Read the audit log
GET/audit-log
Audit entries, newest first.
action accepts a full action (agent.login) or a prefix (agent), which
matches everything in that family. Use from and to to page through a long
history: one call scans a bounded window, so an unfiltered request over a busy
year will not return everything — meta.scan_truncated tells you when that
happened.
Anything done through this API carries details.via = "public_api" plus the
credential's client_id and name, and its agent_id reads
api:<credential_id>.
Request
Responses
- 200
- 400
- 401
- 403
- 503
Audit entries returned.
Response Headers
Correlation id for this request. Quote it when reporting a problem.
The request was malformed, or a parameter was rejected.
Response Headers
Correlation id for this request. Quote it when reporting a problem.
No token, an expired token, or a credential that has been revoked.
Response Headers
Correlation id for this request. Quote it when reporting a problem.
Refused. Either the credential does not hold the scope this endpoint needs (code: insufficient_scope), or the account's IP allow-list does not include the calling address (code: ip_not_allowed).
Response Headers
Correlation id for this request. Quote it when reporting a problem.
A dependency is temporarily unavailable, or a required index is still building. Safe to retry.
Response Headers
Correlation id for this request. Quote it when reporting a problem.