列出Atlas 审核事件

获取 /api/v1/organizations/{id}/audit-events

返回组织操作日志(在组织的项目中采取的操作),最新的在前。键集/游标分页。

路径参数

  • id 字符串 必需

    要读取其Atlas 审核源的组织

查询参数

  • PROJECT_ID 字符串

    按项目筛选

  • limit 整型

    每页最大事件数(默认50,最大为 200)

  • cursor 字符串

    下一页的不透明键游标

  • 操作 字符串

    按动作筛选(例如, 代理 )

  • category 字符串

    按类别过滤:访问权限或更改

  • actor_email 字符串

    按演员电子邮件筛选

  • 结果 字符串

    按结果筛选:成功或失败

  • start_time 字符串

    时间范围开始 (RFC3339)

  • end_time 字符串

    时间范围结束 (RFC3339)

  • show_admin_events 布尔

    包括管理事件(操作符操作和 GSA 运行时事件);默认false 隐藏它们

响应

  • 不支持或格式不正确的API版本、所选已发布合约中不可用的操作或不可接受的表示形式(包括不支持的媒体类型参数或排除的 SSE)。现有的身份验证、授权和速率限制失败优先。

    隐藏响应属性 显示响应属性 对象
    • badRequestDetail 对象

      标准错误模式定义的可选验证详细信息; API协商错误不会发出此字段。

      隐藏 BadRequestDetail 属性 显示 BadRequestDetail 属性 对象
      • 字段 大量[对象]

        验证失败的字段。

        隐藏字段属性 显示字段属性 对象

        字段及其验证失败。

        • 描述 字符串 必需

          人类可读的验证失败。

        • 字段 字符串 必需

          无效请求字段的名称或路径。

    • 详细信息 字符串 必需

      人类可读的错误详细信息。

    • 错误 整型 必需

      HTTP status code.

    • 错误代码 字符串 必需

      机器可读的错误代码。

    • 参数 array[string]

      与错误相关的请求参数名称;不应用时省略。

    • 原因 字符串 必需

      HTTP状态原因短语。

    隐藏响应属性 显示响应属性 对象
    • badRequestDetail 对象

      标准错误模式定义的可选验证详细信息; API协商错误不会发出此字段。

      隐藏 BadRequestDetail 属性 显示 BadRequestDetail 属性 对象
      • 字段 大量[对象]

        验证失败的字段。

        隐藏字段属性 显示字段属性 对象

        字段及其验证失败。

        • 描述 字符串 必需

          人类可读的验证失败。

        • 字段 字符串 必需

          无效请求字段的名称或路径。

    • 详细信息 字符串 必需

      人类可读的错误详细信息。

    • 错误 整型 必需

      HTTP status code.

    • 错误代码 字符串 必需

      机器可读的错误代码。

    • 参数 array[string]

      与错误相关的请求参数名称;不应用时省略。

    • 原因 字符串 必需

      HTTP状态原因短语。

  • 200

    正常

    隐藏响应属性 显示响应属性 对象
    • audit_events 大量[对象]
      隐藏 audit_events 属性 显示 audit_events 属性 对象
      • 操作 字符串

        值为 agent.deploy、agent.rollback、agent.promote、secret.set、secret.delete、workspace_logs.view、data_viewer_access.grant、data_viewer_access.revoke、support_access.grant、support_access.revoke、service_account.create、service_account.rotate_secret、 service_account.revoke、service_account.reactivate、service_account.replace_roles、service_account.token_mint、service_account.token_use、service_account.authz_denied、service_account.ip_access_list.update、oe_profile.capture、oe_profile.download、workspace.delete、project.delete、workspace.deletion_delivered、workspace.restoration_delivered, app_secrets.reclaim, project_secrets.reclaim, api_key_secrets.reclaim, ecr_repository.delete, namespace.delete, atlas_service_account.retire, workspace_records.purge, project_records.purge, project.reclaim, project_platform_target.select, project_staged_rollout.start, project_staged_rollout.resume, app_platform_update.accept、project_operation.force_cancel、project_operation.request_cancel、app_operation.request_cancel、project_operation.resume、runtime_config.set、runtime_config.clear、trace.view、application_secret.migrate、egress_allow_all.migrate、egress.save、guardrail.create、guardrail.update、guardrail.delete、policy.create、policy.update、policy.delete、credential_provider.create、credential_provider.update 或 credential_provider.delete。

      • 演员 对象
        隐藏 actor 属性 显示 actor 属性 对象
        • client_id 字符串

          当类型为 ActorTypeServiceAccount 时,ClientID 是全局服务帐户客户端ID。

        • 电子邮件 字符串
        • 角色 array[string]

          角色是执行者在动作时记录的角色(如有)。可选。

        • 类型 字符串

          类型可区分 actor 类型。 Empty 或 ActorTypeUser 是指由 UserID/Email 标识的人员。 ActorTypeServiceAccount 是指由 ClientID 标识的 GSA(用户 ID/电子邮件可能为空)。

        • user_id 字符串
      • category 字符串

        值为 access 或 mutation。

      • failure_reason 字符串
      • id 字符串
      • metadata 对象

        允许使用其他属性。

      • 结果 字符串

        值为 success 或 failure。

      • 范围 对象
        隐藏作用域属性 显示作用域属性 对象
        • org_id 字符串
        • PROJECT_ID 字符串
        • Workspace_id 字符串
      • source_ip 字符串
      • 目标 对象
        隐藏目标属性 显示目标属性 对象
        • id 字符串
        • 名称 字符串
        • 类型 字符串

