> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wfa.team/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve an assessment

> Retrieve risk results for an existing assessment.

`POST /rwa_retrieve`

If results are still being calculated, the endpoint returns `Pending`. Wait briefly, then retrieve the same assessment again; do not create another assessment.

## Authorization

<ParamField header="Authorization" type="string" required>
  Company Bearer token. Keep it on your server.
</ParamField>

## Body parameters

<ParamField body="assessmentId" type="string" required>
  Assessment identifier returned by the create endpoint.
</ParamField>

## Error responses

| Message | Meaning | Action |
| - | - | - |
| `Invalid Auth` | Company authorization did not match. | Check the company token and environment. |
| `Not Found` | No matching assessment was found. | Check the assessment ID and environment. |
| `Pending` | The assessment exists but its risk results are not ready. | Wait briefly and retrieve the same ID again. Stop polling after a bounded timeout and contact support. |

## Response

The documented success body contains `status: "success"` and a `data` object. Risk scores are numbers and can contain decimals; see [risk ratings](/reference/risk-ratings).

<ResponseField name="data.workingRights" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.payrollTax" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.socialSecurity" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.corporateTax" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.employmentLaw" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.overallTrip" type="number">
  Risk score from 0 to 10. See [risk ratings](/reference/risk-ratings).
</ResponseField>

<ResponseField name="data.assessmentId" type="string">
  Assessment identifier.
</ResponseField>

<ResponseField name="data.employeeId" type="string">
  Saved external Staff ID; may be empty when not assigned.
</ResponseField>

<ResponseField name="data.complianceTeamMemberId" type="string">
  Saved external Staff ID; may be empty when not assigned.
</ResponseField>

<ResponseField name="data.managerId" type="string">
  Saved external Staff ID; may be empty when not assigned.
</ResponseField>

<ResponseField name="data.cumulativePeRiskLevel" type="string">
  Company cumulative permanent-establishment risk level. Work From Anywhere only; separate from the 0–10 scores.
</ResponseField>

<ResponseField name="data.contractorMisclass" type="number">
  Contractor misclassification risk score. Hire From Anywhere only.
</ResponseField>

<Note>
  Check the JSON response as well as HTTP status. HTTP 200 can contain an API error. If a request times out, check the assessment before retrying. Retry deduplication is not verified.
</Note>

<RequestExample>
  ```bash cURL theme={null}
  curl --request POST \
    'https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_retrieve' \
    --header "Authorization: Bearer $WFA_COMPANY_TOKEN" \
    --header 'Content-Type: application/json' \
    --data '{
    "assessmentId": "YOUR_TEST_ASSESSMENT_ID"
  }'
  ```

  ```javascript JavaScript theme={null}
  // Run on your server. Set WFA_COMPANY_TOKEN in its environment.
  const response = await fetch('https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_retrieve', {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.WFA_COMPANY_TOKEN}`,
      'Content-Type': 'application/json'
    },
    body: JSON.stringify({
      "assessmentId": "YOUR_TEST_ASSESSMENT_ID"
    })
  });
  const result = await response.json();
  // Check the JSON body as well as the HTTP status.
  console.log(result);
  ```

  ```python Python theme={null}
  # Run on your server. Set WFA_COMPANY_TOKEN in its environment.
  import os
  import requests

  response = requests.post(
      'https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_retrieve',
      headers={
          'Authorization': f"Bearer {os.environ['WFA_COMPANY_TOKEN']}",
          'Content-Type': 'application/json',
      },
      json={
        "assessmentId": "YOUR_TEST_ASSESSMENT_ID"
      },
      timeout=45,
  )
  # Check the JSON body as well as the HTTP status.
  print(response.json())
  ```
</RequestExample>

<ResponseExample>
  ```json WFA success example theme={null}
  {
    "status": "success",
    "data": {
      "workingRights": 0,
      "payrollTax": 8.3,
      "socialSecurity": 9.1,
      "corporateTax": 7.5,
      "employmentLaw": 4.4,
      "overallTrip": 7.6,
      "assessmentId": "YOUR_ASSESSMENT_ID",
      "employeeId": "STAFF-001",
      "complianceTeamMemberId": "",
      "managerId": "",
      "cumulativePeRiskLevel": "Low"
    }
  }
  ```

  ```json HFA success example theme={null}
  {
    "status": "success",
    "data": {
      "workingRights": 0,
      "payrollTax": 8.3,
      "socialSecurity": 9.1,
      "corporateTax": 7.5,
      "employmentLaw": 4.4,
      "overallTrip": 7.6,
      "assessmentId": "YOUR_ASSESSMENT_ID",
      "employeeId": "STAFF-001",
      "complianceTeamMemberId": "",
      "managerId": "",
      "contractorMisclass": 6.2
    }
  }
  ```

  ```json Pending theme={null}
  {
    "status": "error",
    "success": false,
    "message": "Pending"
  }
  ```

  ```json Not found theme={null}
  {
    "status": "error",
    "success": false,
    "message": "Not Found"
  }
  ```

  ```json Invalid auth theme={null}
  {
    "status": "error",
    "success": false,
    "message": "Invalid Auth"
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.