Skip to main content
GET
Audit events
Every meaningful action in Repo records an audit event with metadata-only fields (never raw content). Use this endpoint to export the trail for SOC 2, GDPR, or internal review.

Required action

admin

Query parameters

integer
default:"100"
Max number of events to return. Min 1, max 500.

Response

Action catalog

Actor identification

Each event has either actorUserId (a Supabase human) or actorApiKeyId (an API key) — never both. Look at which one is non-null to attribute the action.

What’s NOT logged

By design, Repo does NOT log:
  • Full hit content from retrieval (only counts + provider list)
  • API key secrets (only the public prefix)
  • OAuth tokens (encrypted, never appear in logs)
  • Source-item content during ingest
  • LLM completions from /v1/ask
This keeps the audit log small and reduces blast radius if the log is ever exposed.