Every organisation's audit log, newest first (admin).
const url = 'https://api.opdns.io/v1/admin/audit?limit=50';const options = {method: 'GET', headers: {cookie: 'opdns_session=<opdns_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://api.opdns.io/v1/admin/audit?limit=50' \ --cookie opdns_session=<opdns_session>Scope admin. Filters combine: actor exact (account:<id>, token:<id>,
system, …), action exact or, ending in ., a prefix (auth.), and a
time range.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Inclusive start, RFC 3339 or Unix milliseconds.
Exclusive end, RFC 3339 or Unix milliseconds; default now.
Page size.
The next_cursor of the previous page (opaque).
Responses
Section titled “Responses”A page of entries.
object
object
Who acted: account:<id>, token:<id>, system, ddns, …
What happened, e.g. auth.login, auth.login_failed, token.create,
profile.delete. profile.update (name, security, parental, settings,
rules or lists changed) carries a compact diff in meta: section
(profile, rules or lists), version, and for profile a changes
map of <section>.<field> (or name) to {from, to} or, for list-valued
fields, {added, removed}; for rules deny/allow/rewrites and for
lists the top level hold {added, removed} (at most 20 entries each,
with added_count/removed_count when capped).
What it happened to, e.g. session:<id>, profile:<id>.
object
Cursor of the next page (pass it as cursor); null on the last page.
Examplegenerated
{ "entries": [ { "id": 1, "org_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "actor": "example", "action": "example", "target": "example", "meta": {}, "at": "2026-04-15T12:00:00Z" } ], "next_cursor": "example"}Malformed request.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/bad_request", "title": "Bad Request", "status": 400, "code": "bad_request", "detail": "invalid JSON body", "request_id": "5f2c9a0e7b1d4c38"}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Authenticated but not allowed: insufficient_scope, session_required, csrf_rejected, mfa_enrolment_required (restricted session), mfa_required (an operator action, or an admin-scoped token, from a session signed in with the password alone; not in dev), reauth_required (sign in again within five minutes), account_pending_deletion (the account is in its deletion cooling-off).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/insufficient_scope", "title": "Forbidden", "status": 403, "code": "insufficient_scope", "detail": "the token lacks the profiles:write scope", "request_id": "5f2c9a0e7b1d4c38"}Field validation failed (validation_failed, unknown_list).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/validation_failed", "title": "Unprocessable Content", "status": 422, "code": "validation_failed", "detail": "the request has invalid fields", "errors": [ { "field": "settings.block_mode", "message": "one of nxdomain, refused, null, block-page" } ], "request_id": "5f2c9a0e7b1d4c38"}