Skip to main content
Sente writes an audit event whenever something sensitive happens to an account: a credential is read or overwritten, a browser session is opened or exported, a connection is created or revoked, a run is taken over. Read the trail to answer “who got access to this account, and when” — for a security review, an incident, or your own monitoring. The trail is insert-only. There is no API to edit or delete an event, and events outlive the resources they describe: after an identity is deleted, its identity.delete event still names the address. Events are org-scoped and never carry secret values — no passwords, no TOTP seeds, no session state, no cookies. meta holds descriptive fields only.

The audit event object

There is no actor field. Events record what happened to which resource, not which API key or dashboard user did it. If you need per-actor attribution, use a separate API key per caller and correlate by time.

Actions

Every action the API emits today:
session.export and credentials.read are the two high-signal events: both hand out something that grants standing access to a real account, and neither can be revoked after the fact. Alert on them.
Run outcomes (completed, failed, blocked) are not audit events — they live on the run itself and on the run.* webhooks. The audit trail records deliberate acts on credentials, sessions, accounts, and takeover, not the automation’s own progress.

List audit events

GET /v1/audit-events
Response 200: an array of audit event objects, newest first.
There is no cursor, no offset, and no until — the only window control is since, and results always come back newest-first. That makes two patterns possible and one impossible:
  • Tail-following works. Keep the newest createdAt you have seen and pass it as since on the next call to get everything after it. This is the right shape for a monitor that mirrors the trail into your own store.
  • Narrowing works. Filter by action and raise limit to 200 to pull a specific slice.
  • Walking backwards into deep history does not. An earlier since returns the newest 200 again, not an older page. If you need the full history, mirror it forwards from the start rather than trying to paginate into the past.
Events are insert-only, so anything you already mirrored never changes.
This is HTTP-only. Neither SDK nor the CLI wraps the audit trail; the dashboard renders the same data on the Security tab.
Another org’s events are never returned, and there is no endpoint to fetch a single event by id.

Audit trail

What to monitor and how the trail is used.

Security

The vault, the key, and what Sente does not have.

Connections

Write-only credentials and revocation.