Docs / Concepts

Audit log

Every PastKeys request produces exactly one secret-free, hash-chained audit record, optionally signed by a key only the broker holds.

The broker writes exactly one audit record per request, allowed or denied, success or failure. Records never contain a secret, credential or parameter value.

What a record contains

FieldExample
Time, request ID2026-10-08T09:12:44Z, 8a41d0c2
Agent, provider, resource, actiondeploy-bot, cloudflare, example.com, DNS_UPDATE
Decision, reason, matched ruleALLOW, policy_match, dns-write
Credential type and lifetimeshort-lived, 120 seconds
Result, latencysuccess, 184 ms
Parameter fingerprintSHA-256 of the parameters, never the values

Tamper evidence

Each record carries the hash of the previous one, so removing or editing a record breaks the chain. Set BROKER_AUDIT_KEY_FILE and the broker also signs every record with an Ed25519 key that only it holds, so even someone with write access to the stored log cannot forge entries.

./pastkeys audit pubkey                          # print the signing public key
./pastkeys audit verify --file audit.log --pubkey <key>

Where to read it

The dashboard's Audit log lists the latest events with filters. The Overview summarizes the last 24 hours. Emergency actions taken in the dashboard are recorded separately on the Break-glass page.