The organisation's audit log, newest first.
const url = 'https://api.opdns.io/v1/auth/audit?limit=50';const options = {method: 'GET', headers: {cookie: 'opdns_session=<opdns_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://api.opdns.io/v1/auth/audit?limit=50' \ --cookie opdns_session=<opdns_session>Token scope: account:read. Append-only entries for sign-ins and failures,
credential and session changes, token create and revoke, profile, node,
export and deletion events of the caller’s organisation.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Page size.
The next_cursor of the previous page (opaque).
Responses
Section titled “Responses”A page of entries.
object
object
Who acted: account:<id>, token:<id>, system, ddns, …
What happened, e.g. auth.login, auth.login_failed, token.create,
profile.delete. profile.update (name, security, parental, settings,
rules or lists changed) carries a compact diff in meta: section
(profile, rules or lists), version, and for profile a changes
map of <section>.<field> (or name) to {from, to} or, for list-valued
fields, {added, removed}; for rules deny/allow/rewrites and for
lists the top level hold {added, removed} (at most 20 entries each,
with added_count/removed_count when capped).
What it happened to, e.g. session:<id>, profile:<id>.
object
Cursor of the next page (pass it as cursor); null on the last page.
Examplegenerated
{ "entries": [ { "id": 1, "org_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "actor": "example", "action": "example", "target": "example", "meta": {}, "at": "2026-04-15T12:00:00Z" } ], "next_cursor": "example"}Malformed request.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/bad_request", "title": "Bad Request", "status": 400, "code": "bad_request", "detail": "invalid JSON body", "request_id": "5f2c9a0e7b1d4c38"}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Authenticated but not allowed: insufficient_scope, session_required, csrf_rejected, mfa_enrolment_required (restricted session), mfa_required (an operator action, or an admin-scoped token, from a session signed in with the password alone; not in dev), reauth_required (sign in again within five minutes), account_pending_deletion (the account is in its deletion cooling-off).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/insufficient_scope", "title": "Forbidden", "status": 403, "code": "insufficient_scope", "detail": "the token lacks the profiles:write scope", "request_id": "5f2c9a0e7b1d4c38"}Field validation failed (validation_failed, unknown_list).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/validation_failed", "title": "Unprocessable Content", "status": 422, "code": "validation_failed", "detail": "the request has invalid fields", "errors": [ { "field": "settings.block_mode", "message": "one of nxdomain, refused, null, block-page" } ], "request_id": "5f2c9a0e7b1d4c38"}