Audit API
The Audit API lets another system add its own events to the audit log of your company. To read the events in the application, see Audit application.
Every call needs a bearer token from an Audit API client. The client gets the scope api.audit and can post audit events only. See Client types.
https://api.audit.metaforce.net/api/EventLogAudit
Post an event
POST /api/EventLogAudit takes a JSON body. Property names are camel case.
| Field | What it is |
|---|---|
customerId | The id of your company. Required. The event is always stored in the log of the company that owns the API client. |
logName | The name of the log, for example Application. Required. |
source | The system the event comes from, as a number from 1 to 16. Required. See below. |
level | 1 for information, 2 for a warning or 3 for an error. Required. |
user | The user the event belongs to. Required. |
environmentId | Optional. The environment the event happened in. |
eventId | Optional. Your own event number. |
opCode, category, keywords | Optional. Free text that you can use to group events. |
computer | Optional. The machine the event came from. |
gdpr | Optional. true when the event holds personal information. |
logDateUtc | Optional. When the event happened, as a UTC date and time. |
description | A JSON object with the details of the event. Always send it, see the note below. |
📝 Note: An event without
description, or with aCompanyproperty at the top ofdescription, is answered with200but is not stored. Doc Gen addsCompanywith your company name itself.
Send the source as a number. The name, for example Custom, is accepted too.
| Number | Source | Number | Source |
|---|---|---|---|
| 1 | CenterPoint | 9 | Workflow |
| 2 | SmartForms | 10 | MetaTool |
| 3 | DigitalSigning | 11 | Archive |
| 4 | MFDX | 12 | PingDoxAdmin |
| 5 | Viewpoint | 13 | Support |
| 6 | TextLibrary | 14 | MFSolution |
| 7 | WebEditor | 15 | Custom |
| 8 | IdentityServer | 16 | InteractAdmin |
Use 15 for events from your own system.
{
"customerId": "64e4a31fdf775xxxxxxxxxx1",
"logName": "Application",
"source": 15,
"level": 1,
"user": "ingrid.berg@example.com",
"eventId": "1001",
"category": "Employment",
"logDateUtc": "2026-10-01T08:30:00Z",
"gdpr": true,
"description": {
"action": "Contract approved",
"employee": "Ingrid Berg",
"department": "Nordic HR"
}
}Answers
200with no body when the event is stored.400with a message for each field that is missing or not valid, for exampleUser not set.401when the token is missing or has expired.403when the token does not have the scopeapi.audit.
Example
const axios = require('axios').default;
async function postEvent(accessToken) {
const response = await axios({
method: 'POST',
url: 'https://api.audit.metaforce.net/api/EventLogAudit',
headers: {
'content-type': 'application/json',
'Authorization': `Bearer ${accessToken}`
},
data: {
customerId: '64e4a31fdf775xxxxxxxxxx1',
logName: 'Application',
source: 15,
level: 1,
user: 'ingrid.berg@example.com',
description: { action: 'Contract approved', employee: 'Ingrid Berg' }
}
});
console.log(response.status);
}