EvoHub Docs Sign in

EvoTrail API › Audit trail

Count the audit trail by dimension

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}
GET/api/v1/evotrail/audit/facets

How many events match the filters, counted by product, action, actor, actor type, resource type, class and team. Each dimension is counted without its own filter, so the other values stay visible. Actions, actors, resource types and teams list the top 50.

Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read.

Authorization

Any one of:

Parameters

Query parameters

  • product array of Product
    Only these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.
  • actor_id string
    Who did it: a user, API key or agent id.
    Max length: 200
  • actor_type string
    One of: user api_key agent system evohub_staff
  • action string
    An exact action, or a prefix ending in * (alert.*). Lower case, digits, _ and ..
    Example: member.* · Max length: 200 · Pattern: ^[a-z0-9_.]+\*?$
  • resource_type string
    Max length: 200
  • resource_id string
    Max length: 200
  • team_id string
    Events on resources of this team.
    Max length: 200
  • request_id string
    Every event one API request caused.
    Max length: 200
  • ip string
    An IPv4 or IPv6 address.
  • class string
    One of: audit activity
  • from string
    YYYY-MM-DD (UTC) or RFC 3339. Default 30 days before to.
    Example: 2026-09-10
  • to string
    YYYY-MM-DD (inclusive) or RFC 3339. Default now.
    Example: 2026-10-09

Responses

200

Counts per dimension.

Content type: application/json

Type: object

  • data object required
    • products array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • actions array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • actors array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • actor_types array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • resource_types array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • classes array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    • teams array of Facet
      Show Facet properties
      • value string
      • label string
        A display name, for actors.
      • count integer
    Other keys: array of Facet
  • success boolean required
    Value: true

400

A range or filter is not valid (VALIDATION_ERROR); the message names it.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

401

No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

403

The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

429

Too many requests (RATE_LIMITED). Wait Retry-After seconds.

Headers

  • Retry-After integer
    Seconds to wait.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

500

Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

Example request

curl -X GET 'https://evohub.io/api/v1/evotrail/audit/facets' \
  -H 'Authorization: Bearer <TOKEN>'

Last updated