Activity & audit records PAID
Review activity recorded by supported API operations. The example below is the activity-log endpoint. The dashboard also provides a hash-chained audit log: each record includes a fingerprint of the previous record so changes can be detected. Read the audit guide for timestamping, receipts and verification limits.
GET /api/audit
200
{
"entries": [
{ "action": "vault.store", "resource": "vi_abc123", "ip": "...", "timestamp": ... },
{ "action": "encrypt", "resource": "", "ip": "...", "timestamp": ... }
]
}
For engineers: chained records and timestamping
The hash chain is separate for each customer workspace. A background worker requests RFC 3161 timestamps from timestamp authorities (TSAs), using FreeTSA first and DigiCert as fallback. It checks the response fingerprint, nonce (a request-specific random value) and signature; failed requests can remain pending for retry. Retention depends on the account. Inspect the entry and receipt rather than assuming timestamping has already completed.
Download a receipt PDF for an audit-chain entry from the dashboard at /dashboard/audit, or verify a receipt offline with the open-source verifier CLI: npx @deny-sh/verify-receipt path/to/receipt.json. The PDF presents the receipt; the JSON receipt is the verification artifact. The convenience verifier checks the embedded signature. Use the OpenSSL verification route in the audit guide when validating against an independently trusted root certificate.