curl --request POST \
--url https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"envelope_version": "entity_state_envelope_v1",
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 2,
"generated_at": "2023-11-07T05:31:56Z",
"subject": {
"subject_id": "<string>"
},
"attributes": {},
"evidence": [
{
"evidence_id": "<string>",
"evidence_type": "<string>",
"source": "<string>",
"captured_at": "2023-11-07T05:31:56Z",
"retrieved_at": "2023-11-07T05:31:56Z",
"locator": "<string>",
"notes": "<string>"
}
],
"audit": {
"created_by": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"source": "<string>",
"request_id": "<string>",
"correlation_id": "<string>"
},
"attribute_paths": {}
}
'import requests
url = "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states"
payload = {
"envelope_version": "entity_state_envelope_v1",
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 2,
"generated_at": "2023-11-07T05:31:56Z",
"subject": { "subject_id": "<string>" },
"attributes": {},
"evidence": [
{
"evidence_id": "<string>",
"evidence_type": "<string>",
"source": "<string>",
"captured_at": "2023-11-07T05:31:56Z",
"retrieved_at": "2023-11-07T05:31:56Z",
"locator": "<string>",
"notes": "<string>"
}
],
"audit": {
"created_by": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"source": "<string>",
"request_id": "<string>",
"correlation_id": "<string>"
},
"attribute_paths": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
envelope_version: 'entity_state_envelope_v1',
snapshot_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
snapshot_version: 2,
generated_at: '2023-11-07T05:31:56Z',
subject: {subject_id: '<string>'},
attributes: {},
evidence: [
{
evidence_id: '<string>',
evidence_type: '<string>',
source: '<string>',
captured_at: '2023-11-07T05:31:56Z',
retrieved_at: '2023-11-07T05:31:56Z',
locator: '<string>',
notes: '<string>'
}
],
audit: {
created_by: '<string>',
created_at: '2023-11-07T05:31:56Z',
source: '<string>',
request_id: '<string>',
correlation_id: '<string>'
},
attribute_paths: {}
})
};
fetch('https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'envelope_version' => 'entity_state_envelope_v1',
'snapshot_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'snapshot_version' => 2,
'generated_at' => '2023-11-07T05:31:56Z',
'subject' => [
'subject_id' => '<string>'
],
'attributes' => [
],
'evidence' => [
[
'evidence_id' => '<string>',
'evidence_type' => '<string>',
'source' => '<string>',
'captured_at' => '2023-11-07T05:31:56Z',
'retrieved_at' => '2023-11-07T05:31:56Z',
'locator' => '<string>',
'notes' => '<string>'
]
],
'audit' => [
'created_by' => '<string>',
'created_at' => '2023-11-07T05:31:56Z',
'source' => '<string>',
'request_id' => '<string>',
'correlation_id' => '<string>'
],
'attribute_paths' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states"
payload := strings.NewReader("{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}"
response = http.request(request)
puts response.read_body{
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 123,
"envelope_hash": "<string>"
}{
"error": {
"code": "validation_error",
"message": "Request body failed schema validation.",
"details": [
{
"path": "/subject_id",
"message": "subject_id is required."
}
]
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication required."
}
}{
"error": {
"code": "forbidden",
"message": "Owner or grant required."
}
}{
"error": {
"code": "validation_error",
"message": "Request body failed schema validation.",
"details": [
{
"path": "/subject_id",
"message": "subject_id is required.",
"code": "invalid_type"
}
],
"request_id": "req_01j2k3m4n5"
}
}Create Initial State
Creates the first versioned snapshot for a subject. The submitting tenant
automatically becomes the subject’s owner. Requires tenant_editor role.
The subject must not have an existing snapshot — use entity-state-updates
for subsequent versions.
