CloudTruth Audit API

The audit API from CloudTruth — 3 operation(s) for audit.

Operations 3

GET /api/v1/audit/ Audit list #
GET /api/v1/audit/{id}/ Audit retrieve #
GET /api/v1/audit/summary/ Audit summary retrieve #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cloudtruth:cloudtruth-audit-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cloudtruth-audit-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: CloudTruth Management Audit API
  version: v1
  description: CloudTruth centralizes your configuration parameters and secrets making them easier to manage and use as a team.
  contact:
    name: CloudTruth Support
    email: support@cloudtruth.com
tags:
- name: Audit
paths:
  /api/v1/audit/:
    get:
      operationId: audit_list
      description: A searchable log of all the actions taken by users and service accounts within the organization.
      parameters:
      - in: query
        name: action
        schema:
          type: string
          enum:
          - create
          - delete
          - expired
          - pull
          - push
          - update
        description: 'The action that was taken.


          * `create` - Create

          * `update` - Update

          * `delete` - Delete

          * `pull` - Pull

          * `push` - Push

          * `expired` - Value Expiration'
      - in: query
        name: earliest
        schema:
          type: string
          format: date-time
      - in: query
        name: environment_id
        schema:
          type: string
          format: uuid
        description: Returns records for the environment, associated tags, and values.
      - in: query
        name: latest
        schema:
          type: string
          format: date-time
      - in: query
        name: object_id
        schema:
          type: string
      - in: query
        name: object_type
        schema:
          type: string
      - name: ordering
        required: false
        in: query
        description: Which field to use when ordering the results.
        schema:
          type: string
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      - in: query
        name: parameter_id
        schema:
          type: string
          format: uuid
        description: Returns records for the parameter and associated values.
      - in: query
        name: project_id
        schema:
          type: string
          format: uuid
        description: Returns records for the project, it's parameters, and associated values.
      - in: query
        name: user_id
        schema:
          type: string
      tags:
      - Audit
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedAuditTrailList'
          description: ''
      summary: Audit list
      x-summary-source: derived
  /api/v1/audit/{id}/:
    get:
      operationId: audit_retrieve
      description: Retrieve one record from the audit log.
      parameters:
      - in: path
        name: id
        schema:
          type: string
          format: uuid
          description: A unique identifier for the audit record.
        required: true
      tags:
      - Audit
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditTrail'
          description: ''
      summary: Audit retrieve
      x-summary-source: derived
  /api/v1/audit/summary/:
    get:
      operationId: audit_summary_retrieve
      description: Summary information about the organization's audit trail.
      tags:
      - Audit
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditTrailSummary'
          description: ''
      summary: Audit summary retrieve
      x-summary-source: derived
components:
  schemas:
    PaginatedAuditTrailList:
      type: object
      required:
      - count
      - results
      properties:
        count:
          type: integer
          example: 123
        next:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=4
        previous:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=2
        results:
          type: array
          items:
            $ref: '#/components/schemas/AuditTrail'
    AuditTrail:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          format: uuid
          readOnly: true
          description: A unique identifier for the audit record.
        action:
          type: string
          readOnly: true
          description: The action that was taken.
        object_id:
          type: string
          readOnly: true
          description: The id of the object associated with the action.
        object_name:
          type: string
          readOnly: true
          description: The name of the object associated with the action, if applicable.
        object_type:
          allOf:
          - $ref: '#/components/schemas/ObjectTypeEnum'
          readOnly: true
          description: 'The type of object associated with the action.


