Audit log
Every connect, query, share, and credential change — searchable, exportable, streamable.
The Cocobox audit log is the source of truth for who did what, when, from where, and what happened. It captures human and machine activity uniformly and lives outside the application database for tamper resistance.
What’s logged
- Authentication — login, logout, MFA challenge, failed attempts.
- API keys — create, update, delete, key-prefix-only redaction.
- Connections — create, edit, test, credential rotation, share, revoke, delete.
- Queries — connection id, statement (truncated to first 4 KB), duration, row count, error if any. Statement content can be globally redacted in workspace settings.
- MCP tool calls — tool name, arguments (redactable), session id, result code.
- Workspace — invite, join, role change, leave.
- Billing — plan change, invoice, refund.
Anatomy of a log entry
{
"id": "evt_01HF2X7Y9KQR…",
"ts": "2026-05-01T14:22:11.482Z",
"actor": {
"type": "user",
"id": 17,
"name": "Ada Lovelace",
"email": "ada@example.com",
"ip": "203.0.113.7",
"user_agent": "vscode-copilot/1.95.0 (mcp)"
},
"action": "query.run",
"target": { "type": "connection", "id": 42, "name": "prod-readonly" },
"result": "ok",
"details": {
"statement_kind": "SELECT",
"rows": 318,
"duration_ms": 412,
"model": null
}
}
For machine actors, actor.type is api_key and the id references the key’s database id (never the secret).
Search & filter
In the app: Settings → Audit log. Filter by:
- Date range
- Actor (user or API key)
- Action prefix (e.g.
query.*,connection.share) - Target type / id
- Result (ok / error)
- IP
URL parameters are sticky — bookmark a saved filter for repeated investigations.
Retention
| Plan | Retention |
|---|---|
| Trial | 30 days |
| Starter | 90 days |
| Team | 365 days |
| Enterprise | 365 days + custom export to your bucket |
You can extend retention on Team by exporting logs (see below). Enterprise plans can stream to your own SIEM.
Export
Export the current filter view as JSON or CSV. The export includes every field of every entry — no truncation.
curl https://api.cocobox.io/audit/export?since=2026-04-01 \
-H "Authorization: Bearer $JWT" \
-o audit-april.json
Streaming
Enterprise: stream every event to your SIEM via webhook (Splunk HEC format), Kinesis, or S3. Configure under Settings → Audit log → Streaming.
Tamper resistance
Audit entries are append-only at the storage layer. Each entry includes a hash of the previous entry, forming a chain. The latest hash is published daily to a write-once log. Anyone can verify the chain — instructions in Security → Audit chain.