> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-hunner-patch-1.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List Egress Denial Summary

> Groups denied and would-deny egress flows for this Edge by destination, caller, outcome and reason.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples get /api/v1/apps/{app_id}/edges/{id}/egress/denial-summary
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/edges/{id}/egress/denial-summary:
    get:
      tags:
        - Edge
      summary: List Egress Denial Summary
      description: >-
        Groups denied and would-deny egress flows for this Edge by destination,
        caller, outcome and reason.
      operationId: c1.api.edge.v1.EdgeService.ListEgressDenialSummary
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: The appId field.
            type: string
        - in: path
          name: id
          required: true
          schema:
            description: The id field.
            type: string
        - in: query
          name: dest_host
          schema:
            description: The destHost field.
            type: string
        - in: query
          name: dest_host_suffix
          schema:
            description: The destHostSuffix field.
            type: string
        - in: query
          name: egress_enforcement_mode
          schema:
            description: The egressEnforcementMode field.
            type: string
        - in: query
          name: egress_policy_verdict
          schema:
            description: Same filters as EdgeServiceListEgressTrafficEventsRequest.
            type: string
        - in: query
          name: limit
          schema:
            description: Maximum groups returned, largest count first. 0 defaults to 50.
            format: int32
            type: integer
        - in: query
          name: principal_user_id
          schema:
            description: The principalUserId field.
            type: string
        - in: query
          name: since
          schema:
            description: The since field.
            format: int64
            type: string
        - in: query
          name: until
          schema:
            description: The until field.
            format: int64
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.edge.v1.EdgeServiceListEgressDenialSummaryResponse
          description: Successful response
components:
  schemas:
    c1.api.edge.v1.EdgeServiceListEgressDenialSummaryResponse:
      description: The EdgeServiceListEgressDenialSummaryResponse message.
      properties:
        groups:
          description: Ordered by count descending.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.TBEgressDenialGroup'
          type:
            - array
            - 'null'
        truncated:
          description: >-
            True when more groups matched than were returned; narrow the filters
            or
             the window.
          type: boolean
      title: Edge Service List Egress Denial Summary Response
      type: object
      x-speakeasy-name-override: EdgeServiceListEgressDenialSummaryResponse
    c1.api.edge.v1.TBEgressDenialGroup:
      description: TBEgressDenialGroup is one group of ListEgressDenialSummary.
      properties:
        count:
          description: The count field.
          format: int64
          type: string
        destHost:
          description: The destHost field.
          type: string
        egressEnforcementMode:
          description: The egressEnforcementMode field.
          type: string
        egressPolicyVerdict:
          description: The egressPolicyVerdict field.
          type: string
        firstSeen:
          format: date-time
          type:
            - string
            - 'null'
        lastSeen:
          format: date-time
          type:
            - string
            - 'null'
        outcome:
          description: |-
            DENIED, WOULD_DENY or ALLOWED. A flow an observe-mode Edge's policy
             denied but a later check also denied is DENIED.
          enum:
            - TB_EGRESS_FLOW_OUTCOME_UNSPECIFIED
            - TB_EGRESS_FLOW_OUTCOME_DENIED
            - TB_EGRESS_FLOW_OUTCOME_WOULD_DENY
            - TB_EGRESS_FLOW_OUTCOME_ALLOWED
          type: string
          x-speakeasy-unknown-values: allow
        principalUserId:
          description: The C1 user source_principal resolves to; see TBTrafficEvent.
          type: string
        reasonClass:
          description: |-
            The flow's denial family: rule_deny, ssrf, body_cap, encoding,
             content:<Kind>[+<Kind>...] (blocking credential kinds),
             content:response, or other.
          type: string
        sampleEventId:
          description: |-
            The newest flow in the group; pass it with sample_event_time to
             GetEgressTrafficEvent.
          type: string
        sampleEventTime:
          format: date-time
          type:
            - string
            - 'null'
        sourcePrincipal:
          description: The sourcePrincipal field.
          type: string
        sourcePrincipalKind:
          description: The sourcePrincipalKind field.
          type: string
      title: Tb Egress Denial Group
      type: object
      x-speakeasy-name-override: TBEgressDenialGroup
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````