Skip to content

Audit Log API

The audit log API lets your own systems read the audit log of a project or an agency — for archiving, periodic imports or your own reports. To have every new event pushed to you instead, use streaming; both deliver the same event format.

GET https://api.trustcomponent.com/platform/v1/events

Whether the API is available depends on your plan and add-ons; see Current add-ons.

  1. Create an API key. In a project, open Settings › API Keys & Webhooks and choose Create API Key (Member role). In an agency, open Settings › API Keys (Auditor role).

  2. Call the API with the key as bearer token:

    Terminal window
    curl -H "Authorization: Bearer ak_..." \
    "https://api.trustcomponent.com/platform/v1/events?from=2026-09-01T00:00:00.000Z&to=2026-09-02T00:00:00.000Z&pageSize=100"
  3. Read the next page by passing the nextCursor of the response as cursor, with the same from and to, until nextCursor is null.

A project key returns the events of the project and of all its modules. An agency key returns the events of the agency itself, not those of its client projects.

ParameterDefaultMeaning
from24 hours before toStart of the time range, ISO 8601 in UTC
tonowEnd of the time range, ISO 8601 in UTC
cursor–Position to continue after, taken from nextCursor of the previous response
pageSize100Entries per page, at most 1000
page0Zero-based page index, ignored when cursor is set

Events are sorted newest first. Read a range with the cursor: unlike page, it does not shift when new events arrive while you read. Events older than the audit retention of your plan are not returned.

{
"from": "2026-09-01T00:00:00.000Z",
"to": "2026-09-02T00:00:00.000Z",
"content": [
{
"id": "cc2e2d5e-d1ef-4a7f-a7bd-dec5b37df47a",
"schemaVersion": 2,
"occurredAt": "2026-09-01T13:30:05.941Z",
"type": "captcha.captcha.updated",
"action": "updated",
"subject": { "kind": "captcha.captcha", "id": "0f8e...", "label": "Checkout form" },
"scopes": [{ "kind": "platform.subscription", "id": "5664...", "label": "Initech" }],
"origin": { "namespace": "CAPTCHA", "source": "REST_CONTROLLER", "applicationName": "tc-captcha-captchaservice", "traceId": "a1b2...", "transactionId": "e5f6..." },
"actor": { "type": "USER", "userId": "b1c2...", "apiKeyId": null, "automation": null },
"changes": [{ "field": "label", "operation": "SET", "before": "Checkout", "after": "Checkout form", "isRedacted": false }],
"details": {}
}
],
"page": 0,
"pageSize": 100,
"totalElements": 1,
"nextCursor": null
}
FieldMeaning
idUnique id of the event. An event is never delivered with two different ids, so use it to skip duplicates.
schemaVersion2 for events since API keys, automations and anonymous callers are told apart; 1 for older events, which only know USER and SYSTEM.
typeKind of the subject followed by the action, for example platform.user.authentication-failed.
subject / scopesThe resource the action happened to, and the resources it belongs to. label is the name at the time of the event. Kinds use internal names: platform.subscription is a project, platform.organization an agency.
originWhere in TrustComponent the event was recorded. Quote the traceId when you ask support about an event.
actorWho caused the event, see below.
changesThe fields the action changed. Secret values are never recorded; such a change has isRedacted: true.
detailsFacts about the action that are not a change of the subject: the sign-in method and masked IP address of a sign-in, the format and time range of an export.
Actor typeMeaning
USERA signed-in person, identified by userId.
API_KEYA request authenticated with an API key, identified by apiKeyId.
AUTOMATIONA process of TrustComponent that runs by itself: a scheduled job, a task at service start, or a reaction to another event. automation.kind is SCHEDULER, RUNNER or LISTENER, automation.name names the job.
ANONYMOUSA caller that is not signed in, for example a failed sign-in or a password reset through the link in an e-mail.
SYSTEMTrustComponent itself, when no more specific actor applies.
StatusMeaning
401No API key sent
402The plan does not include the audit log API, or the project is locked
403Unknown or expired API key
422from or to is not an ISO 8601 timestamp, from lies after to, or cursor was not returned by this API