# See the status of a submission {#top}

**Read** · `GET /v1/tenants/{tenant}/submissions/{submission}` · MCP tool `status`

Shows what has happened to one submission: its state, the results of its checks, and the progress and output of its build. You can always read a submission you made, even if the same spec would be refused today.

Roles that can call it: `viewer`, `builder`, `deployer`.

## Parameters

| Name | In | Required | Description |
|---|---|---|---|
| `tenant` | path | yes | Your tenant ID |
| `submission` | path | yes | The submission ID that `submit` returned |

## Returns

A JSON object with these keys: `submission`, `tenant`, `spec_hash`, `state`, `submitted_at`, `gates`, `artifacts`, `pipeline`, `guarantee`, `caller_authenticated`, `provisioning`, `retained_tooling`, `warnings`.

## Example request

```sh
curl https://api.tarsana.io/v1/tenants/acme/submissions/sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1 \
  -H "X-Tarsana-Access-Token: $ACCESS_TOKEN" \
  -H 'X-Tarsana-Tenant: acme'
```

## Example response

```json
{
  "submission": "sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1",
  "tenant": "acme",
  "spec_hash": "sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1",
  "state": "accepted",
  "submitted_at": "2026-10-05T02:15:39Z",
  "gates": [
    {
      "gate": "tenant_name",
      "verdict": "pass",
      "status": "wired",
      "detail": "A sentence about this check.",
      "report": null
    },
    {
      "gate": "spec_schema",
      "verdict": "pass",
      "status": "wired",
      "detail": "A sentence about this check.",
      "report": null
    },
    {
      "gate": "policy_precheck",
      "verdict": "pass",
      "status": "wired",
      "detail": "A sentence about this check.",
      "report": {
        "violations": [],
        "warnings": []
      }
    }
  ],
  "artifacts": [
    "artifacts",
    "provenance",
    "sbom",
    "spec"
  ],
  "pipeline": {
    "job": "j-bbdde9adc372c296",
    "state": "dispatched",
    "created": true,
    "what": "A sentence about the build's progress."
  },
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false,
  "provisioning": {
    "state": "not_requested",
    "provider": null,
    "target": null,
    "mechanism": null,
    "attested": null,
    "correlation_id": null,
    "what": "A sentence about the installation."
  },
  "retained_tooling": {
    "state": "none",
    "retained": []
  },
  "warnings": null
}
```

## Errors

| Code | HTTP | What it means |
|---|---|---|
| [`invalid_parameter`](/api/errors#invalid_parameter) | 400 | A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again. |
| [`no_acting_tenant`](/api/errors#no_acting_tenant) | 400 | Your request does not say which tenant you are acting for. Send your tenant ID in the `X-Tarsana-Tenant` header, or with `--as` on the command line. |
| [`isolation_refused`](/api/errors#isolation_refused) | 403 | This address belongs to a tenant ID you do not have access to. Check the tenant ID in the address and in your request header. |
| [`no_such_submission`](/api/errors#no_such_submission) | 404 | You have no submission with this ID. Check the ID that `submit` returned. |
| [`unauthenticated`](/api/errors#unauthenticated) | 401 | Your request has no credential, or one that Tarsana does not recognise. Sign in with `login`, or send a valid access token. |
| [`forbidden`](/api/errors#forbidden) | 403 | Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them. |
| [`rate_limited`](/api/errors#rate_limited) | 429 | You sent too many requests in a short time. Wait for the number of seconds in `retry_after_seconds`, then try again. |
| [`surface_fault`](/api/errors#surface_fault) | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |
