Audit API

Audit endpoints in the Brix REST API: 5 operations (GET, POST), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/audit

Bearer token audit-log.view

Returns the workspace's append-only activity log, with each event's actor shown by name rather than raw id, whether the actor was a person, an API key, or the system. Filter by actor, action, target, and time window.

curl "https://api.brixsignage.com/v1/audit" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/audit

Bearer token audit-log.create

Appends one event to the workspace's activity log from an external system, so actions taken outside Brix appear in the same trail. The activity log is append-only: events can be added but never updated or deleted.

curl -X POST "https://api.brixsignage.com/v1/audit" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/audit/export

Bearer token audit-log.view

Returns the activity log as a feed suitable for a log collector or SIEM tool. Unlike the regular activity log listing, results are returned oldest first, so a collector can page forward from a saved position without missing or re-reading events. Returns newline-delimited JSON by default; pass ?format=json for a human-readable array. Use the from and to parameters for a half-open time window, and the x-brix-next-cursor and x-brix-has-more response headers to page through results.

curl "https://api.brixsignage.com/v1/audit/export" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/audit/integrity

Bearer token

Returns the tamper-evidence chain for the workspace's activity log: a digest to record for later comparison, and the daily checkpoints behind it. Each complete UTC day of events is combined into one checkpoint linked to the day before. The current, still-open day is deliberately not yet included, since a checkpoint over data still being written would have to be recalculated.

curl "https://api.brixsignage.com/v1/audit/integrity" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/audit/integrity/verify

Bearer token

Re-reads every event behind the integrity chain and recomputes it, to prove the activity log has not been altered since a digest was recorded. Returns HTTP 200 with ok: false when verification fails, rather than an error status, so a monitoring script can distinguish "the log was altered" from "the check itself failed". This is rate-limited because it re-reads the full log.

curl -X POST "https://api.brixsignage.com/v1/audit/integrity/verify" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.