---
title: "Cursor-paginated user-scoped document list with status-bucket filter."
method: GET
path: "/v1/documents"
tags: ["Documents"]
---

# Cursor-paginated user-scoped document list with status-bucket filter.

`GET /v1/documents`

Returns active documents for the supplied `user_id`, ordered `(created_at DESC, id DESC)`. The opaque `cursor` is the `next_cursor` from the previous page (base64-url JSON tuple); malformed cursors return 400. The `status` query param buckets rows for the recovery surfaces: `'failed'` (any layer failed), `'unsupported'` (extraction marked unsupported), `'pending'` (extraction or semantic_index in pending/running), or `'all'` (default — every active row).

## Query parameters

- `user_id` string, required
- `limit` string
- `cursor` string
- `status` 'failed' | 'unsupported' | 'pending' | 'all'

## Response `200`

Cursor-paginated document list.

- object — Cursor-paginated document list.
  - `documents` object[], required
    - `content_hash` string, nullable, required
    - `created_at` string, required
    - `delete_semantics` 'delete' | 'unpin' | 'tombstone' | 'null', nullable, required — What AtomicMemory's DELETE call does at the provider boundary for this row's storage_provider. `'delete'` = adapter issues the provider's removal operation; `'unpin'` = removes AtomicMemory's pin but the provider's other peers may continue to serve; `'tombstone'` = AtomicMemory stops managing the bytes but the decentralized network may still serve. `null` for pointer-only rows or providers not registered for cleanup.
    - `display_name` string, nullable, required
    - `external_id` string, required
    - `external_uri` string, nullable, required
    - `extraction_status` 'not_required' | 'pending' | 'running' | 'complete' | 'unsupported' | 'failed', required
    - `id` string, required
    - `indexed_at` string, nullable, required
    - `indexed_content_hash` string, nullable, required
    - `last_error` object, nullable, required
      - `code` string, required
      - `layer` 'raw_storage' | 'extraction' | 'semantic_index', required
      - `message` string, required
      - `occurred_at` string, required
    - `metadata` object, required
    - `mime_type` string, nullable, required
    - `provider_version` string, nullable, required
    - `raw_source_id` string, required
    - `raw_storage_metadata` object, required — Public-facing raw_storage_metadata. STRICTLY allowlisted: codec emits only name+version (AES-GCM internals never reach the wire); filecoin emits public fields (ipfs_cid, piece_cid, copy_count, provider_ids, copy_statuses) — `ipfs_cid` is an optional CIDv1 IPFS / CAR-root identity hint populated by drivers that derive one alongside the PieceCID; the canonical storage URI stays `filecoin://piece/<piece_cid>` regardless. The internal structured copies[{provider_id,status}] shape is flattened at the formatter; upload_result and other internal sidecars are NEVER emitted. The schema is deny-by-default (`.strict()`) at every level — a formatter regression that lets unknown keys through fails response-shape validation.
      - `codec` object
        - `name` 'none' | 'aes_gcm', required
        - `version` number, required
      - `filecoin` object
        - `copy_count` integer
        - `copy_statuses` string[]
        - `ipfs_cid` string
        - `piece_cid` string
        - `provider_ids` string[]
    - `raw_storage_status` 'pointer_recorded' | 'blob_stored' | 'inline_text_stored' | 'raw_storage_failed' | 'blob_deleted' | 'blob_pending' | 'blob_available' | 'blob_archival_failed' | 'blob_tombstoned', required
    - `registration_status` 'registered' | 'registration_failed', required
    - `semantic_index_status` 'not_required' | 'pending' | 'running' | 'complete' | 'failed' | 'stale', required
    - `size_bytes` number, nullable, required
    - `source_modified_at` string, nullable, required
    - `storage_artifact_id` string, uuid, nullable, required
    - `storage_mode` 'pointer_only' | 'managed_blob' | 'inline_small_text', required
    - `storage_provider` string, nullable, required
    - `storage_uri` string, nullable, required
    - `updated_at` string, required
    - `user_id` string, required
  - `next_cursor` string, nullable, required

## Other responses

- `400` — Input validation error
- `500` — Internal server error
- `502` — Upstream AI provider returned an unrecoverable failure (auth, non-retryable 4xx).
- `503` — Upstream AI provider is rate-limited, quota-exhausted, or returned 5xx; consult `retryable`.

---

[API](https://skmtc.net/atomicstrata/apis/atomicmemory-http-api.md) · [All operations](https://skmtc.net/atomicstrata/apis/atomicmemory-http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/atomicstrata/atomicmemory-http-api/versions/d501daa39bb2/schema)
