Audit
GET /v1/audit
Section titled “GET /v1/audit”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
category | query | string | No | auth | autorisation | medlemskab | session | sikkerhed | gdpr | databrug |
type | query | string | No | The domain’s own event name, e.g. eksternt_api_kald |
outcome | query | string | No | succes | fejl | blokeret — a blocked attempt is evidence too |
caseId | query | string | No | Only entries tied to this collection case |
correlationId | query | string | No | Everything that happened under one request |
limit | query | integer | No | Page size, 1-200 (default 50) |
cursor | query | string | No | Opaque cursor from meta.nextCursor |
Request exampleNo request body
curl https://api.rieckflow.com/v1/audit \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/audit");{ "data": [ {} ], "meta": { "nextCursor": null }}200 Newest first. Each entry carries
sequence (monotonic insertion order), category, type, outcome, actorUserId, correlationId, purpose (for data-use entries) and the domain’s own metadata. ⚠️ Append-only and hash-chained: entries are never edited or deleted, not by us and not by you — the database grants this API read access and nothing else. Names are not included; resolve actorUserId with /v1/members if you need one. IP addresses and user agents are deliberately not exposed.application/jsonPossible errors 5
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_cursor | The cursor is malformed, expired or belongs to another list shape. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/audit/integrity
Section titled “GET /v1/audit/integrity”Request exampleNo request body
curl https://api.rieckflow.com/v1/audit/integrity \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/audit/integrity");{ "data": {}}200
intact, the sequence numbers where the chain does not link (brokenAt), and how many entries there are. ⚠️ This is what makes an audit trail more than a list: every row carries the hash of the one before it, so you can prove the log is the same as when it was written rather than taking our word for it. The hashes themselves are not exposed — they are the chain’s mechanics.application/jsonPossible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |