# Get one audit event

`GET https://evohub.io/api/v1/evotrail/audit/{id}`

Part of the [EvoTrail API](https://docs-dev.evohub.io/evotrail.md) reference · operationId `getAuditEvent`.

One event with `before`, `after` and `metadata`. An event of a product the key
may not read answers 404, as if it did not exist.

**Permission (API-key scope):** `evotrail:audit:read`. The event's product also needs its `*:audit:read`.

## Authorization

Any one of:

- `bearerAuth` (evotrail:audit:read)
- `apiKeyHeader` (evotrail:audit:read)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required, max length 200): The id named by the path: an audit event's id (a UUID) under `/audit`, a status page's or a docs or changelog site's id under `/metrics`.

## Responses

### 200 — The event.

Content type: `application/json`

Type: `object`

- `data` (AuditEvent, required)
  - `id` (string (uuid), required)
  - `event_id` (string, required): The producing product's own id for the event.
  - `source` (string, required): The service that reported it.
  - `product` (Product, required, one of `organization`, `oncall`, `uptime`, `status`, `docs`, `changelog`, `board`, `retro`, `support`, `catalog`, `evotrail`)
  - `team_id` (string | null): The team the resource belongs to.
  - `actor` (object, required)
    - `type` (string, one of `user`, `api_key`, `agent`, `system`, `evohub_staff`)
    - `id` (string | null)
    - `name` (string | null)
    - `teams` (array of string | null)
  - `action` (string, required): `<resource>.<verb>`, for example `alert.acknowledged` or `member.role_changed`.
  - `class` (string, required, one of `audit`, `activity`): `audit` is a change to configuration or access (kept 365 days); `activity` is day-to-day work (kept 90 days).
  - `resource` (object, required)
    - `type` (string | null)
    - `id` (string | null)
    - `name` (string | null)
  - `request_id` (string | null)
  - `ip` (string | null): Kept 90 days.
  - `user_agent` (string | null): Kept 90 days.
  - `occurred_at` (string (date-time), required)
  - `has_details` (boolean, required): Whether `before`, `after` or `metadata` exist; read the single event to get them.
  - `before` (any): The resource before the change (single-event read only). Secrets are masked by the producer.
  - `after` (any): The resource after the change (single-event read only).
  - `metadata` (any): Anything else the product recorded (single-event read only).
- `success` (boolean, required, value `true`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 403 — The key lacks the EvoTrail scope, or may read none of the products asked for (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 404 — No such event, or one the key may not read (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/evotrail/audit/string' \
  -H 'Authorization: Bearer <TOKEN>'
```