curl --request POST \
--url https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"envelope_version": "entity_state_envelope_v1",
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 2,
"generated_at": "2023-11-07T05:31:56Z",
"subject": {
"subject_id": "<string>"
},
"attributes": {},
"evidence": [
{
"evidence_id": "<string>",
"evidence_type": "<string>",
"source": "<string>",
"captured_at": "2023-11-07T05:31:56Z",
"retrieved_at": "2023-11-07T05:31:56Z",
"locator": "<string>",
"notes": "<string>"
}
],
"audit": {
"created_by": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"source": "<string>",
"request_id": "<string>",
"correlation_id": "<string>"
},
"attribute_paths": {}
}
'import requests
url = "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states"
payload = {
"envelope_version": "entity_state_envelope_v1",
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 2,
"generated_at": "2023-11-07T05:31:56Z",
"subject": { "subject_id": "<string>" },
"attributes": {},
"evidence": [
{
"evidence_id": "<string>",
"evidence_type": "<string>",
"source": "<string>",
"captured_at": "2023-11-07T05:31:56Z",
"retrieved_at": "2023-11-07T05:31:56Z",
"locator": "<string>",
"notes": "<string>"
}
],
"audit": {
"created_by": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"source": "<string>",
"request_id": "<string>",
"correlation_id": "<string>"
},
"attribute_paths": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
envelope_version: 'entity_state_envelope_v1',
snapshot_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
snapshot_version: 2,
generated_at: '2023-11-07T05:31:56Z',
subject: {subject_id: '<string>'},
attributes: {},
evidence: [
{
evidence_id: '<string>',
evidence_type: '<string>',
source: '<string>',
captured_at: '2023-11-07T05:31:56Z',
retrieved_at: '2023-11-07T05:31:56Z',
locator: '<string>',
notes: '<string>'
}
],
audit: {
created_by: '<string>',
created_at: '2023-11-07T05:31:56Z',
source: '<string>',
request_id: '<string>',
correlation_id: '<string>'
},
attribute_paths: {}
})
};
fetch('https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'envelope_version' => 'entity_state_envelope_v1',
'snapshot_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'snapshot_version' => 2,
'generated_at' => '2023-11-07T05:31:56Z',
'subject' => [
'subject_id' => '<string>'
],
'attributes' => [
],
'evidence' => [
[
'evidence_id' => '<string>',
'evidence_type' => '<string>',
'source' => '<string>',
'captured_at' => '2023-11-07T05:31:56Z',
'retrieved_at' => '2023-11-07T05:31:56Z',
'locator' => '<string>',
'notes' => '<string>'
]
],
'audit' => [
'created_by' => '<string>',
'created_at' => '2023-11-07T05:31:56Z',
'source' => '<string>',
'request_id' => '<string>',
'correlation_id' => '<string>'
],
'attribute_paths' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states"
payload := strings.NewReader("{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://tally-platform-api-xwka6vu2kq-ue.a.run.app/v1/tenants/{tenant_id}/entity-states")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"envelope_version\": \"entity_state_envelope_v1\",\n \"snapshot_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"snapshot_version\": 2,\n \"generated_at\": \"2023-11-07T05:31:56Z\",\n \"subject\": {\n \"subject_id\": \"<string>\"\n },\n \"attributes\": {},\n \"evidence\": [\n {\n \"evidence_id\": \"<string>\",\n \"evidence_type\": \"<string>\",\n \"source\": \"<string>\",\n \"captured_at\": \"2023-11-07T05:31:56Z\",\n \"retrieved_at\": \"2023-11-07T05:31:56Z\",\n \"locator\": \"<string>\",\n \"notes\": \"<string>\"\n }\n ],\n \"audit\": {\n \"created_by\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"source\": \"<string>\",\n \"request_id\": \"<string>\",\n \"correlation_id\": \"<string>\"\n },\n \"attribute_paths\": {}\n}"
response = http.request(request)
puts response.read_body{
"snapshot_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"snapshot_version": 123,
"envelope_hash": "<string>"
}{
"error": {
"code": "validation_error",
"message": "Request body failed schema validation.",
"details": [
{
"path": "/subject_id",
"message": "subject_id is required."
}
]
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication required."
}
}{
"error": {
"code": "forbidden",
"message": "Owner or grant required."
}
}{
"error": {
"code": "validation_error",
"message": "Request body failed schema validation.",
"details": [
{
"path": "/subject_id",
"message": "subject_id is required.",
"code": "invalid_type"
}
],
"request_id": "req_01j2k3m4n5"
}
}Authorizations
Firebase Auth JWT issued by Google Identity Platform.
Obtain a token by signing in at your app domain and calling
firebase.auth().currentUser.getIdToken().
Path Parameters
Tenant identifier.
Body
Immutable versioned identity state envelope. Stored as a snapshot.
attributes is an open map — the canonical v1 field lists for organization
and individual subjects are defined in the schema package and documented in
the identity model.
entity_state_envelope_v1 Deterministic UUIDv5 derived from subject and patch content.
Monotonically increasing version number per subject.
x >= 1Show child attributes
Show child attributes
Identity attributes. Open map — any key/value is accepted.
Canonical organization attributes are grouped under legal, contact,
jurisdiction, and identifiers; legal.legal_name is required.
Canonical individual attributes are grouped under biographic, contact,
jurisdiction, and identifiers; biographic.name is required with at
least one of given_name, family_name, or formatted_name.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Maps JSON Pointer paths to arrays of evidence references. Encodes which evidence supports each attribute value.
Show child attributes
Show child attributes
Show child attributes
Show child attributes