Audit log

Every connect, query, share, and credential change — searchable, exportable, streamable.

Last updated

The Cocobox audit log is the source of truth for who did what, when, from where, and what happened. It captures human and machine activity uniformly and lives outside the application database for tamper resistance.

What’s logged

  • Authentication — login, logout, MFA challenge, failed attempts.
  • API keys — create, update, delete, key-prefix-only redaction.
  • Connections — create, edit, test, credential rotation, share, revoke, delete.
  • Queries — connection id, statement (truncated to first 4 KB), duration, row count, error if any. Statement content can be globally redacted in workspace settings.
  • MCP tool calls — tool name, arguments (redactable), session id, result code.
  • Workspace — invite, join, role change, leave.
  • Billing — plan change, invoice, refund.

Anatomy of a log entry

{
  "id": "evt_01HF2X7Y9KQR…",
  "ts": "2026-05-01T14:22:11.482Z",
  "actor": {
    "type": "user",
    "id": 17,
    "name": "Ada Lovelace",
    "email": "ada@example.com",
    "ip": "203.0.113.7",
    "user_agent": "vscode-copilot/1.95.0 (mcp)"
  },
  "action": "query.run",
  "target": { "type": "connection", "id": 42, "name": "prod-readonly" },
  "result": "ok",
  "details": {
    "statement_kind": "SELECT",
    "rows": 318,
    "duration_ms": 412,
    "model": null
  }
}

For machine actors, actor.type is api_key and the id references the key’s database id (never the secret).

Search & filter

In the app: Settings → Audit log. Filter by:

  • Date range
  • Actor (user or API key)
  • Action prefix (e.g. query.*, connection.share)
  • Target type / id
  • Result (ok / error)
  • IP

URL parameters are sticky — bookmark a saved filter for repeated investigations.

Retention

PlanRetention
Trial30 days
Starter90 days
Team365 days
Enterprise365 days + custom export to your bucket

You can extend retention on Team by exporting logs (see below). Enterprise plans can stream to your own SIEM.

Export

Export the current filter view as JSON or CSV. The export includes every field of every entry — no truncation.

curl https://api.cocobox.io/audit/export?since=2026-04-01 \
  -H "Authorization: Bearer $JWT" \
  -o audit-april.json

Streaming

Enterprise: stream every event to your SIEM via webhook (Splunk HEC format), Kinesis, or S3. Configure under Settings → Audit log → Streaming.

Tamper resistance

Audit entries are append-only at the storage layer. Each entry includes a hash of the previous entry, forming a chain. The latest hash is published daily to a write-once log. Anyone can verify the chain — instructions in Security → Audit chain.