example.com
          gtin: '00012345678905'
          report_type: illness
          severity: moderate
      properties:
        gtin:
          description: >-
            GTIN of the product the report is about, from the resolution
            context.
          title: Gtin
          type: string
        report_type:
          $ref: '#/components/schemas/AdverseReportTypeEnum'
          description: >-
            Typed harm category (illness / injury / allergic_reaction /
            foreign_object / spoilage / packaging_defect).
        severity:
          anyOf:
            - $ref: '#/components/schemas/AdverseReportSeverityEnum'
            - type: 'null'
          description: >-
            Optional consumer-declared severity (``minor`` / ``moderate`` /
            ``serious`` / ``life_threatening``). Omit or null if the consumer
            declined — Closient never infers it.
        body:
          default: ''
          description: >-
            Freeform description of what happened. May be empty for a voice-only
            report.
          title: Body
          type: string
        batch:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Batch/lot identifier (GS1 AI 10) from the scan. The lot is the
            correlation unit for alerts.
          title: Batch
        voice_session_id:
          anyOf:
            - description: >-
                URL-safe 22-character shortuuid encoding of the row's UUID
                primary key. Stable across the row's lifetime; suitable for
                sharing in URLs, log lines, and external SDK clients. Accepted
                on input as either the shortuuid form or the canonical UUID form
                (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
              format: shortuuid
              maxLength: 22
              minLength: 22
              pattern: >-
                ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
              type: string
            - type: 'null'
          description: >-
            Optional public id of a voice capture session backing this report
            (must be the consumer's own).
          title: Voice Session Id
        contact_consent:
          default: false
          description: Explicit opt-in to be contacted by the brand about this report.
          title: Contact Consent
          type: boolean
        contact_email:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Contact address the consumer agrees to be reached at. Must be one of
            their own verified account email addresses. Only meaningful when
            ``contact_consent`` is true.
          title: Contact Email
      required:
        - gtin
        - report_type
      title: AdverseReportCreate
      type: object
    AdverseReportReceiptOut:
      description: >-
        A filed adverse report as the *reporter* sees it — the receipt.


        Carries the immutable reference id, the report's typed fields, the
        delivery

