Kernel Audit Logs API

Read audit log records for the authenticated organization.

OpenAPI Specification

kernel-audit-logs-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Kernel API Keys Audit Logs API
  description: Developer tools and cloud infrastructure for AI agents to use web browsers
  version: 0.1.0
servers:
- url: https://api.onkernel.com
  description: API Server
security:
- bearerAuth: []
tags:
- name: Audit Logs
  description: Read audit log records for the authenticated organization.
paths:
  /audit-logs:
    get:
      operationId: getAuditLogs
      tags:
      - Audit Logs
      summary: List audit logs
      description: API for searching audit logs. Limited to at most 30 day search, returns up to 100 records per page. Not recommended for bulk export.
      security:
      - bearerAuth: []
      parameters:
      - name: start
        in: query
        required: true
        description: Lower bound (inclusive) for the audit record timestamp.
        schema:
          type: string
          format: date-time
          example: '2026-01-01T00:00:00Z'
      - name: end
        in: query
        required: true
        description: Upper bound (exclusive) for the audit record timestamp.
        schema:
          type: string
          format: date-time
          example: '2026-01-02T00:00:00Z'
      - name: auth_strategy
        in: query
        required: false
        description: Filter by authentication strategy.
        schema:
          type: string
      - name: service
        in: query
        required: false
        description: Filter by service name.
        schema:
          type: string
      - name: method
        in: query
        required: false
        description: Filter by HTTP method.
        schema:
          type: string
      - name: exclude_method
        in: query
        required: false
        description: Filter out results by HTTP method.
        style: form
        explode: false
        schema:
          type: array
          maxItems: 10
          items:
            type: string
      - name: search
        in: query
        required: false
        description: Free-text search over path, user ID, email, client IP, and status.
        schema:
          type: string
      - name: search_user_id
        in: query
        required: false
        description: Additional user IDs to OR into free-text search.
        style: form
        explode: false
        schema:
          type: array
          maxItems: 100
          items:
            type: string
      - name: limit
        in: query
        required: false
        description: Maximum number of results to return.
        schema:
          type: integer
          minimum: 1
          maximum: 100
          default: 100
      - name: page_token
        in: query
        required: false
        description: Opaque page token from X-Next-Page-Token for the next page of older records.
        schema:
          type: string
      responses:
        '200':
          description: A list of audit log records.
          headers:
            X-Limit:
              description: The limit applied to the returned records.
              schema:
                type: integer
                minimum: 1
                maximum: 100
            X-Next-Page-Token:
              description: Page token for the next page of older records, omitted when no more results.
              schema:
                type: string
            X-Has-More:
              description: Whether there are more records available beyond this page.
              schema:
                type: boolean
                default: false
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/AuditLogEntry'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '500':
          $ref: '#/components/responses/InternalError'
      x-codeSamples:
      - lang: JavaScript
        source: "import Kernel from '@onkernel/sdk';\n\nconst client = new Kernel({\n  apiKey: process.env['KERNEL_API_KEY'], // This is the default and can be omitted\n});\n\n// Automatically fetches more pages as needed.\nfor await (const auditLogEntry of client.auditLogs.list({\n  end: '2026-01-02T00:00:00Z',\n  start: '2026-01-01T00:00:00Z',\n})) {\n  console.log(auditLogEntry.user_id);\n}"
      - lang: Python
        source: "import os\nfrom datetime import datetime\nfrom kernel import Kernel\n\nclient = Kernel(\n    api_key=os.environ.get(\"KERNEL_API_KEY\"),  # This is the default and can be omitted\n)\npage = client.audit_logs.list(\n    end=datetime.fromisoformat(\"2026-01-02T00:00:00\"),\n    start=datetime.fromisoformat(\"2026-01-01T00:00:00\"),\n)\npage = page.items[0]\nprint(page.user_id)"
      - lang: Go
        source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"time\"\n\n\t\"github.com/kernel/kernel-go-sdk\"\n\t\"github.com/kernel/kernel-go-sdk/option\"\n)\n\nfunc main() {\n\tclient := kernel.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tpage, err := client.AuditLogs.List(context.TODO(), kernel.AuditLogListParams{\n\t\tEnd:   time.Now(),\n\t\tStart: time.Now(),\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", page)\n}\n"
  /audit-logs/export/chunk:
    get:
      operationId: getAuditLogsExportChunk
      tags:
      - Audit Logs
      summary: Download an audit-log export chunk
      description: Download an organization's audit log records for a time range as a file, for archival, compliance, or offline analysis. For interactive browsing, use GET /audit-logs.
      security:
      - bearerAuth: []
      parameters:
      - name: start
        in: query
        required: true
        description: Lower bound (inclusive) for the audit record timestamp.
        schema:
          type: string
          format: date-time
          example: '2026-01-01T00:00:00Z'
      - name: end
        in: query
        required: true
        description: Upper bound (exclusive) for the audit record timestamp.
        schema:
          type: string
          format: date-time
          example: '2026-01-02T00:00:00Z'
      - name: auth_strategy
        in: query
        required: false
        description: Filter by authentication strategy.
        schema:
          type: string
      - name: service
        in: query
        required: false
        description: Filter by service name.
        schema:
          type: string
      - name: method
        in: query
        required: false
        description: Filter by HTTP method.
        schema:
          type: string
