REST API
Audit Log
Every privileged action — credential changes, retention changes, member role changes, workspace deletion — writes an immutable audit row.
List audit log
HTTP
GET /v1/observ/orgs/{org}/workspaces/{ws}/audit-log
Auth: API key or JWT · Role: admin
Query parameters
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
limit | integer | ➖ | 100 | Page size |
cursor | string | null | ➖ | null | Opaque cursor from next_cursor |
Response 200 — not schema-modelled
JSON
{
"data": [
{
"ts": "2026-09-01T14:23:05Z",
"endpoint": "/v1/observ/orgs/acme/workspaces/prod/retention",
"method": "PUT",
"status_code": 200,
"actor_user_id": "3f2b1c8e-...",
"actor_api_key_prefix": null,
"request_id": "9f2c4b1e...",
"metadata": { "old_hours": 720, "new_hours": 168 }
}
],
"meta": {
"request_id": "…",
"schema_version": "1.0",
"next_cursor": "eyJ0cyI6..."
}
}
next_cursoris nested insidemetahere, unlike/traceswhere it is at the top level. Row keys are computed and not schema-modelled — confirm against a live response.
actor_user_id is populated for JWT-authenticated actions;
actor_api_key_prefix is populated for API-key actions. Exactly one is set.
Examples
for row in evigauge.paginate(
"/v1/observ/orgs/{org}/workspaces/{ws}/audit-log", limit=100
):
print(row["ts"], row["action"], row["target"])
for await (const row of evigauge.paginate(
"/v1/observ/orgs/{org}/workspaces/{ws}/audit-log", { limit: 100 },
)) {
console.log(row.ts, row.action, row.target);
}