temperDocs
Menu

API reference

Audit

Security audit log: one append-only hash chain per VM, queryable, with raw lines exportable for offline verification.

Query audit records

GET/v1/environments/{id}/audit

Paginated in ascending order of at, seq, chain. next is an opaque string; pass it back unchanged as after on the next call. It is non-null only when the page is full. A malformed after gives 400. Destroyed environments can be queried too (records are kept for 90 days). Records contain only metadata (time, domain, method, path, which credential was used, action category, decision); they never contain real tokens, request bodies or query strings.

Parameters

ParameterInTypeDescription
sourcequerystring

Only records from this source, for example egress (outbound requests), gateway (requests made with a credential) or browser. The value is not validated.

chainquerystring

Only records from this chain (see /audit/chains).

fromquerystring (date-time)

Only records at or after this time (RFC 3339).

toquerystring (date-time)

Only records before this time (exclusive).

limitqueryinteger

Items per page, default 100; values outside 1–1000 are clamped into that range.

afterquerystring

The previous page's next.

Responses

  • 200A page of audit records AuditRecordList
  • 400Invalid parameters: validation failed, the body is not valid JSON, or the query string could not be parsed (all returned in the same JSON shape).
  • 401Missing, invalid or revoked key
  • 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
  • 500Internal error (details are recorded only in server logs)

Export raw audit lines (NDJSON)

GET/v1/environments/{id}/audit/export

Raw lines, one record per line, ordered by chain and sequence number, with Content-Disposition: attachment; filename="audit-<environment id>.jsonl". Each line carries seq and prev (the SHA-256 of the previous line's exact bytes; the first line of a chain has 64 zeros), so you can recompute the hashes offline and verify the chain links. At most 100000 lines per export: if the range contains more, 409 export_too_large is returned (nothing is truncated); narrow the range with from / to and export in parts. With no records the response body is empty.

Parameters

ParameterInTypeDescription
fromquerystring (date-time)

Only records at or after this time (RFC 3339).

toquerystring (date-time)

Only records before this time (exclusive).

Responses

  • 200NDJSON string
  • 400Invalid parameters: validation failed, the body is not valid JSON, or the query string could not be parsed (all returned in the same JSON shape).
  • 401Missing, invalid or revoked key
  • 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
  • 409State conflict; `error` holds the specific code
  • 500Internal error (details are recorded only in server logs)

Audit hash chain status

GET/v1/environments/{id}/audit/chains

One chain per VM (replacing the VM starts a new chain). intact is false when at least one chain no longer links up from broken_at_seq onward: lines in between were modified, deleted or lost; an audit_chain_broken environment event is also recorded in that case.

Responses

  • 200Each chain AuditChainList
  • 401Missing, invalid or revoked key
  • 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
  • 500Internal error (details are recorded only in server logs)