# EU AI Act deployer evidence pack

Source: https://immiscible.fly.dev/docs/api/get-v1-cli-evidence-ai-act

`GET /v1/cli/evidence/ai-act`

The same pack as [`GET /api/w/:wid/evidence/ai-act`](https://immiscible.fly.dev/docs/api/get-api-w-wid-evidence-ai-act.md), for the workspace the token signed in to: JSON, or a zip with `?format=zip` (what `immiscible evidence ai-act` saves). Needs the `status:read` scope and a role that reads evidence (owner, admin, security admin or auditor); any other role gets `403 forbidden`.

## Authentication

CLI token. A token (`imc_...`) the developer CLI gets by signing in through the browser (`immiscible login`, the OAuth device grant), sent as `Authorization: Bearer`. It acts for one person in one workspace: it reads agents and status, and registers an agent with a rule from the same purposes as the console's "Add an agent". It never approves anything or changes an existing rule. Every use re-checks the person's membership and the workspace's sign-in rules; it lasts 90 days and ends from the console's sessions.

## Request

curl:

```bash
curl "https://immiscible.fly.dev/v1/cli/evidence/ai-act" \
  -H "authorization: Bearer $IMMISCIBLE_TOKEN"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/v1/cli/evidence/ai-act', {
  headers: {
    authorization: `Bearer ${process.env.IMMISCIBLE_TOKEN}`,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.get(
    "https://immiscible.fly.dev/v1/cli/evidence/ai-act",
    headers={
        "authorization": f"Bearer {os.environ['IMMISCIBLE_TOKEN']}",
    },
)
print(res.status_code, res.json())
```
