List authz decision audit events
const url = 'https://example.com/v1/audit/authz?limit=25&outcome=allowed';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/audit/authz?limit=25&outcome=allowed' \ --header 'Authorization: Bearer <token>'Cursor-paginated read of authz-decision audit events for the tenant. Filters (all AND-composed): ?actorSubject= / ?onBehalfOf= / ?action= / ?resource= / ?outcome= / ?runId= / ?from= / ?to=. Admin@tenant only. Only mounted when CreateAppInput.auditEvents is wired.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
Filter to decisions issued for this actor (user:... / agent:...).
Filter to delegated decisions on-behalf-of this subject.
Filter by action verb (read | write | admin | execute | …).
Filter to decisions on this fully-qualified resource (type:id).
Restrict to allowed or denied decisions.
Filter to decisions issued inside this run.
ISO 8601 lower bound (inclusive) on timestamp.
ISO 8601 upper bound (inclusive) on timestamp.
Responses
Section titled “Responses”Page of authz decision audit events.
object
object
object
Example
{ "data": [ { "outcome": "allowed" } ]}Malformed cursor, from, to, or outcome.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}