> ## Documentation Index
> Fetch the complete documentation index at: https://www.worldmonitor.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# GetCountryVulnerabilities

> GetCountryVulnerabilities returns the full per-commodity score evidence for one country.



## OpenAPI

````yaml /api/SupplyChainService.openapi.yaml get /api/supply-chain/v1/get-country-vulnerabilities
openapi: 3.1.0
info:
  title: SupplyChainService API
  version: 1.0.0
servers:
  - url: https://api.worldmonitor.app
security:
  - WorldMonitorKey: []
  - ApiKeyHeader: []
paths:
  /api/supply-chain/v1/get-country-vulnerabilities:
    get:
      tags:
        - SupplyChainService
      summary: GetCountryVulnerabilities
      description: >-
        GetCountryVulnerabilities returns the full per-commodity score evidence
        for one country.
      operationId: GetCountryVulnerabilities
      parameters:
        - name: iso2
          in: query
          description: Uppercase ISO 3166-1 alpha-2 country code.
          required: true
          example: US
          schema:
            type: string
            pattern: ^[A-Z]{2}$
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              example:
                country: US
                generatedAt: '2026-01-15T12:00:00Z'
                iso2: US
                methodologyVersion: example
                upstreamUnavailable: false
              schema:
                $ref: '#/components/schemas/GetCountryVulnerabilitiesResponse'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: >-
            API access requires an active subscription (the API key's
            subscription is inactive or expired).
          headers:
            X-Billing-Verification:
              description: >-
                Present when the 403 is a billing-provider-confirmed
                subscription lapse (value subscription_lapsed, matching the body
                `code`).
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
        '429':
          description: Rate limit exceeded.
          headers:
            X-RateLimit-Limit:
              description: Maximum requests allowed in the active rate-limit window.
              schema:
                type: string
            X-RateLimit-Remaining:
              description: Requests remaining in the active rate-limit window.
              schema:
                type: string
            X-RateLimit-Reset:
              description: >-
                Unix epoch milliseconds when the active rate-limit window
                resets.
              schema:
                type: string
            Retry-After:
              description: Seconds to wait before retrying the request.
              schema:
                type: string
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Error'
                  - $ref: '#/components/schemas/RateLimitError'
        '503':
          description: >-
            Service unavailable. Billing-verification responses include code and
            X-Billing-Verification; other gateway infrastructure failures use
            the generic GatewayError shape.
          headers:
            Retry-After:
              description: Seconds to wait before retrying (1-60).
              schema:
                type: string
            X-Billing-Verification:
              description: >-
                Billing-verification state that produced this response (matches
                the body `code`).
              schema:
                type: string
            X-Validation-Mode:
              description: >-
                Present with value degraded when user API-key validation is
                temporarily unavailable.
              schema:
                type: string
            X-RateLimit-Mode:
              description: >-
                Present with value degraded when a fail-closed rate-limit
                dependency is unavailable.
              schema:
                type: string
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/BillingVerificationError'
                  - $ref: '#/components/schemas/GatewayError'
        default:
          description: Gateway or handler error response.
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Error'
                  - $ref: '#/components/schemas/GatewayError'
components:
  schemas:
    GetCountryVulnerabilitiesResponse:
      type: object
      properties:
        iso2:
          type: string
          description: Uppercase ISO 3166-1 alpha-2 code for the requested country.
        country:
          type: string
          description: Human-readable name of the requested country.
        vulnerabilities:
          type: array
          items:
            $ref: '#/components/schemas/CommodityVulnerability'
        generatedAt:
          type: string
          description: ISO 8601 timestamp when the country index was generated.
        methodologyVersion:
          type: string
          description: Version of the scoring methodology used for every row.
        upstreamUnavailable:
          type: boolean
          description: True when the published country index could not be read.
    ValidationError:
      type: object
      properties:
        violations:
          type: array
          items:
            $ref: '#/components/schemas/FieldViolation'
          description: List of validation violations
      required:
        - violations
      description: >-
        ValidationError is returned when request validation fails. It contains a
        list of field violations describing what went wrong.
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          description: Human-readable error message.
      required:
        - error
      description: >-
        Returned when the API key is missing, malformed, or lacks current API
        access.
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          description: Human-readable entitlement failure reason.
        code:
          type: string
          enum:
            - subscription_lapsed
          description: >-
            Machine-readable denial code, present when the 403 is a
            billing-provider-confirmed subscription lapse (mirrored in the
            X-Billing-Verification response header).
        requiredTier:
          type: integer
          format: int32
          description: Minimum entitlement tier required for this endpoint.
        currentTier:
          type: integer
          format: int32
          description: Caller entitlement tier when known.
        planKey:
          type: string
          description: Caller plan key when known.
      required:
        - error
      description: >-
        Returned when a PRO-gated endpoint denies access because the caller has
        no resolved authenticated user, entitlements cannot be verified, or the
        caller lacks the required entitlement tier.
    Error:
      type: object
      properties:
        message:
          type: string
          description: Error message (e.g., 'user not found', 'database connection failed')
      description: >-
        Error is returned when a handler encounters an error. It contains a
        simple error message that the developer can customize.
    RateLimitError:
      type: object
      description: Returned when a gateway or handler rate limit rejects the request.
      properties:
        error:
          type: string
          description: Human-readable rate-limit failure reason.
      required:
        - error
    BillingVerificationError:
      type: object
      description: >-
        Returned with HTTP 503 when paid access cannot be confirmed right now:
        the billing provider is re-verifying a recently expired subscription, or
        the entitlement backend is unreachable. Retryable — honor Retry-After.
      properties:
        error:
          type: string
          description: Human-readable billing-verification failure reason.
