openapi: 3.2.0 info: title: APImetrics Audits API description: API for the APImetrics platform termsOfService: http://apimetrics.io/tos/ contact: name: APIContext Support url: https://apicontext.io/ email: support@apicontext.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html version: v2026-09-02 tags: - name: Audits description: Audit log paths: /api/2/audits/: get: tags: - Audits summary: List-Audits description: List audit records for the project. operationId: list-audits security: - OAuth2: [] - ApiKey: [] parameters: - name: cursor in: query required: false schema: anyOf: - type: string - type: 'null' title: Cursor - name: limit in: query required: false schema: type: integer default: 100 title: Limit - name: apimetrics-project-id in: header required: false schema: anyOf: - type: string - type: 'null' title: Apimetrics-Project-Id responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/2/audits/organization/{org_id}/: get: tags: - Audits summary: List-Audits-By-Org description: List audit records for an organization. operationId: list-audits-by-org security: - OAuth2: [] - ApiKey: [] parameters: - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID - name: cursor in: query required: false schema: anyOf: - type: string - type: 'null' title: Cursor - name: limit in: query required: false schema: type: integer default: 100 title: Limit responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/2/audits/resource/{key_str}/: get: tags: - Audits summary: List-Audits-By-Resource description: 'List audit records for a specific resource, optionally merging related kinds. A resource''s history is not owned by the active project -- org-level entities record their org as the owning scope -- so this route authorizes by scope rather than gating on project access alone: EDITOR on the header project and ADMIN on an org (which reaches the org''s own records *and* its projects'') are independent bases for the read (see ``_audit_scope_readable``). Callers with neither get 403.' operationId: list-audits-by-resource security: - OAuth2: [] - ApiKey: [] parameters: - name: key_str in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: cursor in: query required: false schema: anyOf: - type: string - type: 'null' title: Cursor - name: limit in: query required: false schema: type: integer default: 100 title: Limit - name: include in: query required: false schema: anyOf: - type: array items: type: string - type: 'null' title: Include - name: apimetrics-project-id in: header required: false schema: anyOf: - type: string - type: 'null' title: Apimetrics-Project-Id responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' components: schemas: HTTPValidationError: properties: detail: items: $ref: '#/components/schemas/ValidationError' type: array title: Detail type: object title: HTTPValidationError ValidationError: properties: loc: items: anyOf: - type: string - type: integer type: array title: Location msg: type: string title: Message type: type: string title: Error Type input: title: Input ctx: type: object title: Context type: object required: - loc - msg - type title: ValidationError securitySchemes: OAuth2: type: oauth2 flows: authorizationCode: scopes: openid: OpenID Connect identity profile: User profile email: User email address authorizationUrl: https://auth.apimetrics.io/authorize?audience=https://client.apimetrics.io tokenUrl: https://auth.apimetrics.io/oauth/token ApiKey: type: apiKey in: header name: X-Api-Key