DEVELOPER DOCS

REST API

Audit Log

Every privileged action — credential changes, retention changes, member role changes, workspace deletion — writes an immutable audit row.


List audit log

HTTP
GET /v1/observ/orgs/{org}/workspaces/{ws}/audit-log

Auth: API key or JWT · Role: admin

Query parameters

NameTypeRequiredDefaultDescription
limitinteger➖100Page size
cursorstring | null➖nullOpaque cursor from next_cursor

Response 200 — not schema-modelled

JSON
{
  "data": [
    {
      "ts": "2026-09-01T14:23:05Z",
      "endpoint": "/v1/observ/orgs/acme/workspaces/prod/retention",
      "method": "PUT",
      "status_code": 200,
      "actor_user_id": "3f2b1c8e-...",
      "actor_api_key_prefix": null,
      "request_id": "9f2c4b1e...",
      "metadata": { "old_hours": 720, "new_hours": 168 }
    }
  ],
  "meta": {
    "request_id": "…",
    "schema_version": "1.0",
    "next_cursor": "eyJ0cyI6..."
  }
}

next_cursor is nested inside meta here, unlike /traces where it is at the top level. Row keys are computed and not schema-modelled — confirm against a live response.

actor_user_id is populated for JWT-authenticated actions; actor_api_key_prefix is populated for API-key actions. Exactly one is set.

Examples

for row in evigauge.paginate(
    "/v1/observ/orgs/{org}/workspaces/{ws}/audit-log", limit=100
):
    print(row["ts"], row["action"], row["target"])