      - name: exclude_method
        in: query
        required: false
        description: Filter out results by HTTP method.
        style: form
        explode: false
        schema:
          type: array
          maxItems: 10
          items:
            type: string
      - name: search
        in: query
        required: false
        description: Free-text search over path, user ID, email, client IP, and status.
        schema:
          type: string
      - name: search_user_id
        in: query
        required: false
        description: Additional user IDs to OR into free-text search.
        style: form
        explode: false
        schema:
          type: array
          maxItems: 100
          items:
            type: string
      - name: cursor
        in: query
        required: false
        description: Opaque cursor from X-Next-Cursor for the next chunk of older records.
        schema:
          type: string
      - name: limit
        in: query
        required: false
        description: Maximum number of records to return in this chunk.
        schema:
          type: integer
          minimum: 1
          maximum: 50000
          default: 50000
      - name: format
        in: query
        required: false
        description: Encoding for the returned chunk.
        schema:
          type: string
          enum:
          - jsonl
          - jsonl.gz
          default: jsonl.gz
      responses:
        '200':
          description: One chunk of audit log records.
          headers:
            X-Has-More:
              description: Whether more records remain beyond this chunk.
              schema:
                type: boolean
                default: false
            X-Next-Cursor:
              description: Cursor for the next chunk of older records, empty when no more results.
              schema:
                type: string
            X-Row-Count:
              description: Number of records in this chunk.
              schema:
                type: integer
                minimum: 0
                maximum: 50000
            X-Content-Sha256:
              description: Hex SHA-256 of the response body.
              schema:
                type: string
                pattern: ^[a-f0-9]{64}$
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '500':
          $ref: '#/components/responses/InternalError'
      x-codeSamples:
      - lang: JavaScript
        source: "import Kernel from '@onkernel/sdk';\n\nconst client = new Kernel({\n  apiKey: process.env['KERNEL_API_KEY'], // This is the default and can be omitted\n});\n\nconst response = await client.auditLogs.exportChunk({\n  end: '2026-01-02T00:00:00Z',\n  start: '2026-01-01T00:00:00Z',\n});\n\nconsole.log(response);\n\nconst content = await response.blob();\nconsole.log(content);"
      - lang: Python
        source: "import os\nfrom datetime import datetime\nfrom kernel import Kernel\n\nclient = Kernel(\n    api_key=os.environ.get(\"KERNEL_API_KEY\"),  # This is the default and can be omitted\n)\nresponse = client.audit_logs.export_chunk(\n    end=datetime.fromisoformat(\"2026-01-02T00:00:00\"),\n    start=datetime.fromisoformat(\"2026-01-01T00:00:00\"),\n)\nprint(response)\ncontent = response.read()\nprint(content)"
      - lang: Go
        source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"time\"\n\n\t\"github.com/kernel/kernel-go-sdk\"\n\t\"github.com/kernel/kernel-go-sdk/option\"\n)\n\nfunc main() {\n\tclient := kernel.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tresponse, err := client.AuditLogs.ExportChunk(context.TODO(), kernel.AuditLogExportChunkParams{\n\t\tEnd:   time.Now(),\n\t\tStart: time.Now(),\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", response)\n}\n"
components:
  responses:
    InternalError:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized – missing or invalid authorization token
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: Bad Request – invalid input
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    Error:
      type: object
      required:
      - code
      - message
      properties:
        code:
          type: string
          description: Application-specific error code (machine-readable)
          example: bad_request
        message:
          type: string
          description: Human-readable error description for debugging
          example: 'Missing required field: app_name'
        details:
          type: array
          description: Additional error details (for multiple errors)
          items:
            $ref: '#/components/schemas/ErrorDetail'
        inner_error:
          $ref: '#/components/schemas/ErrorDetail'
    AuditLogEntry:
      type: object
      required:
      - timestamp
      - auth_strategy
      - user_id
      - email
      - status
      - method
      - path
      - route
      - domain
      - duration_ms
      - client_ip
      - user_agent
      properties:
        timestamp:
          type: string
          format: date-time
          description: UTC time when the request was received.
        auth_strategy:
          type: string
          description: Authentication strategy used for the request.
        user_id:
          type: string
          description: ID of the authenticated user, if any.
        email:
          type: string
          description: Email of the authenticated user at request time, if any.
        status:
          type: integer
          description: HTTP response status code.
        method:
          type: string
          description: HTTP method.
        path:
          type: string
          description: Request path.
        route:
          type: string
          description: Matched API route pattern, if available.
        domain:
          type: string
          description: Request host.
        duration_ms:
          type: integer
          description: Request duration in milliseconds.
        client_ip:
          type: string
          description: Client IP address.
        user_agent:
          type: string
          description: User agent header.
    ErrorDetail:
      type: object
      properties:
        code:
          type: string
          description: Lower-level error code providing more specific detail
          example: invalid_input
        message:
          type: string
          description: Further detail about the error
          example: Provided version string is not semver compliant
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer