Porta v1.11.0
Skip to content

Audit Log API ​

View the audit trail of administrative and security events.

Base path: /api/admin/audit

List Audit Events ​

http
GET /api/admin/audit

Query parameters:

ParameterTypeDescription
limitintegerMax results to return (default: 50, max: 500)
eventstringFilter by event_type
orguuidFilter by organization_id
useruuidFilter by user_id
sinceISO 8601Filter events after this date

Response: 200 OK

json
{
  "data": [
    {
      "id": "event-uuid",
      "eventType": "organization.created",
      "eventCategory": "admin",
      "actorId": "user-uuid",
      "organizationId": "org-uuid",
      "userId": "user-uuid",
      "description": "Organization created",
      "metadata": {
        "name": "Acme Corp",
        "slug": "acme-corp"
      },
      "ipAddress": "192.168.1.1",
      "createdAt": "2024-01-15T10:30:00.000Z"
    }
  ],
  "total": 156
}

Audit Event Types ​

Organization Events ​

ActionDescription
organization.createdNew organization created
organization.updatedOrganization details updated
organization.suspendedOrganization suspended
organization.activatedOrganization reactivated
org.deletedOrganization deleted
organization.branding_updatedBranding settings changed

User Events ​

ActionDescription
user.createdNew user created
user.invitedInvitation created (no user record yet)
user.updatedUser profile updated
user.deactivatedUser deactivated
user.activatedUser activated
user.deletedUser deleted
user.password_changedPassword changed
user.login_successSuccessful login
user.login_failureFailed login attempt

Client Events ​

ActionDescription
client.createdNew OIDC client created
client.updatedClient configuration updated
client.deletedClient deleted
client.secret_generatedNew client secret generated
client.secret_revokedClient secret revoked

RBAC Events ​

ActionDescription
role.createdNew role created
role.updatedRole updated
role.deletedRole deleted
permission.deletedPermission deleted
role.permission_assignedPermission assigned to role
role.permission_removedPermission removed from role
user.role_assignedRole assigned to user
user.role_removedRole removed from user

Security Events ​

ActionDescription
security.login_method_disabledAttempted login via disabled method
security.2fa_enabled2FA enabled for user
security.2fa_disabled2FA disabled for user
security.rate_limitedRate limit triggered

Data Export and Deletion Events ​

ActionDescription
user.data_exportedUser data exported (GDPR Article 20)
app.deletedApplication deleted
app.module.deletedApplication module deleted
claim.deletedClaim definition deleted

Account Lockout Events ​

ActionDescription
user.auto_lockedAccount auto-locked after failed login threshold
user.auto_unlockedAccount auto-unlocked after cooldown expired

Audit durability

Compatibility audit events remain best-effort and do not change the public operation result. Authorized administrative mutations also write a required business audit row in the same PostgreSQL transaction as their database changes. Import is atomic: an audit failure rolls back the manifest and returns a minimal service-unavailable response. Bulk processing is intentionally per-item: an audit failure rolls back the current item, preserves earlier committed items, marks the current and remaining items not_attempted, and returns the ordered partial result with one correlation identifier.

Audit Retention & Cleanup ​

Porta supports configurable audit log retention with automatic cleanup of old entries.

Configure Retention ​

The retention period is managed via the audit_retention_days system configuration key:

bash
# Set retention to 365 days
porta config set --key audit_retention_days --value 365

Cleanup Old Entries ​

http
DELETE /api/admin/audit/cleanup

Deletes audit log entries older than the configured audit_retention_days value.

Response: 200 OK

json
{
  "deleted": 1542,
  "retentionDays": 365,
  "cutoffDate": "2025-04-21T00:00:00.000Z"
}

WARNING

Audit cleanup is irreversible. Ensure your retention period meets your compliance requirements before running cleanup. Consider exporting old audit data to cold storage before purging.

Released under the MIT License.