Skip to main content
Read your organization’s own slice of Baselayer’s tamper-evident, sequenced log: every identity registration, credential issuance, and revocation tied to a principal_ref, business_ref, or jti you hold.

Before you start

You need at least one of principal_ref, business_ref, or jti from your own prior activity. The query is refused without one; there is no way to browse the whole log unscoped.

Reading the log

GET /audit-log — scope with principal_ref, business_ref, and/or jti; optionally filter by event_type (issuance, credential_revocation, identity_registration, and others). Paginate with limit / offset, or cursor (from the X-Next-Cursor response header) for keyset paging — the two paging modes can’t be combined. Very recent events may lag slightly behind the fast-store views used elsewhere (identity lookup, submission polling), since this log is populated by an asynchronous batch sequencer.

Event shapes

  • issuance — a credential mint, mirroring the mint response minus the credential string itself (a short-TTL projection this log deliberately never stores).
  • credential_revocation — one credential killed by jti, with a reason (agent_key_compromise, identity_superseded, fraud_suspected, and others). The subject keeps its authority to mint — this says one artifact died, nothing about what’s issued next.
  • identity_registration — a submission or hosted session reaching a verdict, carrying business_operator_link_status at the time.

Troubleshooting