FruxonDocs
ApiAudit log

Lists audit events, newest first.

Every query is bounded in time: without `from` it covers the 90 days before `to` (default: now). `action` takes an exact name or a prefix such as `secret.*`. A workspace whose plan does not include the audit log sees only Fruxon staff access, which is recorded for every workspace. Requires the `audit:read` scope (Admin and Owner).

GET
/v1/tenants/{tenant}/auditEvents
AuthorizationBearer <token>

JWT Authorization header using the Bearer scheme. Enter 'Bearer' [space] and then your token.

In: header

Path Parameters

tenant*string

The tenant identifier

Query Parameters

From?integer

Start of the window, Unix ms, inclusive. Defaults to 90 days before Fruxon.Model.AuditLog.AuditEventsFilter.To. Always bounded, so a query only touches the monthly partitions it needs.

Formatint64
To?integer

End of the window, Unix ms, inclusive. Defaults to now.

Formatint64
UserId?string

Only events by this person (their user id).

TokenId?string

Only calls made with this token.

Formatuuid
ServiceAccountId?string

Only events by this service account.

Formatuuid
Action?string

An exact action (secret.delete), or a prefix ending in .* (secret.*) for every action under it.

ResourceType?string
ResourceId?string
Category?array<AuditCategory>

Repeat the parameter to match any of several.

Outcome?array<AuditOutcome>

Repeat the parameter to match any of several.

PrincipalType?string
Value in"UNSPECIFIED" | "USER" | "SERVICE_ACCOUNT" | "FRUXON_STAFF" | "SYSTEM"
PageSize?integer

The maximum number of items to return per page

Formatint32
PageToken.Skip?integer
Formatint32
PageToken.Cursor?string

Opaque cursor token from an external system (e.g. RAG API). When set, M:Fruxon.Common.Collections.PageToken.AsString returns this value directly instead of encoding Fruxon.Common.Collections.PageToken.Skip.

Response Body

curl -X GET "https://api.fruxon.com/v1/tenants/string/auditEvents"
{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "createdAt": 0,
      "principal": {
        "type": "UNSPECIFIED",
        "userId": "string",
        "displayName": "string",
        "email": "string",
        "tokenId": null,
        "tokenName": "string",
        "serviceAccountId": null,
        "serviceAccountName": "string",
        "actor": "string"
      },
      "clientIp": "string",
      "userAgent": "string",
      "traceId": "string",
      "action": "string",
      "category": "WRITE",
      "resourceType": "string",
      "resourceId": "string",
      "parentResourceId": "string",
      "changedFields": [
        "string"
      ],
      "outcome": "SUCCEEDED",
      "statusCode": 0,
      "attemptEventId": "00000000-0000-0000-0000-000000000000",
      "sourceLedger": "string",
      "sourceEventId": "00000000-0000-0000-0000-000000000000"
    }
  ],
  "nextPageToken": "string",
  "totalCount": 0
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}
Empty
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}