> ## Documentation Index
> Fetch the complete documentation index at: https://developers.marko.fr/llms.txt
> Use this file to discover all available pages before exploring further.

# Récupérer un suivi par identifiants externes

> Retourne la note uniquement si elle appartient à l'opération externe indiquée.



## OpenAPI

````yaml https://partner-api.marko.fr/v1/openapi.json get /operations/external/{operation_external_id}/notes/external/{note_external_id}
openapi: 3.1.0
info:
  title: MARKO External Partner API
  version: v1
  description: >-
    Stable external API contract for the live environment.


    Authentication flow for partner integrations:

    1. Generate an API key from the MARKO entity admin API section.

    2. Keep the raw API secret server-side and use it only to sign `POST
    /v1/auth/token`.

    3. Build the canonical message
    `MARKO-EXTERNAL-API-TOKEN-V1\n{key_id}\n{timestamp}\n{nonce}`.

    4. Sign that message with HMAC-SHA256 and send the hex signature with
    `key_id`, `timestamp` and `nonce`.

    5. Use the returned short-lived bearer on business endpoints as
    `Authorization: Bearer <access_token>`.

    The raw API secret must never be sent on business endpoints.


    This public contract intentionally excludes beta endpoints.
servers:
  - url: https://partner-api.marko.fr/v1
security:
  - BearerAuth: []
externalDocs:
  description: Download the matching Postman collection.
  url: /v1/postman.json
paths:
  /operations/external/{operation_external_id}/notes/external/{note_external_id}:
    get:
      tags:
        - operations
      summary: Récupérer un suivi par identifiants externes
      description: >-
        Retourne la note uniquement si elle appartient à l'opération externe
        indiquée.
      operationId: operations_notes_external_get
      parameters:
        - in: path
          name: operation_external_id
          required: true
          schema:
            type: string
            pattern: ^[A-Za-z0-9_~-][A-Za-z0-9._:~-]{0,254}$
            minLength: 1
            maxLength: 255
          example: CF-OP-001
        - in: path
          name: note_external_id
          required: true
          schema:
            type: string
            pattern: ^[A-Za-z0-9_~-][A-Za-z0-9._:~-]{0,254}$
            minLength: 1
            maxLength: 255
          example: CF-NOTE-002
        - in: header
          name: X-Request-ID
          required: false
          description: >-
            Partner-generated correlation identifier echoed in logs and error
            payloads.
          schema:
            type: string
          example: marko-operations-notes-external-get
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                properties:
                  id:
                    format: uuid
                    title: Id
                    type: string
                  operation_id:
                    format: uuid
                    title: Operation Id
                    type: string
                  date:
                    format: date-time
                    title: Date
                    type: string
                  text:
                    title: Text
                    type: string
                  category:
                    title: Category
                    type: string
                  description_i18n:
                    additionalProperties:
                      type: string
                    title: Description I18N
                    type: object
                  source_created_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                    default: null
                    title: Source Created At
                  source_updated_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                    default: null
                    title: Source Updated At
                  created_at:
                    format: date-time
                    title: Created At
                    type: string
                  updated_at:
                    format: date-time
                    title: Updated At
                    type: string
                required:
                  - id
                  - operation_id
                  - date
                  - text
                  - category
                  - created_at
                  - updated_at
                title: ExternalNoteResourceResponse
                type: object
              example:
                id: 55555555-5555-5555-5555-555555555555
                operation_id: 44444444-4444-4444-4444-444444444444
                date: '2026-08-22T08:00:00Z'
                category: custom__a3e08c7bde__comite
                text: 'Comité: prorogation à documenter.'
                description_i18n: {}
                created_at: '2026-08-22T08:00:00Z'
                updated_at: '2026-08-22T08:00:00Z'
        '401':
          description: Authentication required
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Unauthorized
                status: 401
                detail: A valid bearer token is required.
                request_id: req_example_partner_call
        '403':
          description: Scope, route or IP restriction
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Forbidden
                status: 403
                detail: The API key does not allow this operation.
                request_id: req_example_partner_call
        '422':
          description: Validation failed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Unprocessable Content
                status: 422
                detail: The request payload or parameters are invalid.
                request_id: req_example_partner_call
        '429':
          description: Rate limit or progressive ban
          headers:
            Retry-After:
              description: Cooldown in seconds before retrying the request.
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Too Many Requests
                status: 429
                detail: The request rate limit was exceeded.
                request_id: req_example_partner_call
        '500':
          description: Unexpected server error
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Internal Server Error
                status: 500
                detail: An unexpected server error occurred.
                request_id: req_example_partner_call
      deprecated: false
      security:
        - BearerAuth: []
components:
  schemas:
    ProblemDetails:
      type: object
      required:
        - title
        - status
        - detail
      properties:
        type:
          type: string
          default: about:blank
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
        request_id:
          type: string
        scope:
          type: string
        route_id:
          type: string
        reason_code:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: MARKO short-lived bearer
      description: >-
        Use the `access_token` returned by `POST /v1/auth/token`. Do not send
        the raw API secret on business endpoints.

````