curl --request GET \
--url https://api.openworklabs.com/v1/audit/usage \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/usage"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/usage', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/usage",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/usage"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/usage")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/usage")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"entitlement": {
"enabled": true,
"source": "enterprise_plan"
},
"captureOn": true,
"captureAvailable": true,
"policy": {
"organizationId": "<string>",
"revision": 123,
"source": "cloud",
"enabled": true,
"categories": [
"change"
],
"allowance": 0,
"excessMode": "delete_oldest",
"effectiveAt": "2023-11-07T05:31:56Z",
"captureStartedAt": "2023-11-07T05:31:56Z",
"attachmentWindowSeconds": 43200
},
"captureEnabled": true,
"retainedOperations": 0,
"eventCount": 0,
"logicalBytes": 0,
"oldestAvailableAt": "2023-11-07T05:31:56Z",
"measuredAt": "2023-11-07T05:31:56Z",
"billing": "disabled",
"cleanup": "dry_run",
"drains": "not_configured"
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}Read audit retention usage
Organization administrator access to currently captured, retained audit history only; this is not coverage of every cloud action. Requires the latest literal metadata.capabilities.auditLogs=true and deployment visibility; feature disable returns 403 audit_feature_disabled without deleting history or changing capture preference. Legacy arbitrary payloads are preserved separately and are not backfilled or returned. One operation may contain multiple child events. Visibility is independent of capture entitlement. No duration, charge or continuous-drain guarantee is made. Reads stored policy and tenant counters, plus the oldest retained operation. Capture requires audit entitlement, organization captureOn and the deployment capture flag. A ready organization without a policy is lazily initialized ON, including on this GET, with one system lifecycle event. Temporary defaults: 6,000,000 retained OPERATIONS (not child events), 300-second grouping window, change/security/execution/access/request/lifecycle categories, cloud/delete_oldest for Enterprise or operator/keep_all for explicit self-hosted entitlement. Existing OFF and custom policies are preserved. These are provisional declarations, not enforced caps: no billing, cleanup or deletion is activated. Drains are not configured. Logical bytes are not physical database size; access capture may itself add one operation.
curl --request GET \
--url https://api.openworklabs.com/v1/audit/usage \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/usage"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/usage', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/usage",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/usage"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/usage")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/usage")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"entitlement": {
"enabled": true,
"source": "enterprise_plan"
},
"captureOn": true,
"captureAvailable": true,
"policy": {
"organizationId": "<string>",
"revision": 123,
"source": "cloud",
"enabled": true,
"categories": [
"change"
],
"allowance": 0,
"excessMode": "delete_oldest",
"effectiveAt": "2023-11-07T05:31:56Z",
"captureStartedAt": "2023-11-07T05:31:56Z",
"attachmentWindowSeconds": 43200
},
"captureEnabled": true,
"retainedOperations": 0,
"eventCount": 0,
"logicalBytes": 0,
"oldestAvailableAt": "2023-11-07T05:31:56Z",
"measuredAt": "2023-11-07T05:31:56Z",
"billing": "disabled",
"cleanup": "dry_run",
"drains": "not_configured"
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}Authorizations
Session token passed as Authorization: Bearer <session-token> for user-authenticated Den routes.
Response
Current stored audit policy and usage, without a history scan.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
-9007199254740991 <= x <= 9007199254740991-9007199254740991 <= x <= 9007199254740991-9007199254740991 <= x <= 9007199254740991^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$"disabled""dry_run""not_configured"Was this page helpful?