# GET /api/v1/public/decks/{token}

> Public deck viewer (unauthenticated)

- **Tag:** ai-reporting-public
- **Operation ID:** `fetch_public_deck_api_v1_public_decks__token__get`

## Description

Resolve a share token to a read-only, redacted DeckSpec. Returns 404 for unknown / expired / revoked tokens. Rate-limited per IP.

## Authentication

Bearer token in `Authorization` header.
Required header: `x-business-id: <business uuid>`.

## Parameters

- `token` (path, string, required)

## Responses

### 200 — Successful Response

Schema: `PublicDeckResponse`

- `deck` (DeckSpec · required) → `DeckSpec`
  - `id` (string · required)
  - `business_id` (string · required)
  - `title` (string · required)
  - `period_start` (string · date)
  - `period_end` (string · date)
  - `slides` (array · CoverSlide | ExecSummarySlide | PnlSummarySlide | ArAgingSlide | CashPositionSlide | InventoryCogsSlide | CustomerConcentrationSlide | AsksSlide | CustomSlideSpec)
  - `created_at` (string · date-time · required)
  - `theme` (DeckTheme)
- `cached` (boolean)

### 404 — Not Found - Resource does not exist

### 422 — Validation Error

Schema: `HTTPValidationError`

- `detail` (array · ValidationError) → `ValidationError`
  - `loc` (array · string | integer · required)
  - `msg` (string · required)
  - `type` (string · required)
  - `input` (object)
  - `ctx` (object)

### 429 — Too Many Requests - Rate limit exceeded

## Code samples

### cURL

```bash
curl -X GET 'https://api.ondayzero.com/api/v1/public/decks/{token}' \
  -H 'Authorization: Bearer dz_your_token' \
  -H 'x-business-id: YOUR_BUSINESS_ID'
```

### JavaScript

```javascript
const response = await fetch('https://api.ondayzero.com/api/v1/public/decks/{token}', {
  method: 'GET',
  headers: {
    Authorization: 'Bearer dz_your_token',
    'x-business-id': 'YOUR_BUSINESS_ID',
  },
});
const data = await response.json();
```

### Python

```python
import httpx

headers = {
    "Authorization": "Bearer dz_your_token",
    "x-business-id": "YOUR_BUSINESS_ID",
}

response = httpx.get("https://api.ondayzero.com/api/v1/public/decks/{token}", headers=headers)
data = response.json()
```

## See also

- HTML version: https://www.ondayzero.com/docs/reference/ai-reporting-public/fetch-public-deck
- OpenAPI slice: https://www.ondayzero.com/docs/reference/ai-reporting-public/fetch-public-deck/openapi.json
- Other endpoints in **ai-reporting-public**: https://www.ondayzero.com/docs/reference/ai-reporting-public
