EvoHub Docs Sign in

EvoTrail API › Audit trail

Search the audit trail

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}
GET/api/v1/evotrail/audit

Events from every product the key may read, newest first. Filters combine. Paged by cursor: pass next_cursor back as cursor while has_more is true. The list rows leave out before, after and metadata; read one event for those.

Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read; Catalog's rows are for owners and administrators only.

Authorization

Any one of:

Parameters

Query parameters

  • product array of Product
    Only these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.
  • actor_id string
    Who did it: a user, API key or agent id.
    Max length: 200
  • actor_type string
    One of: user api_key agent system evohub_staff
  • action string
    An exact action, or a prefix ending in * (alert.*). Lower case, digits, _ and ..
    Example: member.* · Max length: 200 · Pattern: ^[a-z0-9_.]+\*?$
  • resource_type string
    Max length: 200
  • resource_id string
    Max length: 200
  • team_id string
    Events on resources of this team.
    Max length: 200
  • request_id string
    Every event one API request caused.
    Max length: 200
  • ip string
    An IPv4 or IPv6 address.
  • class string
    One of: audit activity
  • from string
    YYYY-MM-DD (UTC) or RFC 3339. Default 30 days before to.
    Example: 2026-09-10
  • to string
    YYYY-MM-DD (inclusive) or RFC 3339. Default now.
    Example: 2026-10-09
  • limit integer
    Default: 50 · Minimum: 1 · Maximum: 200
  • cursor string
    next_cursor from the previous page.

Responses

200

A page of events.

Content type: application/json

Type: object

  • data object required
    • items array of AuditEvent
      Show AuditEvent properties
      • id string (uuid) required
      • event_id string required
        The producing product's own id for the event.
      • source string required
        The service that reported it.
      • product Product required
        One of: organization oncall uptime status docs changelog board retro support catalog evotrail
      • team_id string | null
        The team the resource belongs to.
      • actor object required
        • type string
          One of: user api_key agent system evohub_staff
        • id string | null
        • name string | null
        • teams array of string | null
      • action string required
        <resource>.<verb>, for example alert.acknowledged or member.role_changed.
      • class string required
        audit is a change to configuration or access (kept 365 days); activity is day-to-day work (kept 90 days).
        One of: audit activity
      • resource object required
        • type string | null
        • id string | null
        • name string | null
      • request_id string | null
      • ip string | null
        Kept 90 days.
      • user_agent string | null
        Kept 90 days.
      • occurred_at string (date-time) required
      • has_details boolean required
        Whether before, after or metadata exist; read the single event to get them.
      • before any
        The resource before the change (single-event read only). Secrets are masked by the producer.
      • after any
        The resource after the change (single-event read only).
      • metadata any
        Anything else the product recorded (single-event read only).
    • next_cursor string
      Absent on the last page.
    • has_more boolean
    • products array of Product
      The products searched.
    • from string (date-time)
    • to string (date-time)
  • success boolean required
    Value: true

400

A range or filter is not valid (VALIDATION_ERROR); the message names it.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

401

No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

403

The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

429

Too many requests (RATE_LIMITED). Wait Retry-After seconds.

Headers

  • Retry-After integer
    Seconds to wait.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

500

Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

Example request

curl -X GET 'https://evohub.io/api/v1/evotrail/audit' \
  -H 'Authorization: Bearer <TOKEN>'

Last updated