← Docs

Audit log

GET /api/v1/audit/ lists this Organization's IdentityEvent rows, filterable by ?event_type=, ?user= (a User UUID), and ?created_after=/?created_before= (ISO datetimes). Security-sensitive event types are marked distinctly in the Audit log page itself, not rendered as an opaque type string.

Event types that actually get logged today

login · logout · signup · self_registration_rejected · invite_sent · invite_accepted · session_revoked · organization_healed · role_changed · mfa_changed · email_changed · password_changed · password_sync_failed · suspicious_activity · device_verified · device_revoked · api_key_created · api_key_revoked · agent_grant_issued · agent_grant_revoked · passkey_registered · passkey_removed · scim_user_provisioned · scim_user_deprovisioned · federated_identity_linked

logout is distinct from session_revoked — logged only when you end your own session yourself ("log out this device"/"log out one of my other devices"). An admin revoking someone else's session, an org-wide revocation, or a refresh-token reuse-detection response all still log session_revoked, since those weren't the user's own deliberate action.

Reserved, not yet wired

These event types exist in the schema and are filterable, but nothing in this codebase currently writes one — they will never appear in a real Organization's log yet. account_recovery_initiated/account_recovery_completed are reserved for a real recovery flow (losing both your password and your MFA/backup codes simultaneously) that hasn't been built yet — they are not the same thing as the existing forgot-password flow, which already works and already logs a real password_changed event.

account_recovery_initiated · account_recovery_completed