Audit API
The Audit API lets your own systems read events from Audit and write events into it. Use it for reports, for monitoring, or to record the actions of your own applications next to those of Doc Gen.
The API is for one company at a time. Every call reads or writes the events of that company only.
The Audit API runs on api.audit.metaforce.net. All paths below start with https:// and that host.
Authentication
Every call needs a bearer token in the Authorization header. Get the token as described in Authentication, and see REST API for the other Doc Gen APIs. You create the client id and client secret in Administration, under Integration, in API Clients. The Client Type you choose there decides what the token may do.
| Call | Token needs |
|---|---|
| Read events | An API client with Client Type Standard (scope api.external), or a signed-in company administrator. |
| Write an event | An API client with Client Type Audit (scope api.audit). This type can only post events. |
A call without a valid token gets 401. A token that is not allowed to make the call gets 403.
Read events
Search the events of your company. This is the call the Audit list uses.
POST /api/Audit
| Field | Type | Description |
|---|---|---|
dateFrom | date | First day to include. |
dateTo | date | Last day to include. The whole day is included. |
level | number | Optional. 1 is Information, 2 is Warning, 3 is Error. |
source | number | Optional. The source number from the table further down. |
search | text | Optional. Matches the event name only. |
skip | number | How many events to skip, for paging. |
take | number | How many events to return. When you leave it out or send 0, skip is ignored and the answer holds every matching event, so always send take when you page. |
Dates count as whole days. The events come back newest first.
curl -X POST "https://api.audit.metaforce.net/api/Audit" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"dateFrom": "2026-09-01",
"dateTo": "2026-09-30",
"level": 1,
"source": 2,
"search": "Dialog definition",
"skip": 0,
"take": 15
}'
The answer holds the events of this page, the number of events that match in total, and how long the search took in seconds:
{
"eventLogs": [
{
"id": "6abd66c5434ead4965395927",
"createdDate": "2026-09-30T21:45:12Z",
"logName": "Dialog definition folder added",
"source": 2,
"level": 1,
"user": "Kari Nordmann",
"category": "Administration",
"gdpr": false,
"description": { "Company": "Fjordbank AS" }
}
],
"totalRecords": 153,
"searchTimeSeconds": 0.04
}To read all events, call again with skip set to the number of events you have already read until you have totalRecords of them.
Read one event
GET /api/Audit/{id}
Returns one event with the same fields as in the list. Use the id from a search result. It needs the same token as a search. An id that does not exist in your company answers 400.
Write an event
Record an event from your own system. It appears in the Audit list like any other event.
POST /api/EventLogAudit
The token needs the scope api.audit, which an API client with Client Type Audit gets.
| Field | Required | Description |
|---|---|---|
customerId | Yes | The id of your company. |
logName | Yes | The name of the event. This is what you search for and what the Event column shows. |
user | Yes | The user the event belongs to. |
source | Yes | The source number from the table below. |
level | Yes | 1 is Information, 2 is Warning, 3 is Error. |
environmentId | No | The environment the event belongs to. |
eventId | No | A number or code for the event. Shown as Event ID. |
opCode | No | Shown as OpCode. |
category | No | Shown as Category. |
keywords | No | Shown as Keyword. |
computer | No | Shown as IP. |
gdpr | No | true when the event holds personal data. Shown as GDPR. |
logDateUtc | No | When the event happened, in UTC. It is stored with the event but not shown or returned. Logged and createdDate show when Audit received the event. |
description | Yes, in practice | A JSON object with facts about the event, shown in the Description card. Send at least {}. Do not add a Company value: Audit puts the name of your company in front of the first value you send. |
curl -X POST "https://api.audit.metaforce.net/api/EventLogAudit" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"customerId": "YOUR-COMPANY-ID",
"logName": "Payment reminder sent",
"user": "Anna Andersson",
"source": 9,
"level": 1,
"category": "Billing",
"gdpr": true,
"logDateUtc": "2026-09-30T08:30:00Z",
"description": {
"Customer": "Nordlys Forsikring AB",
"Invoice": "2026-1042"
}
}'
A successful call answers 200 with no body. An event without a description, or with a Company value in it, also gets 200 but is not stored, so check that your event appears in the Audit list the first time you send one. A call that misses a required field answers 400 with a message such as CustomerId not set, Event name not set or User not set.
Source numbers
| Number | Source |
|---|---|
| 1 | Doc Gen |
| 2 | Smartforms |
| 3 | DigitalSigning |
| 4 | MFDX |
| 5 | Viewpoint |
| 6 | TextLibrary |
| 7 | WebEditor |
| 8 | IdentityServer |
| 9 | Workflow |
| 10 | MetaTool |
| 11 | Archive |
| 12 | PingDoxAdmin |
| 13 | Support |
| 14 | Metaforce Solution |
| 15 | Custom |
| 16 | Interact Admin |
Events written with source 15, Custom, are stored, but the Source filter in the application does not offer it. See Events and sources for what the sources mean.
Limits and errors
| Answer | Meaning |
|---|---|
200 | The call worked. |
400 | A required field is missing, a value is not valid, or the event id does not exist. The body says what is wrong. |
401 | The token is missing or not valid. |
403 | The token is valid but is not allowed to make this call, for example writing an event with a token that does not have the scope api.audit. |
The API has no calls to change or delete events. Use log forwarding when you want every new event sent to your own system as it happens.