# Exemptions

Access and modify Exemptions to Security Issues

## Exemptions#ListExemptions

 - [GET /sto/api/v2/exemptions](https://apidocs.harness.io/exemptions/exemptions_listexemptions.md): List a collection of Exemptions

## Exemptions#CreateExemption

 - [POST /sto/api/v2/exemptions](https://apidocs.harness.io/exemptions/exemptions_createexemption.md): Create a new Exemption

## Exemptions#DeleteExemption

 - [DELETE /sto/api/v2/exemptions/{id}](https://apidocs.harness.io/exemptions/exemptions_deleteexemption.md): Delete an existing Exemption

## Exemptions#FindExemptionById

 - [GET /sto/api/v2/exemptions/{id}](https://apidocs.harness.io/exemptions/exemptions_findexemptionbyid.md): Find Exemption by ID

## Exemptions#UpdateExemption

 - [PUT /sto/api/v2/exemptions/{id}](https://apidocs.harness.io/exemptions/exemptions_updateexemption.md): Update an existing Exemption

## Exemptions#ApproveExemption

 - [PUT /sto/api/v2/exemptions/{id}/{action}](https://apidocs.harness.io/exemptions/exemptions_approveexemption.md): Approve/reject an existing Exemption

## Exemptions#PromoteExemption

 - [PUT /sto/api/v2/exemptions/{id}/promote](https://apidocs.harness.io/exemptions/exemptions_promoteexemption.md): Promote an existing Exemption to a higher scope

## Bulk create exemptions

 - [POST /sto/api/v2/exemptions/bulk](https://apidocs.harness.io/exemptions/exemptions_bulkcreateexemptions.md): Create multiple Exemptions in bulk. The batch is all-or-none for policy violations: if any item would violate an exemption rule, the entire batch is rejected with HTTP 400 and a single error message naming the failing issue and rule (no DB writes happen). Infrastructure failures (DB constraint violations, transaction errors) also fail the entire batch and are surfaced per-item in the response body so ops can diagnose which item triggered the failure.

## Get exemption for issue

 - [GET /sto/api/v2/exemptions/issue/{issueId}](https://apidocs.harness.io/exemptions/exemptions_getexemptionforissue.md): Get the highest-priority exemption for an issue across all scopes (account, org, project)

## List exemption history for issue

 - [GET /sto/api/v2/exemptions/issue/{issueId}/history](https://apidocs.harness.io/exemptions/exemptions_listissueexemptionhistory.md): Paginated flat timeline of exemption history events for an issue

## Export exemption history for issue as CSV

 - [GET /sto/api/v2/exemptions/issue/{issueId}/history/export](https://apidocs.harness.io/exemptions/exemptions_exportissueexemptionhistory.md): CSV export of the full exemption history timeline for an issue (fetch-all, no pagination)

