principal_ref, business_ref, or jti you hold.
Before you start
You need at least one ofprincipal_ref, business_ref, or jti from your own prior activity. The query is refused without one; there is no way to browse the whole log unscoped.Reading the log
GET /audit-log — scope with principal_ref, business_ref, and/or jti; optionally filter by event_type (issuance, credential_revocation, identity_registration, and others). Paginate with limit / offset, or cursor (from the X-Next-Cursor response header) for keyset paging — the two paging modes can’t be combined.
Very recent events may lag slightly behind the fast-store views used elsewhere (identity lookup, submission polling), since this log is populated by an asynchronous batch sequencer.
Event shapes
issuance— a credential mint, mirroring the mint response minus the credential string itself (a short-TTL projection this log deliberately never stores).credential_revocation— one credential killed byjti, with areason(agent_key_compromise,identity_superseded,fraud_suspected, and others). The subject keeps its authority to mint — this says one artifact died, nothing about what’s issued next.identity_registration— a submission or hosted session reaching a verdict, carryingbusiness_operator_link_statusat the time.