curl --request GET \
--url https://api.openworklabs.com/v1/audit/operations/{operationId}/events \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/operations/{operationId}/events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/operations/{operationId}/events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/operations/{operationId}/events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/operations/{operationId}/events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/operations/{operationId}/events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/operations/{operationId}/events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"events": [
{
"schemaVersion": 1,
"id": "<string>",
"organizationId": "<string>",
"operationId": "<string>",
"sequence": 123,
"operation": {
"kind": "<string>",
"scope": "<string>",
"origin": "api",
"originTrust": "authenticated",
"initiatingActor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"startedAt": "2023-11-07T05:31:56Z"
},
"actor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"action": "<string>",
"category": "change",
"outcome": "succeeded",
"occurredAt": "2023-11-07T05:31:56Z",
"recordedAt": "2023-11-07T05:31:56Z",
"requestId": "<string>",
"resources": [
{
"type": "<string>",
"id": "<string>",
"relationship": "target",
"label": "<string>"
}
],
"logicalBytes": 0,
"jobRunId": "<string>",
"causedByEventId": "<string>",
"changes": {
"before": {},
"after": {},
"changedFields": [
"<string>"
]
},
"reasonCode": "<string>"
}
],
"nextCursor": "<string>",
"snapshotSequence": 0
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}List retained operation events
Organization administrator access to currently captured, retained audit history only; this is not coverage of every cloud action. Requires the latest literal metadata.capabilities.auditLogs=true and deployment visibility; feature disable returns 403 audit_feature_disabled without deleting history or changing capture preference. Legacy arbitrary payloads are preserved separately and are not backfilled or returned. One operation may contain multiple child events. Visibility is independent of capture entitlement. No duration, charge or continuous-drain guarantee is made. Default limit 50, maximum 100. Cursors are signed, organization/filter/mode scoped and expire 24 hours after the first page (not renewed). Repeat the same filters; limit may change. The snapshotSequence is the committed tenant publication watermark, not a timestamp or auto-increment allocation. Events above it are excluded, including later children of an existing operation. Missing retained anchors or changed removal counters return 410 audit_history_unavailable; start a new snapshot. These checks are not lossless-drain or retention protection guarantees. Events are in ascending tenant sequence order and carry complete versioned envelopes. Missing or foreign retained operations return the same 404.
curl --request GET \
--url https://api.openworklabs.com/v1/audit/operations/{operationId}/events \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/operations/{operationId}/events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/operations/{operationId}/events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/operations/{operationId}/events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/operations/{operationId}/events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/operations/{operationId}/events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/operations/{operationId}/events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"events": [
{
"schemaVersion": 1,
"id": "<string>",
"organizationId": "<string>",
"operationId": "<string>",
"sequence": 123,
"operation": {
"kind": "<string>",
"scope": "<string>",
"origin": "api",
"originTrust": "authenticated",
"initiatingActor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"startedAt": "2023-11-07T05:31:56Z"
},
"actor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"action": "<string>",
"category": "change",
"outcome": "succeeded",
"occurredAt": "2023-11-07T05:31:56Z",
"recordedAt": "2023-11-07T05:31:56Z",
"requestId": "<string>",
"resources": [
{
"type": "<string>",
"id": "<string>",
"relationship": "target",
"label": "<string>"
}
],
"logicalBytes": 0,
"jobRunId": "<string>",
"causedByEventId": "<string>",
"changes": {
"before": {},
"after": {},
"changedFields": [
"<string>"
]
},
"reasonCode": "<string>"
}
],
"nextCursor": "<string>",
"snapshotSequence": 0
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}Authorizations
Session token passed as Authorization: Bearer <session-token> for user-authenticated Den routes.
Path Parameters
^aop_[0-7][0-9a-hjkmnp-tv-z]{25}$Query Parameters
Maximum rows in this page.
1 <= x <= 100Opaque nextCursor from the prior page of the same query and mode.
4096Was this page helpful?