Audit API

The Audit API lets another system add its own events to the audit log of your company. To read the events in the application, see Audit application.

Every call needs a bearer token from an Audit API client. The client gets the scope api.audit and can post audit events only. See Client types.

https://api.audit.metaforce.net/api/EventLogAudit

Post an event

POST /api/EventLogAudit takes a JSON body. Property names are camel case.

FieldWhat it is
customerIdThe id of your company. Required. The event is always stored in the log of the company that owns the API client.
logNameThe name of the log, for example Application. Required.
sourceThe system the event comes from, as a number from 1 to 16. Required. See below.
level1 for information, 2 for a warning or 3 for an error. Required.
userThe user the event belongs to. Required.
environmentIdOptional. The environment the event happened in.
eventIdOptional. Your own event number.
opCode, category, keywordsOptional. Free text that you can use to group events.
computerOptional. The machine the event came from.
gdprOptional. true when the event holds personal information.
logDateUtcOptional. When the event happened, as a UTC date and time.
descriptionA JSON object with the details of the event. Always send it, see the note below.

📝 Note: An event without description, or with a Company property at the top of description, is answered with 200 but is not stored. Doc Gen adds Company with your company name itself.

Send the source as a number. The name, for example Custom, is accepted too.

NumberSourceNumberSource
1CenterPoint9Workflow
2SmartForms10MetaTool
3DigitalSigning11Archive
4MFDX12PingDoxAdmin
5Viewpoint13Support
6TextLibrary14MFSolution
7WebEditor15Custom
8IdentityServer16InteractAdmin

Use 15 for events from your own system.

{
    "customerId": "64e4a31fdf775xxxxxxxxxx1",
    "logName": "Application",
    "source": 15,
    "level": 1,
    "user": "ingrid.berg@example.com",
    "eventId": "1001",
    "category": "Employment",
    "logDateUtc": "2026-10-01T08:30:00Z",
    "gdpr": true,
    "description": {
        "action": "Contract approved",
        "employee": "Ingrid Berg",
        "department": "Nordic HR"
    }
}

Answers

  • 200 with no body when the event is stored.
  • 400 with a message for each field that is missing or not valid, for example User not set.
  • 401 when the token is missing or has expired.
  • 403 when the token does not have the scope api.audit.

Example

const axios = require('axios').default;

async function postEvent(accessToken) {
  const response = await axios({
      method: 'POST',
      url: 'https://api.audit.metaforce.net/api/EventLogAudit',
      headers: {
          'content-type': 'application/json',
          'Authorization': `Bearer ${accessToken}`
      },
      data: {
          customerId: '64e4a31fdf775xxxxxxxxxx1',
          logName: 'Application',
          source: 15,
          level: 1,
          user: 'ingrid.berg@example.com',
          description: { action: 'Contract approved', employee: 'Ingrid Berg' }
      }
  });
  console.log(response.status);
}