# GET /repository/find/{datatype}/{dataId}

Section: [Repository](https://appengine.appmint.io/documentation/tag/repository.md) · Full index: https://appengine.appmint.io/documentation.md
## GET /repository/find/{datatype}/{dataId}

**Query records**

`operationId: RepositoryController_query`

The richest read on the controller: filters by attributes, categories, tags and keyword together, with paging and sorting.

It is mounted at two paths — `find/...` and `find-page-data/...` — which behave identically. `find/` is the one to use; the other name is historical.

#### Signature

```http
GET /repository/find/{datatype}/{dataId} (datatype: string, dataId: string, attributes?: string, categories?: string, tags?: string, keyword?: string, p?: integer, ps?: integer, l?: string, s?: string, st?: string, en?: boolean) -> A page of matching records
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /repository/find-page-data/{datatype}/{dataId}`
- `POST /repository/find/{datatype}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `datatype` | path | string | yes | The collection to act on. |
| `dataId` | path | string | yes | Restrict to one record. |
| `l` | query | string | — | Cursor for keyset pagination: the sort value of the last record from the previous page. Pass it to continue past that record instead of skipping with `p`, which stays fast at any depth. |
| `keyword` | query | string | — | Text filter. |
| `en` | query | boolean | — | Resolve linked records inline. |
| `attributes` | query | string | — | Field/value pairs to match. |
| `categories` | query | string | — | Categories to match. Repeat for several. |
| `tags` | query | string | — | Tags to match. Repeat for several. |
| `p` | query | integer | — | Page number, 1-based. |
| `ps` | query | integer | — | Page size — how many records to return. Large values are slower; prefer cursor paging via `l` for deep scans. |
| `s` | query | string | — | Field to sort by. |
| `st` | query | "asc" \| "desc" | — | Sort direction. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | A page of matching records |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

