> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `GET /v1/audit`.

> # Errors

Returns `401` without usable credentials and `500` when the log cannot be
read.



## OpenAPI

````yaml /openapi.json get /v1/audit
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/audit:
    get:
      tags:
        - Audit
      summary: Handles `GET /v1/audit`.
      description: >-
        # Errors


        Returns `401` without usable credentials and `500` when the log cannot
        be

        read.
      operationId: list_audit_handler
      responses:
        '200':
          description: Audit events, newest first
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditListResponseBody'
        '401':
          description: No usable credentials
        '503':
          description: A backing store could not be reached
      security:
        - api_key: []
        - session_cookie: []
components:
  schemas:
    AuditListResponseBody:
      type: object
      description: Audit listing response body.
      required:
        - events
      properties:
        events:
          type: array
          items:
            $ref: '#/components/schemas/AuditEventBody'
          description: Events, newest first.
        next_cursor:
          type:
            - string
            - 'null'
          description: >-
            Pass back as `cursor` to read the next page. Absent at the end of
            the

            listing, which is how a caller knows to stop.
    AuditEventBody:
      type: object
      description: One audit event as returned to a customer.
      required:
        - event_id
        - action
        - actor_type
        - subject_id
        - detail
        - context
        - created_at
      properties:
        action:
          type: string
          description: Stable action code.
        actor_id:
          type:
            - string
            - 'null'
          description: The person who acted, when it was a person.
        actor_type:
          type: string
          description: Whether an automated workflow or a named person acted.
        context:
          type: object
          description: 'Structured facts: previous and new state, reason, role.'
          additionalProperties:
            type: string
          propertyNames:
            type: string
        correlation_id:
          type:
            - string
            - 'null'
          description: Request this event belongs to.
        created_at:
          type: string
          description: RFC 3339 time the action happened.
        decision_id:
          type:
            - string
            - 'null'
          description: Decision the action relates to.
        detail:
          type: string
          description: Human-readable detail.
        event_id:
          type: string
          description: Event identifier.
        subject_id:
          type: string
          description: Object acted on.
  securitySchemes:
    api_key:
      type: http
      scheme: bearer
      description: >-
        A tenant API key. Acts for exactly one tenant and cannot conclude a
        case, because a conclusion records a person.
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````