curl -s \
"https://engine.example.com/v1/audit-log?limit=100" \
-H "Authorization: Bearer $TOKEN"
# The feed's next is never null: poll with the last.// A client from OpenAPI Generator: see Build a client.
import {
ApprovalsAndOperationsApi,
Configuration,
ProblemFromJSON,
ResponseError,
} from "./nodeasset-client";
const api = new ApprovalsAndOperationsApi(new Configuration({
basePath: "https://engine.example.com",
accessToken: process.env.TOKEN,
}));
try {
// The feed's next is never null: poll with the last.
let after: string | undefined;
for (;;) {
const page = await api.listAuditLog({ limit: 100, after });
for (const auditLogEntry of page.value ?? []) {
console.log(auditLogEntry);
}
after = page.next ?? after;
if (!page.value?.length) {
await new Promise((resolve) => setTimeout(resolve, 5000));
}
}
} catch (e) {
if (!(e instanceof ResponseError)) throw e;
// A refusal is a problem; its type ends in the slug.
const problem = ProblemFromJSON(await e.response.json());
const slug = problem.type.split(":").pop();
console.error(e.response.status, slug, problem.detail);
}
# A client from OpenAPI Generator: see Build a client.
import os
import sys
import time
import nodeasset_client
config = nodeasset_client.Configuration(
host="https://engine.example.com",
access_token=os.environ["TOKEN"],
)
with nodeasset_client.ApiClient(config) as client:
api = nodeasset_client.ApprovalsAndOperationsApi(client)
try:
# The feed's next is never null: poll with the last.
after = None
while True:
page = api.list_audit_log(limit=100, after=after)
for audit_log_entry in page.value or []:
print(audit_log_entry)
after = page.next or after
if not page.value:
time.sleep(5)
except nodeasset_client.ApiException as e:
# A refusal is a problem; its type ends in the slug.
problem = nodeasset_client.Problem.from_json(e.body)
slug = problem.type.rsplit(":", 1)[-1]
print(e.status, slug, problem.detail, file=sys.stderr)
// A client from OpenAPI Generator: see Build a client.
import nodeasset.client.ApiClient;
import nodeasset.client.ApiException;
import nodeasset.client.api.ApprovalsAndOperationsApi;
import nodeasset.client.model.Problem;
public class ListAuditLog {
public static void main(String[] args) throws Exception {
ApiClient client = new ApiClient();
client.updateBaseUri("https://engine.example.com");
client.setRequestInterceptor(builder ->
builder.header("Authorization", "Bearer " + System.getenv("TOKEN")));
ApprovalsAndOperationsApi api = new ApprovalsAndOperationsApi(client);
try {
// The feed's next is never null: poll with the last.
String after = null;
while (true) {
var request = ApprovalsAndOperationsApi.APIListAuditLogRequest.newBuilder()
.limit(100)
.after(after)
.build();
var page = api.listAuditLog(request);
for (var auditLogEntry : page.getValue()) {
System.out.println(auditLogEntry);
}
if (page.getNext() != null) after = page.getNext();
if (page.getValue().isEmpty()) Thread.sleep(5000);
}
} catch (ApiException e) {
// A refusal is a problem; its type ends in the slug.
Problem problem = client.getObjectMapper()
.readValue(e.getResponseBody(), Problem.class);
String type = problem.getType();
String slug = type.substring(type.lastIndexOf(':') + 1);
System.err.println(e.getCode() + " " + slug + " " + problem.getDetail());
}
}
}
{
"offset": 0,
"now": "2026-10-03T13:26:06.371593093Z",
"value": [
{
"seq": 204,
"operationId": "op-75d03649-97a5-4282-b94d-502def0221d9",
"state": "succeeded",
"at": "2026-10-03T13:25:50.017130Z",
"entry": "{\"actor\":\"operator-1\",\"at\":\"2026-10-03T13:25:50.017130363Z\",\"kind\":\"webhook.register\",\"operationId\":\"op-75d03649-97a5-4282-b94d-502def0221d9\",\"outcome\":\"814b2829e30b9087d9ff853277e57b2336c3890968174469ca2b3764b8dffdb5\",\"request\":\"d44ae6914216ff4ff70cd50b0c4ad1a210fbc61a42ec7e42a5d5eb39a739c6ec\",\"resourceId\":\"ops-alerts\",\"resourceKind\":\"webhook\",\"role\":\"operator\",\"state\":\"SUCCEEDED\"}",
"prevHash": "a784308accd1ecf896702285286fc3cb60be503b9a8b3ca1fc0bc3f053fe2d07",
"hash": "cd70c1340d4a237c19d3ace3f902fed63fde01477397afbd95d802ddf7f4433c"
}
],
"next": "204"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}List the audit log
Lists the audit log, oldest first: every change of an operation’s state, hash-chained.
curl -s \
"https://engine.example.com/v1/audit-log?limit=100" \
-H "Authorization: Bearer $TOKEN"
# The feed's next is never null: poll with the last.// A client from OpenAPI Generator: see Build a client.
import {
ApprovalsAndOperationsApi,
Configuration,
ProblemFromJSON,
ResponseError,
} from "./nodeasset-client";
const api = new ApprovalsAndOperationsApi(new Configuration({
basePath: "https://engine.example.com",
accessToken: process.env.TOKEN,
}));
try {
// The feed's next is never null: poll with the last.
let after: string | undefined;
for (;;) {
const page = await api.listAuditLog({ limit: 100, after });
for (const auditLogEntry of page.value ?? []) {
console.log(auditLogEntry);
}
after = page.next ?? after;
if (!page.value?.length) {
await new Promise((resolve) => setTimeout(resolve, 5000));
}
}
} catch (e) {
if (!(e instanceof ResponseError)) throw e;
// A refusal is a problem; its type ends in the slug.
