Audit log
The audit log is the ledger of workspace-changing actions — key mints and revocations, product and variant changes, deliveries, webhook endpoints, shipping settings, partner provisioning. It's the same data the portal's activity view renders, and the same data you'd hand to a compliance reviewer asking "who did what when?". This page covers the fulkruma.auditLog namespace. For HTTP fields, see API: Audit log.
Namespace
fulkruma.auditLog — every method:
fulkruma.auditLog.list(params?)
One method. Audit entries are written by the system only — you can't create or delete them via the SDK by design.
Methods
auditLog.list
Signature. fulkruma.auditLog.list(params?: { action?: string; target_type?: string; limit?: number }): Promise<{ entries: AuditEntry[] }>
Returns audit entries newest-first. Filters:
action— a prefix of the action name:'api_key.'matchesapi_key.createdandapi_key.revoked;'product'matches everyproduct.*action.target_type— the exact resource type, e.g.'Product','ApiKey'.limit— default 100, max 500.
There is no cursor and no date filter: a call returns the newest limit entries that match. To reach further back, narrow action / target_type.
const { entries } = await fulkruma.auditLog.list({ action: 'api_key.', limit: 50 });
for (const e of entries) {
console.log(e.createdAt, e.actorType, e.actorId, e.action, e.targetId, JSON.stringify(e.after));
}
Action names in use:
api_key.created/api_key.revokedproduct.created/product.updated/product.archivedvariant.created/variant.updated/variant.archiveddelivery.created/delivery.extend/delivery.reset-downloads/delivery.revokewebhook.created/webhook.updated/webhook.deletedshipping.origin_updated/shipping.config_updatedpartner.workspace_provisionedstorlaunch.product.synced
The table of what triggers each lives in API: Audit log.
Types
interface AuditEntry {
id: string;
accountId: string;
actorType: 'user' | 'api_key' | 'system';
actorId: string | null; // Huudis user ID, or the workspace ID for an API-key call
actorEmail: string | null;
action: string;
targetType: string | null;
targetId: string | null;
ip: string | null;
userAgent: string | null;
before: Record<string, unknown> | null;
after: Record<string, unknown> | null;
metadata: Record<string, unknown>;
createdAt: string;
}
before / after carry the fields the action changed and vary by action — treat them as unknown-typed and pick fields out at the per-action call site. See API: Audit log.
Common patterns
Tail the most recent activity
For a "what just happened?" pane:
const { entries } = await fulkruma.auditLog.list({ limit: 25 });
return entries; // already newest-first
Export what the log holds for one resource type
For an export-to-CSV job, take the most the endpoint returns in one call:
const { entries } = await fulkruma.auditLog.list({ target_type: 'Product', limit: 500 });
for (const e of entries) writeRow(e);
If a resource type has more than 500 entries, only the newest 500 come back; split the export by action prefix to reach more.
Filter on action
For a security review focused on key management:
const { entries } = await fulkruma.auditLog.list({ action: 'api_key.', limit: 500 });
const minted = entries.filter((e) => e.action === 'api_key.created').length;
console.log(`${minted} keys minted, ${entries.length - minted} revoked (newest 500)`);
Reconcile against your own logs
If your service also keeps an audit trail, you can cross-check against Fulkruma's by actorId + time window:
async function reconcile(actorId: string, fromIso: string) {
const { entries } = await fulkruma.auditLog.list({ limit: 500 });
return entries.filter((e) => e.actorId === actorId && e.createdAt >= fromIso);
}
Errors
| Code | Status | Cause |
|---|---|---|
NO_ACCOUNT |
403 | The credentials resolve to no workspace. |
Unknown action / target_type values aren't errors — they match nothing and return an empty list.
Next
- API keys — the most-audited resource.
- Webhooks — real-time events for shipments, stock and licenses (the audit log itself emits none).
- API: Audit log — HTTP reference, including the full action table.