Skip to main content
Every audit log event has an event type that identifies what happened. Event types follow a dot-separated naming convention: <category>.<resource>.<action>. Below is the full list of event types, grouped by category. The Metadata column lists the keys that may appear in the metadata field for each event type. See Metadata key reference for descriptions.

Authentication

API

Entity CRUD

Entity schema

Workspace members

Workspace billing

Workspace SSO

Workspace API keys

Workspace settings

Domains

App lifecycle

App users

Integrations

App runtime

Security


Metadata key reference

All metadata values are strings.

agent_name

Name of the AI agent.

app_name

Name of the app.

app_type

Type of the app.

auth_method

Authentication method (e.g. email_password, google).

auth_provider

OAuth provider name, if applicable.

automation_id

ID of the automation.

automation_name

Name of the automation.

automation_type

Type of automation (e.g. scheduled, triggered).

backend_functions_issues_count

Number of backend function issues found in security scan.

checkpoint_id

Deployment checkpoint ID.

conversation_id

ID of the AI agent conversation.

count

Number of affected records, invoices, or other items.

credit_count

Credits consumed by the operation.

domain

The domain name.

domain_id

The domain ID.

duration_ms

Execution time in milliseconds.

email_domain

Domain portion of the user’s email address.

email_hash

SHA-256 hash of the user’s email address.

endpoint_count

Number of endpoints on the custom integration.

entity_id

ID of the affected entity record.

entity_name

Name of the entity.

failure_reason

Reason for failure when status is "failure".

fields

Fields included in a query response.

fields_changed

Comma-separated list of fields that were changed.

file_path

Path of the file being edited.

filter_fields

Field names being filtered on in a query (e.g. data.status, data.user_id).

function_name

Name of the backend function or integration function.

hardcoded_secrets_count

Number of hardcoded secrets found in security scan.

has_rls

Whether row-level security is enabled on the entity schema.

integration_name

Name of the custom integration.

integration_slug

Slug identifier of the custom integration.

integration_type

Type of OAuth integration.

invitation_count

Number of invitations sent in a bulk invite.

invitation_email

Email associated with the invitation.

invitee_email

Email of the invited user.

invitee_emails

Comma-separated emails of invited users (bulk invite).

is_enterprise

Whether the workspace is on an enterprise plan.

is_new_user

Whether this is the user’s first login.

key_id

ID of the workspace API key.

key_name

Name of the workspace API key.

key_prefix

Non-secret prefix of the API key, used to identify it without exposing the secret.

limit

Maximum number of records requested in a query.

mcp_oauth

Whether the login was initiated via an MCP OAuth flow.

message_count

Number of messages in an AI agent conversation.

method

Bulk operation method.

mfa_method

MFA method used (e.g. totp, sms).

new_description

New description after an update.

new_name

New name after a rename.

new_role

New role after a role change.

oauth_error_type

Type of OAuth error on failure.

old_description

Previous description before an update.

old_name

Previous name before a rename.

old_role

Previous role before a role change.

page_name

Name of the visited page.

registration_method

How the app user registered.

requester_email

Email of the user requesting access.

rls_changed

Whether row-level security settings changed.

rls_recommendations_count

Number of RLS recommendations from security scan.

role

Role assigned to a user.

sandbox_id

Stripe sandbox ID.

signup_stage

Signup progress indicator (e.g. otp_pending, otp_verified).

skip

Number of records skipped in a query.

sort

Sort parameters used in a query.

sso_provider

SSO provider name.

status_code

HTTP status code returned by a backend function call.

stripe_customer_id

Stripe customer ID.

subscription_tier

Subscription tier of the workspace.

target_email

Email of the user affected by the action.

target_tier

Target subscription tier for a migration.

target_user_id

ID of the app user affected by the action.

turnstile_result

Cloudflare Turnstile verification result.

updated_fields

SSO settings fields that were updated.

user_id

ID of the authenticated user.

verification_status

Domain verification result. Marketing visitor cookie identifier.

workspace_name

Name of the workspace.