GET /api/v1/audit/ lists this Organization's IdentityEvent rows, filterable by ?event_type=, ?user= (a User UUID), and ?created_after=/?created_before= (ISO datetimes). Security-sensitive event types are marked distinctly in the Audit log page itself, not
rendered as an opaque type string.
login · logout · signup · self_registration_rejected · invite_sent · invite_accepted · session_revoked · organization_healed · role_changed · mfa_changed · email_changed · password_changed · password_sync_failed · suspicious_activity · device_verified · device_revoked · api_key_created · api_key_revoked · agent_grant_issued · agent_grant_revoked · passkey_registered · passkey_removed · scim_user_provisioned · scim_user_deprovisioned · federated_identity_linked
logout is distinct from session_revoked — logged only when you end your
own session yourself ("log out this device"/"log out one of my other devices"). An
admin revoking someone else's session, an org-wide revocation, or a refresh-token
reuse-detection response all still log session_revoked,
since those weren't the user's own deliberate action.
These event types exist in the schema and are filterable, but nothing in this codebase
currently writes one — they will never appear in a real Organization's log yet. account_recovery_initiated/account_recovery_completed are reserved for a real recovery flow (losing both your password and your MFA/backup
codes simultaneously) that hasn't been built yet — they are not the same thing as the
existing forgot-password flow, which already works and already logs a real password_changed event.
account_recovery_initiated · account_recovery_completed