# List orders

`GET /v0/labs/orders`

> **Authentication:** every request must send `X-ConfidentLims-APIKey`, `X-ConfidentLims-Timestamp` (unix seconds) and `X-ConfidentLims-Signature`, an HMAC-SHA256 signature of the request. The examples below call `sign_request()` from the [Request Signing guide](https://api.confidentcannabis.com/v0/docs/request-signing.md) — read it first. Request bodies are form-encoded, never JSON.

Return every order belonging to your lab, most recently placed first.

Use `start` and `limit` to page through the results — a maximum of 100
orders
are returned at a time. When more orders are available beyond the current page,
`more_results` is `true`.

The list can also be narrowed to a single order status, a single client, or to
orders changed since a given time.

## Query parameters

- `start` (integer, optional, default `0`) — Zero-based index of the first order to return.
- `limit` (integer, optional, default `100`) — Maximum number of orders to return. Capped at 100.
- `status_id` (integer, optional) — Only return orders currently in this order status.
- `modified_since_time` (string, optional) — Only return orders modified after this time, e.g. `2025-03-14T09:12:44`.
- `client_id` (integer, optional) — Only return orders placed by this client.

## Responses

### 200 Success

Fields (alongside the `success: true` envelope flag):

- `orders` (array of objects)
  - `id` (string) — Order ID
  - `industry_id` (integer) — Industry ID
  - `industry_name` (string) — Industry Name
  - `lims_id` (string) — Order lims ID
  - `client_id` (integer) — Client ID
  - `status_id` (integer) — Status ID
  - `status_name` (string) — Status Name
  - `lab_license_number` (string) — Lab license number under which order was tested
  - `client_license_number` (string) — Client license number under which order was placed
  - `ordered_date` (timestamp) — Order Date [when order was placed]
  - `verified_date` (timestamp) — Verified Date [when order was verified]
  - `completed_date` (timestamp) — Completed Date [when order was completed]
  - `last_modified` (timestamp) — Time this order was last modified
- `more_results` (boolean) — True when more orders are available beyond this page.

Example:

```json
{
  "success": true,
  "orders": [
    {
      "id": "2503GLL0042",
      "industry_id": 1,
      "industry_name": "Cannabis",
      "lims_id": "PO-8841",
      "client_id": 318,
      "status_id": 2,
      "status_name": "Placed",
      "lab_license_number": "C8-0000123-LIC",
      "client_license_number": "CDPH-10003456",
      "ordered_date": "2025-03-14T09:12:44",
      "verified_date": null,
      "completed_date": null,
      "last_modified": "2025-03-14T09:12:44"
    },
    {
      "id": "2503GLL0041",
      "industry_id": 1,
      "industry_name": "Cannabis",
      "lims_id": "PO-8840",
      "client_id": 318,
      "status_id": 4,
      "status_name": "Completed",
      "lab_license_number": "C8-0000123-LIC",
      "client_license_number": "CDPH-10003456",
      "ordered_date": "2025-03-11T11:38:02",
      "verified_date": "2025-03-11T16:20:55",
      "completed_date": "2025-03-13T14:05:31",
      "last_modified": "2025-03-13T14:05:31"
    }
  ],
  "more_results": false
}
```

### 400 Bad request

The request was malformed or failed validation. Validation failures include per-field messages in `error_details`. Possible `error_code` values: `invalid_request`, `request_too_old`.

### 401 Unauthorized

Authentication failed. Possible `error_code` values: `missing_api_key`, `invalid_api_key`, `invalid_credentials_type`, `api_access_restricted`, `api_access_denied`, `missing_signature`, `missing_timestamp`, `invalid_timestamp`, `invalid_signature`.

### 403 Permission denied

The API key is valid but does not have permission for this endpoint (for example, a client key calling a labs endpoint). Possible `error_code` values: `permission_denied`.

## Examples

### cURL

```bash
# X-ConfidentLims-Signature: see the Request Signing guide - https://api.confidentcannabis.com/v0/docs/request-signing.md
curl -X GET 'https://api.confidentcannabis.com/v0/labs/orders' \
  -H 'X-ConfidentLims-APIKey: YOUR_API_KEY' \
  -H 'X-ConfidentLims-Timestamp: UNIX_TIMESTAMP' \
  -H 'X-ConfidentLims-Signature: REQUEST_SIGNATURE'
```

### Python

```python
import time
import requests

# sign_request() is defined in the Request Signing guide:
# https://api.confidentcannabis.com/v0/docs/request-signing.md
from sign_request import sign_request

API_KEY = 'YOUR_API_KEY'
API_SECRET = 'YOUR_API_SECRET'
path = '/v0/labs/orders'

params = {
    # optional query params go here - they are signed too
}

headers = {'X-ConfidentLims-Timestamp': str(int(time.time()))}
headers['X-ConfidentLims-Signature'] = sign_request(
    'GET', path, headers, params, API_KEY, API_SECRET)
headers['X-ConfidentLims-APIKey'] = API_KEY

response = requests.get(
    'https://api.confidentcannabis.com' + path,
    headers=headers,
    params=params,
)
print(response.json())
```

### JavaScript

```javascript
// signRequest() is defined in the Request Signing guide:
// https://api.confidentcannabis.com/v0/docs/request-signing.md
import { signRequest } from './sign_request.js';

const API_KEY = 'YOUR_API_KEY';
const API_SECRET = 'YOUR_API_SECRET';
const path = "/v0/labs/orders";

const params = {
  // optional query params go here - they are signed too
};

const headers = { 'X-ConfidentLims-Timestamp': String(Math.floor(Date.now() / 1000)) };
headers['X-ConfidentLims-Signature'] = signRequest(
  "GET", path, headers, params, API_KEY, API_SECRET);
headers['X-ConfidentLims-APIKey'] = API_KEY;

const response = await fetch(`https://api.confidentcannabis.com${path}?${new URLSearchParams(params)}`, {
  headers,
});
console.log(await response.json());
```

---

HTML version: https://api.confidentcannabis.com/v0/docs/labs/get-orders  
OpenAPI spec for this section: https://api.confidentcannabis.com/v0/docs/labs/openapi.json  
Request Signing guide: https://api.confidentcannabis.com/v0/docs/request-signing.md
