Skip to content

Audit

Your audit trail

audit:read
ParameterInTypeRequiredDescription
categoryquerystringNoauth | autorisation | medlemskab | session | sikkerhed | gdpr | databrug
typequerystringNoThe domain’s own event name, e.g. eksternt_api_kald
outcomequerystringNosucces | fejl | blokeret — a blocked attempt is evidence too
caseIdquerystringNoOnly entries tied to this collection case
correlationIdquerystringNoEverything that happened under one request
limitqueryintegerNoPage size, 1-200 (default 50)
cursorquerystringNoOpaque cursor from meta.nextCursor
Request exampleNo request body
curl https://api.rieckflow.com/v1/audit \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Newest first. Each entry carries sequence (monotonic insertion order), category, type, outcome, actorUserId, correlationId, purpose (for data-use entries) and the domain’s own metadata. ⚠️ Append-only and hash-chained: entries are never edited or deleted, not by us and not by you — the database grants this API read access and nothing else. Names are not included; resolve actorUserId with /v1/members if you need one. IP addresses and user agents are deliberately not exposed.application/json
Possible errors 5
HTTPCodeMeaning
400invalid_cursorThe cursor is malformed, expired or belongs to another list shape.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Verify the hash chain

audit:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/audit/integrity \
-H "Authorization: Bearer $RIECK_API_KEY"
200 intact, the sequence numbers where the chain does not link (brokenAt), and how many entries there are. ⚠️ This is what makes an audit trail more than a list: every row carries the hash of the one before it, so you can prove the log is the same as when it was written rather than taking our word for it. The hashes themselves are not exposed — they are the chain’s mechanics.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.