Browse docs · Concepts
Get started
Concepts
Guides
Security
Reference
Docs / Concepts
Audit log
Every PastKeys request produces exactly one secret-free, hash-chained audit record, optionally signed by a key only the broker holds.
The broker writes exactly one audit record per request, allowed or denied, success or failure. Records never contain a secret, credential or parameter value.
What a record contains
| Field | Example |
|---|---|
| Time, request ID | 2026-10-08T09:12:44Z, 8a41d0c2 |
| Agent, provider, resource, action | deploy-bot, cloudflare, example.com, DNS_UPDATE |
| Decision, reason, matched rule | ALLOW, policy_match, dns-write |
| Credential type and lifetime | short-lived, 120 seconds |
| Result, latency | success, 184 ms |
| Parameter fingerprint | SHA-256 of the parameters, never the values |
Tamper evidence
Each record carries the hash of the previous one, so removing or editing a record breaks the chain. Set BROKER_AUDIT_KEY_FILE and the broker also signs every record with an Ed25519 key that only it holds, so even someone with write access to the stored log cannot forge entries.
./pastkeys audit pubkey # print the signing public key ./pastkeys audit verify --file audit.log --pubkey <key>
Where to read it
The dashboard's Audit log lists the latest events with filters. The Overview summarizes the last 24 hours. Emergency actions taken in the dashboard are recorded separately on the Break-glass page.