const problem = ProblemFromJSON(await e.response.json());
const slug = problem.type.split(":").pop();
console.error(e.response.status, slug, problem.detail);
}
# A client from OpenAPI Generator: see Build a client.
import os
import sys
import time
import nodeasset_client
config = nodeasset_client.Configuration(
host="https://engine.example.com",
access_token=os.environ["TOKEN"],
)
with nodeasset_client.ApiClient(config) as client:
api = nodeasset_client.ApprovalsAndOperationsApi(client)
try:
# The feed's next is never null: poll with the last.
after = None
while True:
page = api.list_audit_log(limit=100, after=after)
for audit_log_entry in page.value or []:
print(audit_log_entry)
after = page.next or after
if not page.value:
time.sleep(5)
except nodeasset_client.ApiException as e:
# A refusal is a problem; its type ends in the slug.
problem = nodeasset_client.Problem.from_json(e.body)
slug = problem.type.rsplit(":", 1)[-1]
print(e.status, slug, problem.detail, file=sys.stderr)
// A client from OpenAPI Generator: see Build a client.
import nodeasset.client.ApiClient;
import nodeasset.client.ApiException;
import nodeasset.client.api.ApprovalsAndOperationsApi;
import nodeasset.client.model.Problem;
public class ListAuditLog {
public static void main(String[] args) throws Exception {
ApiClient client = new ApiClient();
client.updateBaseUri("https://engine.example.com");
client.setRequestInterceptor(builder ->
builder.header("Authorization", "Bearer " + System.getenv("TOKEN")));
ApprovalsAndOperationsApi api = new ApprovalsAndOperationsApi(client);
try {
// The feed's next is never null: poll with the last.
String after = null;
while (true) {
var request = ApprovalsAndOperationsApi.APIListAuditLogRequest.newBuilder()
.limit(100)
.after(after)
.build();
var page = api.listAuditLog(request);
for (var auditLogEntry : page.getValue()) {
System.out.println(auditLogEntry);
}
if (page.getNext() != null) after = page.getNext();
if (page.getValue().isEmpty()) Thread.sleep(5000);
}
} catch (ApiException e) {
// A refusal is a problem; its type ends in the slug.
Problem problem = client.getObjectMapper()
.readValue(e.getResponseBody(), Problem.class);
String type = problem.getType();
String slug = type.substring(type.lastIndexOf(':') + 1);
System.err.println(e.getCode() + " " + slug + " " + problem.getDetail());
}
}
}
{
"offset": 0,
"now": "2026-10-03T13:26:06.371593093Z",
"value": [
{
"seq": 204,
"operationId": "op-75d03649-97a5-4282-b94d-502def0221d9",
"state": "succeeded",
"at": "2026-10-03T13:25:50.017130Z",
"entry": "{\"actor\":\"operator-1\",\"at\":\"2026-10-03T13:25:50.017130363Z\",\"kind\":\"webhook.register\",\"operationId\":\"op-75d03649-97a5-4282-b94d-502def0221d9\",\"outcome\":\"814b2829e30b9087d9ff853277e57b2336c3890968174469ca2b3764b8dffdb5\",\"request\":\"d44ae6914216ff4ff70cd50b0c4ad1a210fbc61a42ec7e42a5d5eb39a739c6ec\",\"resourceId\":\"ops-alerts\",\"resourceKind\":\"webhook\",\"role\":\"operator\",\"state\":\"SUCCEEDED\"}",
"prevHash": "a784308accd1ecf896702285286fc3cb60be503b9a8b3ca1fc0bc3f053fe2d07",
"hash": "cd70c1340d4a237c19d3ace3f902fed63fde01477397afbd95d802ddf7f4433c"
}
],
"next": "204"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"requestId": "<string>",
"gate": "<string>",
"check": "<string>",
"recovery": "<string>",
"retryAfter": 123,
"retryable": true,
"packageName": "<string>",
"party": "<string>",
"contractId": "<string>",
"projectionOffset": 123,
"ledgerEnd": 123,
"code": 123,
"reason": "<string>",
"policyVersion": 123,
"errors": [
{
"pointer": "<string>",
"detail": "<string>"
}
]
}auditor, operator.Authorizations
A JWT from the deployment's identity provider, whose roles claim names the caller's roles and whose holder claim names an investor's holder.
Headers
A signed request's key id, as venue.api.signing.clients configures it for the bearer's subject.
Seconds since the epoch, within venue.api.signing.window of the engine's clock, 5 minutes by default.
^[0-9]+$At least 16 random bytes in base64url, never reused within twice the window.
22 - 128^[A-Za-z0-9_-]+={0,2}$The base64 HMAC-SHA256, under the key's secret, of the method, the path and query, the timestamp, the nonce and the body's SHA-256.
Your id for this request, 1 to 128 printable characters, repeated in the answer; absent, the engine makes one.
128^[\x21-\x7E]+$A W3C trace context, which the engine joins and passes on.
^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$Query Parameters
The most records a page holds, 1 to 1000; 100 by default.
1 <= x <= 1000The previous page's next; absent, the first page.
Response
The entries.
The ledger offset the answer was read at; 0 for an answer from the engine's own records.
The engine's clock when it answered, an ISO-8601 instant.
What the read answers; for a list, the page's records in the list's order.
Show child attributes
Show child attributes
The cursor for the next page, sent back as after; null on a list's last page, never on a feed.

