Security and audit
List security alerts
Returns things that looked unusual, newest first, one page at a time. Owners, admins and admin API keys get the alerts of the whole workspace; agents signed in to the app get only the alerts about themselves.
- Bearer API key
- Scope:
adminonly - or app session
- Workspace:
X-Tenant-ID(optional with a key)
Headers
AuthorizationstringrequiredYour API key as
Bearer <key>. The wordBearerand the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.X-Tenant-IDuuidoptionalWorkspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass
?tenant=<id>instead.
Query parameters
cursorstringoptionalThe
next_cursorof the previous page, unchanged. Leave it out to get the first page.limitintegeroptionalItems per page.
Response
200 OKapplication/json
itemsarray<SecurityAlert>Alerts, newest first.
Show child attributesHide child attributes14
iduuidAlert id.
kindenumnew_device,new_country,failed_logins,api_key_new_ip,large_data_access,admin_addedorapi_key_created. See the list below.summarystringOne sentence that says what happened.
user_iduuidnullableThe teammate the alert is about, or
null.user_namestringTheir name, or
"".api_key_iduuidnullableThe API key the alert is about, or
null.api_key_namestringIts name, or
"".ipstringIP address involved, or
"".locationstringCity and country of that address (for example
Ljubljana, SI), or"".devicestringBrowser and operating system, or
"".countintegerHow many times it happened. Repeats within the same hour raise the count instead of adding alerts.
emailedbooleantruewhen an email about the alert was sent.created_attimestampFirst occurrence (RFC 3339).
last_seen_attimestampLatest occurrence (RFC 3339).
next_cursorstringSend it as
cursorto get the next page. An empty string ("") means this is the last page.
Status codes
- 200OK. One page of alerts.
- 400Bad request. Session requests only: no workspace was selected (
workspace required (X-Tenant-ID)). - 401Unauthorized. The API key is unknown, revoked or expired (
invalid or expired API key), or there is no key and no signed-in session (unauthorized). - 403Forbidden. The API key does not have the
adminscope (this endpoint needs an API key with the admin scope:readandwritekeys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address,code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace,forbidden). - 500Server error. Something went wrong on our side. Retry with backoff.
Which alerts are there?
kind | When |
|---|---|
new_device | A teammate signed in from a device their account had not used before. |
new_country | A teammate signed in from a country their account had not signed in from before. |
failed_logins | Repeated failed sign-ins to a teammate’s account. |
api_key_new_ip | An API key was used from an IP address it had not been used from before. |
large_data_access | An unusually large amount of data was read or exported. |
admin_added | Someone was given the admin role. |
api_key_created | A new API key was created. |
The same alert about the same person or key is raised at most once an hour: repeats within the hour raise count and last_seen_at instead of adding a new alert. Handle kinds you do not recognise: new ones may be added.
How do I page through the list?
Items come newest first, limit at a time (50 by default, at most 200). While next_cursor is not empty, call the endpoint again with the same filters and cursor=<next_cursor>. An empty next_cursor ("") means you have the last page.