            * `AwsIntegration` - AwsIntegration

            * `Environment` - Environment

            * `GitHubIntegration` - GitHubIntegration

            * `Grant` - Grant

            * `Invitation` - Invitation

            * `LogDestination` - LogDestination

            * `Membership` - Membership

            * `Organization` - Organization

            * `OrganizationSettings` - OrganizationSettings

            * `Parameter` - Parameter

            * `ParameterRule` - ParameterRule

            * `ParameterType` - ParameterType

            * `ParameterTypeRule` - ParameterTypeRule

            * `Project` - Project

            * `Pull` - Pull

            * `Push` - Push

            * `ServiceAccount` - ServiceAccount

            * `Tag` - Tag

            * `Task` - Task

            * `Template` - Template

            * `Value` - Value'
        timestamp:
          type: string
          format: date-time
          readOnly: true
          description: The timestamp of the activity that was audited.
        user:
          allOf:
          - $ref: '#/components/schemas/User'
          readOnly: true
          description: Details of the user associated with this change.
        ip_address:
          type:
          - string
          - 'null'
          readOnly: true
          description: The client IP address for the request that produced this record, if available.
        user_agent:
          type: string
          readOnly: true
          description: The User-Agent header for the request that produced this record, if available.
        request_id:
          type:
          - string
          - 'null'
          format: uuid
          readOnly: true
          description: A correlation id for the request that produced this record (X-Request-ID or generated).
        changed_fields:
          type: array
          items:
            type: string
          readOnly: true
          description: Names of model fields that changed (update only). Field values are not stored to avoid leaking secret content.
      required:
      - action
      - changed_fields
      - id
      - ip_address
      - object_id
      - object_name
      - object_type
      - request_id
      - timestamp
      - url
      - user
      - user_agent
    ObjectTypeEnum:
      enum:
      - AwsIntegration
      - Environment
      - GitHubIntegration
      - Grant
      - Invitation
      - LogDestination
      - Membership
      - Organization
      - OrganizationSettings
      - Parameter
      - ParameterRule
      - ParameterType
      - ParameterTypeRule
      - Project
      - Pull
      - Push
      - ServiceAccount
      - Tag
      - Task
      - Template
      - Value
      type: string
      description: '* `AwsIntegration` - AwsIntegration

        * `Environment` - Environment

        * `GitHubIntegration` - GitHubIntegration

        * `Grant` - Grant

        * `Invitation` - Invitation

        * `LogDestination` - LogDestination

        * `Membership` - Membership

        * `Organization` - Organization

        * `OrganizationSettings` - OrganizationSettings

        * `Parameter` - Parameter

        * `ParameterRule` - ParameterRule

        * `ParameterType` - ParameterType

        * `ParameterTypeRule` - ParameterTypeRule

        * `Project` - Project

        * `Pull` - Pull

        * `Push` - Push

        * `ServiceAccount` - ServiceAccount

        * `Tag` - Tag

        * `Task` - Task

        * `Template` - Template

        * `Value` - Value'
    AuditTrailSummary:
      type: object
      properties:
        earliest:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
          description: The earliest audit record timestamp available.
        max_days:
          type: integer
          readOnly: true
          description: The maximum number of days the system will save auditing records, based on your subscription.
        max_records:
          type: integer
          readOnly: true
          description: The maximum number of auditing records the system will save based on your subscription.
        total:
          type: integer
          readOnly: true
          description: The total number of audit records available.
      required:
      - earliest
      - max_days
      - max_records
      - total
    User:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          description: The unique identifier of a user.
          maxLength: 256
        type:
          type: string
          description: The type of user record.
          maxLength: 12
        name:
          type:
          - string
          - 'null'
          readOnly: true
        organization_name:
          type:
          - string
          - 'null'
          readOnly: true
          description: The user's organization name.
        membership_id:
          type:
          - string
          - 'null'
          readOnly: true
          description: Membership identifier for user.
        chatgpt_threads:
          type: object
          additionalProperties: {}
          readOnly: true
          description: The threads this user is participating in with ChatGPT.
        role:
          type:
          - string
          - 'null'
          readOnly: true
          description: The user's role in the current organization (defined by the request authorization header).
        email:
          type:
          - string
          - 'null'
          readOnly: true
        picture_url:
          type:
          - string
          - 'null'
          readOnly: true
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
      required:
      - chatgpt_threads
      - created_at
      - email
      - id
      - membership_id
      - modified_at
      - name
      - organization_name
      - picture_url
      - role
      - url
  securitySchemes:
    ApiKeyAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your CloudTruth API Key to authenticate to the API.  You can get\nan API Key by creating a Service Account.  During setup of the Service\nAccount you will generate a long-lived API key intended for use by automation\nand API clients.  Access through the service account will be audited separately\nfrom any other user.\n\nIf you are just trying to use the API in a normal workflow, this is likely the\nauthentication mechanism you want to use.\n\nTo use the API Key, place your API Key in the Authorization header as 'Api-Key APIKEY', where\nAPIKEY is your CloudTruth API Key.  For example:\n\n    Authorization: Api-Key fskur.ghlsiudhrg84so938r5u\n        "
    JWTAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your JWT to authenticate to the API.  This is how the CloudTruth\nWeb UI authenticates to the backend.  It requires a user to have already logged in\nand gotten a JWT from the login process.  This is usually done by an Auth0 authentication\nflow from one of the Auth0 javascript libraries.  Alternatively, you can pull the\nJWT from your browser if you have a logged in session with the CloudTruth UI.\n\nThis authentication mechanism is intended for deeper integrations into the CloudTruth\nsystem, where you want to handle the user logins directly in your application.  For\nnormal API use, you likely want the Api-Key authentication header and not this one.\n\nTo use the JWT, place your JWT in the Authorization header as 'Bearer JWT', where\nJWT is your JWT.  For example:\n\n    Authorization: Bearer eyJhbGciOiJIkuydfy.eyJzdWIiOiIxMjM....\n        "
    tokenAuth:
      type: http
      scheme: bearer
externalDocs:
  url: https://docs.cloudtruth.com/