Audit Event

The audit_event object

An immutable record of a single change to a resource, capturing who made the change, what changed, and when.

Audit events are recorded automatically as mutations happen; they cannot be created, edited, or deleted through the API. Recording is asynchronous, so an event may take a moment to become readable after the request that caused it has returned. An update that leaves every tracked field at its existing value records no event unless the mutation attaches metadata of its own — a password rotation, for example, records metadata and no field changes.

idstring

Audit event ID.

objectstringenumValues:audit_event

Resource type identifier.

actionstringenumValues:createupdateupsert

The type of action this event records.

  • create: the resource was created.
  • update: one or more fields were changed.
  • delete: the resource was deleted.
  • restore: a previously deleted resource was restored.
  • archive: the resource was archived.
  • approve: a human approved a gated action, such as allowing a review-gated agent tool to run.
  • deny: a human denied a gated action, such as rejecting a review-gated agent tool.
resource_typestringenumValues:accountactorentity

Resource type of the audited entity.

resource_idstring

Audited resource ID.

actoractornullable

Actor who performed the mutation.

idstring

Unique identifier of the actor.

objectstringenumValues:actor

Resource type identifier.

typestringenumValues:userapi_keyagent

Actor type.

  • user: a human user account.
  • api_key: a programmatic caller authenticating with an API key.
  • agent: an automated agent acting on the account's behalf.
  • group: a shared group identity, such as a "Customer Service" persona, rather than a single individual.
namestringnullable

The actor's display name.

handlestringnullable

Human-readable handle identifying the actor.

  • For user actors: the user's email address.
  • For api_key actors: the redacted key value.

Other actor types carry no handle.

avatar_urlstringnullable

URL of the actor's profile photo, if one is set.

Only populated for user actors.

rolerolenullable

The role the actor holds in the account, which determines what it is permitted to do.

Always returned as null in this endpoint.
accountaccountnullable

Account the audited mutation was performed against.

For a mutation on one of your own resources this is your account; when you act on a customer's or supplier's account, it is that account.

idstring

Account ID.

objectstringenumValues:account

Resource type identifier.

namestring

The account's display name.

default_billing_addressaddressnullable

The address billed by default on orders for this account.

Always returned as null in this endpoint.
default_shipping_addressaddressnullable

The address shipped to by default on orders for this account.

Always returned as null in this endpoint.
brandingaccount_brandingnullable

Customer-facing branding for the account, such as the logo, support contacts, and social links.

Always returned as null in this endpoint.
portalaccount_portalnullable

The account's customer portal settings, including the portal URL slug.

Always returned as null in this endpoint.
created_atstring (date-time)

Creation timestamp.

updated_atstring (date-time)

Last updated timestamp.

changeslistnullable

Field-level changes recorded for this event.

Only fields OpenMRP tracks for that resource type are compared, and only those whose value actually differs are listed. Actions that do not alter stored fields, such as approve and deny, generally record no changes.

objectstringenumValues:list

Resource type identifier.

page_infoobject

Pagination metadata.

next_page_urlstringnullable

Relative URL that fetches the next page of results.

previous_page_urlstringnullable

Relative URL that fetches the previous page of results.

has_next_pageboolean

Whether more results exist after this page.

has_prev_pageboolean

Whether results exist before this page.

dataarray of audit_field_change

Resources in this page.

objectstringenumValues:audit_field_change

Resource type identifier.

fieldstring

Name of the changed field.

Field names come from the audited record's stored representation and can differ slightly from the corresponding field on the API resource — for example commission_policy_code rather than commission_policy.

old_valueobjectnullable

Previous value as a JSON fragment.

null on create events, where the field had no prior value.

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

new_valueobjectnullable

New value as a JSON fragment.

null on delete events, where the field has no remaining value.

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

metadataobjectnullable

Arbitrary JSON metadata for the mutation (e.g. reason, source, tags).

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

requestrequest_lognullable

Log of the API request that caused the mutation.

Changes that did not originate from an API request have no originating request log.

idstring

Request log ID.

objectstringenumValues:request_log

Resource type identifier.

methodstringenumValues:GETPOSTPUT

HTTP method.

hoststring

Request host.

Usually api.openmrp.ai.

pathstring

The exact path the request was made to, including path parameter values.

normalized_routestring

The route template the request matched, with path parameters left as placeholders.

For example /v1/sales/customers/{id} is the normalized route for the request path /v1/sales/customers/ac_.... Falls back to the raw path when the request did not match a registered route.

query_paramsobjectnullable

Query-string parameters the request was made with, as a JSON object.

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

status_codeinteger

HTTP response status code (e.g. 200, 404).

latency_usinteger

Request latency in microseconds.

Measured at the API edge, from the moment the request was received until the response was written, so it excludes network time between your client and OpenMRP.

api_versionstringnullable

The API version the request was served with.

Taken from the OpenMRP-Version header the caller sent; requests rejected for omitting that header record no version.

client_ipstringnullable

Client IP address the request came from.

Not recorded for requests an OpenMRP agent made on your behalf, since those originate inside OpenMRP's own network.

user_agentstringnullable

User agent.

referrerstringnullable

Referrer header.

error_codestringnullableenumValues:expired_tokenapi_key_expiredapi_key_revoked

Machine-readable API error code.

Matches the code of the error response the caller received. Populated only for failed requests.

error_messagestringnullable

Human-readable error message.

The same message the caller received. Populated only for failed requests.

occurred_atstring (date-time)

When the request was received.

Request logs are ordered and date-filtered by this timestamp rather than by created_at.

created_atstring (date-time)

When the log entry was written.

accountaccountnullable

Account targeted by the request: the account the request acted upon.

Results are scoped to logs where your account is either the acting account or the target account. Use the target_account_ids query parameter to filter by which account was acted upon, and actor_account_ids to filter by who acted.

Always returned as null in this endpoint.
actoractornullable

Actor who made the request.

Always returned as null in this endpoint.
idempotency_keystringnullable

User-provided idempotency key.

request_bodyobjectnullable

The JSON body the request was sent with.

Sensitive values such as passwords, tokens, and secrets are redacted before the body is stored. Bodies larger than 256 KB are not stored in full; a small marker object with _truncated set to true is stored in their place.

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

response_bodyobjectnullable

The JSON body OpenMRP responded with.

Sensitive values such as generated API key secrets are redacted before the body is stored. Bodies larger than 256 KB are not stored in full; a small marker object with _truncated set to true is stored in their place.

Encoded as a JSON value (object, array, string, number, boolean, or null), not a JSON-encoded string.

idempotency_keystringnullable

Idempotency key of the originating request.

source_ipstringnullable

Originating client IP address.

occurred_atstring (date-time)

When the audited mutation occurred.

Audit events are ordered and date-filtered by this timestamp rather than by created_at.

created_atstring (date-time)

When the audit event record was written.

Slightly later than occurred_at, since events are recorded out of band from the request that caused them.

Used by