        code:
          type: string
          enum:
            - renewal_verification_pending
            - renewal_verification_failed
            - entitlement_verification_unavailable
          description: >-
            Machine-readable billing-verification state, mirrored in the
            X-Billing-Verification response header.
        requiredTier:
          type: integer
          format: int32
          description: >-
            Minimum entitlement tier required for this endpoint, when the denial
            came from a tier gate.
      required:
        - error
        - code
    GatewayError:
      type: object
      description: >-
        Returned by gateway infrastructure errors before an RPC handler runs,
        such as origin, routing, method, authentication, or quota checks.
      properties:
        error:
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
          description: Gateway error reason or structured gateway failure details.
      required:
        - error
    CommodityVulnerability:
      type: object
      properties:
        countryIso2:
          type: string
          description: ISO 3166-1 alpha-2 code for the scored country.
        countryName:
          type: string
          description: English display name for the scored country.
        commodityId:
          type: string
          description: Stable reviewed commodity mapping identifier.
        commodity:
          type: string
          description: Human-readable commodity name.
        score:
          type: number
          format: double
          description: >-
            Vulnerability score from 0 to 100; absent when evidence is
            insufficient.
        band:
          type: string
          description: >-
            Score band: low, moderate, high, or critical; empty when the score
            is absent.
        components:
          $ref: '#/components/schemas/VulnerabilityComponents'
        coverage:
          type: array
          items:
            type: string
            description: Source coverage labels that contributed to this score.
        state:
          type: string
          description: 'Evidence state: ok, insufficient_data, or stale_input.'
        reasons:
          type: array
          items:
            type: string
            description: Machine-readable explanations for an insufficient or stale state.
        methodologyVersion:
          type: string
          description: Version of the scoring methodology that produced this row.
    FieldViolation:
      type: object
      properties:
        field:
          type: string
          description: >-
            The field path that failed validation (e.g., 'user.email' for nested
            fields). For header validation, this will be the header name (e.g.,
            'X-API-Key')
        description:
          type: string
          description: >-
            Human-readable description of the validation violation (e.g., 'must
            be a valid email address', 'required field missing')
      required:
        - field
        - description
      description: FieldViolation describes a single validation error for a specific field.
    VulnerabilityComponents:
      type: object
      properties:
        sourceConcentration:
          $ref: '#/components/schemas/VulnerabilitySourceConcentration'
        transitExposure:
          $ref: '#/components/schemas/VulnerabilityTransitExposure'
        buffer:
          $ref: '#/components/schemas/VulnerabilityBuffer'
    VulnerabilitySourceConcentration:
      type: object
      properties:
        value:
          type: number
          format: double
          description: Combined supplier or producer concentration from 0 to 1.
        importHhi:
          type: number
          format: double
          description: Import supplier Herfindahl-Hirschman concentration from 0 to 1.
        mineHhi:
          type: number
          format: double
          description: Mine-stage production concentration from 0 to 1.
        refineryHhi:
          type: number
          format: double
          description: Refinery-stage production concentration from 0 to 1.
        productionHhi:
          type: number
          format: double
          description: Combined mine and refinery production concentration from 0 to 1.
        productionCoverage:
          type: string
          description: Producer-stage coverage used for the combined concentration.
        coverage:
          type: string
          description: Overall concentration coverage state.
        inputs:
          type: array
          items:
            $ref: '#/components/schemas/VulnerabilityInput'
    VulnerabilityTransitExposure:
      type: object
      properties:
        value:
          type: number
          format: double
          description: Combined chokepoint exposure from 0 to 1.
        chokepoints:
          type: array
          items:
            $ref: '#/components/schemas/VulnerabilityTransitRoute'
    VulnerabilityBuffer:
      type: object
      properties:
        state:
          type: string
          description: 'Buffer evidence state: known or unknown.'
        vulnerability:
          type: number
          format: double
          description: Residual vulnerability after the available buffer, from 0 to 1.
        kind:
          type: string
          description: Buffer source class, such as stocks_to_use or gas_storage_fill.
        inputs:
          type: array
          items:
            $ref: '#/components/schemas/VulnerabilityInput'
    VulnerabilityInput:
      type: object
      properties:
        sourceKey:
          type: string
          description: Redis or source-contract key that supplied this observation.
        sourceName:
          type: string
          description: Human-readable source name.
        sourceUrl:
          type: string
          description: Public source or methodology URL.
        value:
          type: number
          format: double
          description: >-
            Numeric observation used by the scorer; absent when the source is
            unknown.
        year:
          type: integer
          format: int32
          description: Observation year when the source publishes annual data.
        fetchedAt:
          type: string
          description: ISO 8601 timestamp when the source snapshot was fetched.
        stale:
          type: boolean
          description: >-
            True when this observation is older than its source-specific
            freshness budget.
        detail:
          type: string
          description: Bounded explanation of the mapped input.
    VulnerabilityTransitRoute:
      type: object
      properties:
        id:
          type: string
          description: Stable chokepoint identifier.
        name:
          type: string
          description: Human-readable chokepoint name.
        transitShare:
          type: number
          format: double
          description: Country and commodity exposure share using this route, from 0 to 1.
        weightedTransitShare:
          type: number
          format: double
          description: Transit share after the current disruption multiplier, from 0 to 1.
        status:
          type: string
          description: >-
            Current route state: baseline, disrupted, or unknown when the flow
            row is absent.
        inputs:
          type: array
          items:
            $ref: '#/components/schemas/VulnerabilityInput'
  securitySchemes:
    WorldMonitorKey:
      type: apiKey
      in: header
      name: X-WorldMonitor-Key
      description: User-issued WorldMonitor API key.
    ApiKeyHeader:
      type: apiKey
      in: header
      name: X-Api-Key
      description: Alias header for the WorldMonitor API key (X-WorldMonitor-Key).

````