The audit module reads and appends rows in the AuditLog table (audit_logs). Rows cannot be edited or deleted through the API. Not every audit row comes through this router. Other modules write to the same table directly. For example, the foods repository writes an mbp.anchors.reprice row with resourceType STUDIO_SETTINGS when a studio changes its MBP anchors (see Studios).

Mount point and auth

Source: apps/core-api/src/modules/audit/. The router has no role guard. Every query is scoped to req.auth.studioId.

The audit entry

string
cuid.
string
Owning studio, from the auth context.
string
Who did it. On POST this comes from the request body, not from req.auth.userId.
string
Free-text action name, for example mbp.anchors.reprice.
string
Free-text resource type, for example STUDIO_SETTINGS.
string | null
Id of the affected record.
object | null
Free-form JSON describing the change.
string
ISO timestamp. There is no updatedAt.

Endpoints

GET /v1/web/audit

Lists the studio’s audit entries, newest first. Auth: web lane, any role.
string
Exact match on resourceType.
string
Exact match on actorId.
integer
default:"1"
Positive integer.
integer
default:"20"
Positive integer, maximum 500.
Response:
Errors: VALIDATION (422), UNAUTHORIZED (401).

POST /v1/web/audit

Appends one entry. Responds with status 201. Auth: web lane, any role.
string
required
At least 1 character. The service stores it as sent and does not compare it to the caller.
string
required
At least 1 character.
string
required
At least 1 character.
string
Optional id of the affected record.
object
Optional JSON object.
Response: the created audit entry. Errors: VALIDATION (422), UNAUTHORIZED (401).

Indexes

AuditLog is indexed on studioId, on studioId, resourceType and on studioId, createdAt, which covers the list query with and without the resourceType filter. The actorId filter has no index of its own.