          类型是资源种类(例如“workspace_logs”、“deployment”、“secret”)。

      • timestamp 字符串
    • has_more 布尔
    • next_cursor 字符串
    隐藏响应属性 显示响应属性 对象
    • audit_events 大量[对象]
      隐藏 audit_events 属性 显示 audit_events 属性 对象
      • 操作 字符串

        值为 agent.deploy、agent.rollback、agent.promote、secret.set、secret.delete、workspace_logs.view、data_viewer_access.grant、data_viewer_access.revoke、support_access.grant、support_access.revoke、service_account.create、service_account.rotate_secret、 service_account.revoke、service_account.reactivate、service_account.replace_roles、service_account.token_mint、service_account.token_use、service_account.authz_denied、service_account.ip_access_list.update、oe_profile.capture、oe_profile.download、workspace.delete、project.delete、workspace.deletion_delivered、workspace.restoration_delivered, app_secrets.reclaim, project_secrets.reclaim, api_key_secrets.reclaim, ecr_repository.delete, namespace.delete, atlas_service_account.retire, workspace_records.purge, project_records.purge, project.reclaim, project_platform_target.select, project_staged_rollout.start, project_staged_rollout.resume, app_platform_update.accept、project_operation.force_cancel、project_operation.request_cancel、app_operation.request_cancel、project_operation.resume、runtime_config.set、runtime_config.clear、trace.view、application_secret.migrate、egress_allow_all.migrate、egress.save、guardrail.create、guardrail.update、guardrail.delete、policy.create、policy.update、policy.delete、credential_provider.create、credential_provider.update 或 credential_provider.delete。

      • 演员 对象
        隐藏 actor 属性 显示 actor 属性 对象
        • client_id 字符串

          当类型为 ActorTypeServiceAccount 时,ClientID 是全局服务帐户客户端ID。

        • 电子邮件 字符串
        • 角色 array[string]

          角色是执行者在动作时记录的角色(如有)。可选。

        • 类型 字符串

          类型可区分 actor 类型。 Empty 或 ActorTypeUser 是指由 UserID/Email 标识的人员。 ActorTypeServiceAccount 是指由 ClientID 标识的 GSA(用户 ID/电子邮件可能为空)。

        • user_id 字符串
      • category 字符串

        值为 access 或 mutation。

      • failure_reason 字符串
      • id 字符串
      • metadata 对象

        允许使用其他属性。

      • 结果 字符串

        值为 success 或 failure。

      • 范围 对象
        隐藏作用域属性 显示作用域属性 对象
        • org_id 字符串
        • PROJECT_ID 字符串
        • Workspace_id 字符串
      • source_ip 字符串
      • 目标 对象
        隐藏目标属性 显示目标属性 对象
        • id 字符串
        • 名称 字符串
        • 类型 字符串

          类型是资源种类(例如“workspace_logs”、“deployment”、“secret”)。

      • timestamp 字符串
    • has_more 布尔
    • next_cursor 字符串
  • Bad Request

    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
  • Unauthorized

    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
  • Forbidden

    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
  • 内部服务器错误

    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
    隐藏响应属性 显示响应属性 对象
    • 代码 字符串
    • 错误 字符串
    • Success 布尔
GET /api/v1/organizations/{id}/audit-events
curl \
 --request GET 'https://agentengine.mongodb.com/api/v1/organizations/{id}/audit-events' \
 --header "Authorization: $API_KEY"
响应示例 (406)
{
  "detail": "This operation is not available in API version 2026-09-20-preview.",
  "error": 406,
  "errorCode": "OPERATION_NOT_IN_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
{
  "detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
  "error": 406,
  "errorCode": "UNACCEPTABLE_MEDIA_TYPE",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
{
  "detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
  "error": 406,
  "errorCode": "UNSUPPORTED_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
响应示例 (406)
{
  "detail": "This operation is not available in API version 2026-09-20-preview.",
  "error": 406,
  "errorCode": "OPERATION_NOT_IN_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
响应示例 (200)
{
  "audit_events": [
    {
      "action": "agent.deploy",
      "actor": {
        "client_id": "string",
        "email": "string",
        "roles": [
          "string"
        ],
        "type": "string",
        "user_id": "string"
      },
      "category": "access",
      "failure_reason": "string",
      "id": "string",
      "metadata": {},
      "outcome": "success",
      "scope": {
        "org_id": "string",
        "project_id": "string",
        "workspace_id": "string"
      },
      "source_ip": "string",
      "target": {
        "id": "string",
        "name": "string",
        "type": "string"
      },
      "timestamp": "string"
    }
  ],
  "has_more": true,
  "next_cursor": "string"
}
响应示例 (200)
{
  "audit_events": [
    {
      "action": "agent.deploy",
      "actor": {
        "client_id": "string",
        "email": "string",
        "roles": [
          "string"
        ],
        "type": "string",
        "user_id": "string"
      },
      "category": "access",
      "failure_reason": "string",
      "id": "string",
      "metadata": {},
      "outcome": "success",
      "scope": {
        "org_id": "string",
        "project_id": "string",
        "workspace_id": "string"
      },
      "source_ip": "string",
      "target": {
        "id": "string",
        "name": "string",
        "type": "string"
      },
      "timestamp": "string"
    }
  ],
  "has_more": true,
  "next_cursor": "string"
}
响应示例 (400)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (400)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (401)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (401)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (403)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (403)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (500)
{
  "code": "string",
  "error": "string",
  "success": true
}
响应示例 (500)
{
  "code": "string",
  "error": "string",
  "success": true
}