Skip to content

Check that the stored audit was not changed

GET
/v1/audit-log/integrity
curl --request GET \
--url http://localhost:8080/v1/audit-log/integrity \
--header 'Authorization: Bearer <token>'
Available inEmbeddedBundledCluster
AuthAuthenticated Bearer token

Checks the caller’s tenant’s stored ACCESS and IDENTITY entries against their hash chains and names, per chain, the first place the chain no longer holds (CHANGED, UNLINKED, MISSING or HEAD). Removing the oldest entries is what retention does and is not a break. Embedded keeps its audit in memory only and answers durable false with no chains. Requires audit:read. Reads every stored entry of the tenant.

x-tenant-id
string
>= 1 characters

Tenant selection. A principal of one tenant may omit it, and if sent it must name that tenant. A principal that may act in several tenants sends it on every request.

sequence
integer format: int64
>= 1

Also answer each chain’s stored hash at this position

One report per chain

Media typeapplication/json
object
durable
required
boolean
intact
required
boolean
chains
required
Array<object>
object
category
required
string
Allowed values: ACCESS IDENTITY
entries
required
integer format: int64
firstSequence
integer | null format: int64
lastSequence
integer | null format: int64
headSequence
required
integer format: int64
headHash
string | null
hashAtSequence
string
intact
required
boolean
broken
object
sequence
integer format: int64
problem
string
Allowed values: CHANGED UNLINKED MISSING HEAD
detail
string
Example
{
"chains": [
{
"category": "ACCESS",
"broken": {
"problem": "CHANGED"
}
}
]
}

Invalid request

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:invalid-argument",
"title": "Bad Request",
"status": 400,
"detail": "The request is malformed",
"instance": "/v1/audit-log/integrity"
}

Authentication required

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "A valid bearer credential is required",
"instance": "/v1/audit-log/integrity"
}
WWW-Authenticate
string

The caller lacks the required permission.

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:forbidden",
"title": "Forbidden",
"status": 403,
"detail": "The principal lacks the action this route requires",
"instance": "/v1/audit-log/integrity"
}

Tenant-scoped resource not found

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:not-found",
"title": "Not Found",
"status": 404,
"detail": "The requested resource does not exist",
"instance": "/v1/audit-log/integrity"
}

Idempotency conflict

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:conflict",
"title": "Conflict",
"status": 409,
"detail": "The idempotency key is already associated with another request",
"instance": "/v1/audit-log/integrity"
}

Authenticated request exceeds its configured bound

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:payload-too-large",
"title": "Payload Too Large",
"status": 413,
"detail": "The request exceeds the configured size limit",
"instance": "/v1/audit-log/integrity"
}

Tenant quota exhausted

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:quota-exhausted",
"title": "Quota Exhausted",
"status": 429,
"detail": "The tenant active-instance quota is exhausted",
"instance": "/v1/audit-log/integrity"
}

Non-leaking internal failure

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:internal",
"title": "Internal Server Error",
"status": 500,
"detail": "The request could not be completed",
"instance": "/v1/audit-log/integrity"
}

The operation is on the reviewed allow-list of what this deployment mode cannot serve.

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:mode-not-supported",
"title": "Mode Not Supported",
"status": 501,
"detail": "GET /v1/audit-log/integrity is not supported in embedded mode",
"instance": "/v1/audit-log/integrity",
"mode": "embedded"
}

Backpressure or dependency unavailable

Media typeapplication/problem+json
object
type
required
string
/^urn:bpm:error:/
title
required
string
status
required
integer
>= 400 <= 599
detail
required
string
instance
required

The request path.

string
mode

Present only on mode-not-supported. It names the engine’s mode.

string
Example
{
"type": "urn:bpm:error:unavailable",
"title": "Service Unavailable",
"status": 503,
"detail": "The required engine service is not ready",
"instance": "/v1/audit-log/integrity"
}