Skip to content

Audit Log API & Streaming

The audit log records which actor changed which resource, and how - see Audit logs. Besides reading it in the dashboard, you can hand it to your own systems in two ways:

Audit log APIStreaming
DirectionYour system pullsTrustComponent pushes every new event
Typical useArchiving, periodic imports, own reportsSIEM and log platforms, real-time alerting
PlanGovernance add-onGovernance Enterprise add-on

Both deliver an event in the same JSON format, so one parser handles both.

  1. Create an API key. In your Project, open Settings → API Keys and choose Create API Key. For an Organization, open Governance → Audit Logs; the organization keys are listed there.

  2. Call the API with the key as bearer token:

    Terminal window
    curl -H "Authorization: Bearer ak_..." \
    "https://api.trustcomponent.com/platform/v1/events?from=2026-09-01T00:00:00.000Z&to=2026-09-02T00:00:00.000Z&pageSize=100"
  3. Read the next page by passing the nextCursor of the response as cursor, with the same from and to, until nextCursor is null.

A Project key returns the events of the Project and of all its modules. An Organization key returns the events of the Organization itself, not the ones of its client projects.

ParameterDefaultMeaning
from24 hours before toStart of the time range, ISO 8601 in UTC
tonowEnd of the time range, ISO 8601 in UTC
cursor–Position to continue after, taken from nextCursor of the previous response
pageSize100Entries per page, at most 1000
page0Zero-based page index, ignored when cursor is set

Events are sorted newest first. Read a range with the cursor: unlike page, it does not shift when new events arrive while you read. Events older than the audit retention of your plan are not returned.

{
"from": "2026-09-01T00:00:00.000Z",
"to": "2026-09-02T00:00:00.000Z",
"content": [
{
"id": "cc2e2d5e-d1ef-4a7f-a7bd-dec5b37df47a",
"schemaVersion": 2,
"occurredAt": "2026-09-01T13:30:05.941Z",
"type": "captcha.captcha.updated",
"action": "updated",
"subject": { "kind": "captcha.captcha", "id": "0f8e...", "label": "Checkout form" },
"scopes": [{ "kind": "platform.subscription", "id": "5664...", "label": "Initech" }],
"origin": { "namespace": "CAPTCHA", "source": "REST_CONTROLLER", "applicationName": "tc-captcha-captchaservice", "traceId": "a1b2...", "transactionId": "e5f6..." },
"actor": { "type": "USER", "userId": "b1c2...", "apiKeyId": null, "automation": null },
"changes": [{ "field": "label", "operation": "SET", "before": "Checkout", "after": "Checkout form", "isRedacted": false }],
"details": {}
}
],
"page": 0,
"pageSize": 100,
"totalElements": 1,
"nextCursor": null
}
FieldMeaning
idUnique id of the event. An event is never delivered with two different ids, so use it to skip duplicates.
schemaVersion2 for events since API keys, automations and anonymous callers are told apart; 1 for older events, which only know USER and SYSTEM.
typeKind of the subject followed by the action, for example platform.user.authentication-failed.
subject / scopesThe resource the action happened to, and the resources it belongs to. label is the name at the time of the event.
originWhere in TrustComponent the event was recorded. Quote the traceId when you ask support about an event.
actorWho caused the event, see below.
changesThe fields the action changed. Secret values are never recorded; such a change has isRedacted: true.
detailsFacts about the action that are not a change of the subject: the sign-in method and masked IP address of a sign-in, the format and time range of an export.
Actor typeMeaning
USERA signed-in person, identified by userId.
API_KEYA request authenticated with an API key, identified by apiKeyId.
AUTOMATIONA process of TrustComponent that runs by itself: a scheduled job, a task at service start, or a reaction to another event. automation.kind is SCHEDULER, RUNNER or LISTENER, automation.name names the job.
ANONYMOUSA caller that is not signed in, for example a failed sign-in or a password reset through the link in an e-mail.
SYSTEMTrustComponent itself, when no more specific actor applies.
StatusMeaning
401No API key sent
402The plan does not include the audit log API, or the Project is locked
403Unknown or expired API key
422from or to is not an ISO 8601 timestamp, from lies after to, or cursor was not returned by this API

Streaming sends every new audit log event as one JSON document - exactly the event format of the API above - by HTTPS POST to a destination of your choice. Deliveries that fail are retried several times.

  1. Open Governance → Audit Logs and choose New Destination in the Streaming section.
  2. Pick the type and fill in the fields below.
  3. Open the menu of the destination and choose Send test event. You see right away whether your platform accepted it.

Create an HTTP Event Collector token in Splunk and enter the address of the collector (for example https://splunk.example.com:8088) and the token. TrustComponent sends to /services/collector/raw?sourcetype=_json with the header Authorization: Splunk <token>. If your collector requires indexer acknowledgement, edit the destination afterwards and add the header X-Splunk-Request-Channel.

A delivery that is retried keeps its body, so use the id of the event to skip one you already stored. Every request carries the headers TC-Webhook-Id, TC-Webhook-Event (platform.audit-event.created, or platform.export-destination.test for a test event) and TC-Webhook-Timestamp. TC-Webhook-Signature has the form t=<timestamp>,v1=<signature>, where the signature is the hex-encoded HMAC-SHA256 of <timestamp>.<body> with the signing secret shown when you edit the destination. Check it if your endpoint is reachable from the internet.

If your plan no longer includes streaming, existing destinations are suspended: they receive nothing, and you can only pause or delete them. After an upgrade, active destinations continue on their own.