        record, and the prefilled regulator handoff (Closient never files on the

        consumer's behalf — the handoff is how they complete the real report).
      examples:
        - batch: LOT-2026-04
          body: Two of us were unwell a few hours after eating this.
          contact_consent: true
          created: '2026-07-14T14:30:00Z'
          delivery:
            delivered_at: '2026-07-14T14:30:00Z'
            sla_deadline: '2026-07-15T14:30:00Z'
            state: delivered
            within_sla: true
          gtin: '00012345678905'
          has_voice: false
          id: a1b2c3d4e5f6
          reference_id: AR-7F3K9Q2M
          regulator_handoff:
            agency: fda_srp
            agency_name: U.S. Food and Drug Administration
            guidance: Report a food problem to the FDA.
            prefill:
              batch_lot: LOT-2026-04
              closient_reference: AR-7F3K9Q2M
              gtin: '00012345678905'
              product_name: Acme Bagged Salad
            program: Safety Reporting Portal
            url: https://www.safetyreporting.hhs.gov
          report_type: illness
          severity: moderate
          status: active
      properties:
        reference_id:
          description: Immutable, human-facing reference the reporter quotes to track it.
          title: Reference Id
          type: string
        id:
          description: Public short-UUID identifier of the adverse report.
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        gtin:
          description: GTIN-14 of the product this report is about.
          title: Gtin
          type: string
        batch:
          anyOf:
            - type: string
            - type: 'null'
          description: Batch/lot identifier (GS1 AI 10) from the scan, or null.
          title: Batch
        serial:
          anyOf:
            - type: string
            - type: 'null'
          description: Serialized-unit context from the scan, or null.
          title: Serial
        report_type:
          $ref: '#/components/schemas/AdverseReportTypeEnum'
          description: Typed harm category code.
        severity:
          anyOf:
            - $ref: '#/components/schemas/AdverseReportSeverityEnum'
            - type: 'null'
          description: >-
            Consumer-declared severity code, or null if not graded. Never
            inferred by Closient.
        body:
          description: >-
            Freeform description the consumer wrote (may be empty for
            voice-only).
          title: Body
          type: string
        status:
          description: 'Underlying signal lifecycle code: ``active`` or ``revoked``.'
          title: Status
          type: string
        has_voice:
          description: True when a voice capture session backs this report.
          title: Has Voice
          type: boolean
        contact_consent:
          description: Whether the consumer opted in to be contacted by the brand.
          title: Contact Consent
          type: boolean
        created:
          description: ISO-8601 timestamp the report was filed.
          format: date-time
          title: Created
          type: string
        delivery:
          $ref: '#/components/schemas/DeliveryOut'
          description: The immutable delivery record for this report.
        regulator_handoff:
          $ref: '#/components/schemas/RegulatorHandoffOut'
          description: >-
            Prefilled handoff to the appropriate regulator — the consumer
            completes the filing.
      required:
        - reference_id
        - id
        - gtin
        - report_type
        - body
        - status
        - has_voice
        - contact_consent
        - created
        - delivery
        - regulator_handoff
      title: AdverseReportReceiptOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    AdverseReportTypeEnum:
      description: >-
        Typed harm category. Mirrors
        :class:`apps.signals.models.AdverseReportType`.
      enum:
        - illness
        - injury
        - allergic_reaction
        - foreign_object
        - spoilage
        - packaging_defect
      title: AdverseReportTypeEnum
      type: string
    AdverseReportSeverityEnum:
      description: >-
        Consumer-declared severity grade. Mirrors
        :class:`apps.signals.models.AdverseReportSeverity`.
      enum:
        - minor
        - moderate
        - serious
        - life_threatening
      title: AdverseReportSeverityEnum
      type: string
    DeliveryOut:
      description: The immutable delivery record attesting how/when the report was routed.
      examples:
        - delivered_at: '2026-07-14T14:30:00Z'
          sla_deadline: '2026-07-15T14:30:00Z'
          state: delivered
          within_sla: true
      properties:
        state:
          $ref: '#/components/schemas/AdverseDeliveryStateEnum'
          description: >-
            Routing outcome recorded at file time: ``delivered`` / ``held`` /
            ``unroutable``.
        sla_deadline:
          description: >-
            Hard SLA deadline by which Closient committed to route the report to
            the brand.
          format: date-time
          title: Sla Deadline
          type: string
        delivered_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          description: >-
            When the report reached an accountable organization, or null while
            held/unroutable.
          title: Delivered At
        within_sla:
          description: >-
            True when delivery met the SLA (or is still inside the window while
            pending).
          title: Within Sla
          type: boolean
      required:
        - state
        - sla_deadline
        - within_sla
      title: DeliveryOut
      type: object
    RegulatorHandoffOut:
      description: >-
        A prefilled handoff to the appropriate regulator (Closient files with
        nobody).
      examples:
        - agency: fda_srp
          agency_name: U.S. Food and Drug Administration
          guidance: Report a food, dietary-supplement or cosmetic problem to the FDA.
          prefill:
            batch_lot: LOT-2026-04
            closient_reference: AR-7F3K9Q2M
            gtin: '00012345678905'
            product_name: Acme Bagged Salad
          program: Safety Reporting Portal
          url: https://www.safetyreporting.hhs.gov
      properties:
        agency:
          description: >-
            Stable regulator code (e.g. ``fda_srp``, ``fda_medwatch``,
            ``cpsc``).
          title: Agency
          type: string
        agency_name:
          description: Human-readable regulator name (display label).
          title: Agency Name
          type: string
        program:
          description: The specific reporting program within the regulator.
          title: Program
          type: string
        url:
          description: Public consumer reporting entry-point URL for the program.
          title: Url
          type: string
        guidance:
          description: >-
            Honest, non-prescriptive guidance on the program and its clock.
            Never medical advice.
          title: Guidance
          type: string
        prefill:
          $ref: '#/components/schemas/RegulatorPrefillOut'
          description: Product/lot facts pre-assembled for the consumer's filing.
      required:
        - agency
        - agency_name
        - program
        - url
        - guidance
        - prefill
      title: RegulatorHandoffOut
      type: object
    AdverseDeliveryStateEnum:
      description: >-
        Immutable delivery outcome. Mirrors
        :class:`apps.signals.models.AdverseDeliveryState`.
      enum:
        - delivered
        - held
        - unroutable
      title: AdverseDeliveryStateEnum
      type: string
    RegulatorPrefillOut:
      description: >-
        The product/lot facts pre-assembled for the consumer's own regulator
        filing.
      examples:
        - batch_lot: LOT-2026-04
          closient_reference: AR-7F3K9Q2M
          gtin: '00012345678905'
          product_name: Acme Bagged Salad
      properties:
        product_name:
          description: Product name (falls back to the GTIN when unnamed).
          title: Product Name
          type: string
        gtin:
          description: GTIN-14 of the product.
          title: Gtin
          type: string
        batch_lot:
          description: Batch/lot identifier (GS1 AI 10), or empty string when none.
          title: Batch Lot
          type: string
        closient_reference:
          description: The Closient adverse-report reference id, for cross-linking.
          title: Closient Reference
          type: string
      required:
        - product_name
        - gtin
        - batch_lot
        - closient_reference
      title: RegulatorPrefillOut
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    SessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````