Audit Log API
The audit log API lets your own systems read the audit log of a project or an agency — for archiving, periodic imports or your own reports. To have every new event pushed to you instead, use streaming; both deliver the same event format.
GET https://api.trustcomponent.com/platform/v1/eventsWhether the API is available depends on your plan and add-ons; see Current add-ons.
Reading events
Section titled “Reading events”Create an API key. In a project, open Settings › API Keys & Webhooks and choose Create API Key (Member role). In an agency, open Settings › API Keys (Auditor role).
Call the API with the key as bearer token:
Terminal window curl -H "Authorization: Bearer ak_..." \"https://api.trustcomponent.com/platform/v1/events?from=2026-09-01T00:00:00.000Z&to=2026-09-02T00:00:00.000Z&pageSize=100"Read the next page by passing the
nextCursorof the response ascursor, with the samefromandto, untilnextCursorisnull.
A project key returns the events of the project and of all its modules. An agency key returns the events of the agency itself, not those of its client projects.
| Parameter | Default | Meaning |
|---|---|---|
from | 24 hours before to | Start of the time range, ISO 8601 in UTC |
to | now | End of the time range, ISO 8601 in UTC |
cursor | – | Position to continue after, taken from nextCursor of the previous response |
pageSize | 100 | Entries per page, at most 1000 |
page | 0 | Zero-based page index, ignored when cursor is set |
Events are sorted newest first. Read a range with the cursor: unlike page, it does not shift when new events arrive while you read. Events older than the audit retention of your plan are not returned.
{ "from": "2026-09-01T00:00:00.000Z", "to": "2026-09-02T00:00:00.000Z", "content": [ { "id": "cc2e2d5e-d1ef-4a7f-a7bd-dec5b37df47a", "schemaVersion": 2, "occurredAt": "2026-09-01T13:30:05.941Z", "type": "captcha.captcha.updated", "action": "updated", "subject": { "kind": "captcha.captcha", "id": "0f8e...", "label": "Checkout form" }, "scopes": [{ "kind": "platform.subscription", "id": "5664...", "label": "Initech" }], "origin": { "namespace": "CAPTCHA", "source": "REST_CONTROLLER", "applicationName": "tc-captcha-captchaservice", "traceId": "a1b2...", "transactionId": "e5f6..." }, "actor": { "type": "USER", "userId": "b1c2...", "apiKeyId": null, "automation": null }, "changes": [{ "field": "label", "operation": "SET", "before": "Checkout", "after": "Checkout form", "isRedacted": false }], "details": {} } ], "page": 0, "pageSize": 100, "totalElements": 1, "nextCursor": null}| Field | Meaning |
|---|---|
id | Unique id of the event. An event is never delivered with two different ids, so use it to skip duplicates. |
schemaVersion | 2 for events since API keys, automations and anonymous callers are told apart; 1 for older events, which only know USER and SYSTEM. |
type | Kind of the subject followed by the action, for example platform.user.authentication-failed. |
subject / scopes | The resource the action happened to, and the resources it belongs to. label is the name at the time of the event. Kinds use internal names: platform.subscription is a project, platform.organization an agency. |
origin | Where in TrustComponent the event was recorded. Quote the traceId when you ask support about an event. |
actor | Who caused the event, see below. |
changes | The fields the action changed. Secret values are never recorded; such a change has isRedacted: true. |
details | Facts about the action that are not a change of the subject: the sign-in method and masked IP address of a sign-in, the format and time range of an export. |
Actor type | Meaning |
|---|---|
USER | A signed-in person, identified by userId. |
API_KEY | A request authenticated with an API key, identified by apiKeyId. |
AUTOMATION | A process of TrustComponent that runs by itself: a scheduled job, a task at service start, or a reaction to another event. automation.kind is SCHEDULER, RUNNER or LISTENER, automation.name names the job. |
ANONYMOUS | A caller that is not signed in, for example a failed sign-in or a password reset through the link in an e-mail. |
SYSTEM | TrustComponent itself, when no more specific actor applies. |
| Status | Meaning |
|---|---|
401 | No API key sent |
402 | The plan does not include the audit log API, or the project is locked |
403 | Unknown or expired API key |
422 | from or to is not an ISO 8601 timestamp, from lies after to, or cursor was not returned by this API |