DocumentationAuditAudit API

Audit API

The Audit API lets your own systems read events from Audit and write events into it. Use it for reports, for monitoring, or to record the actions of your own applications next to those of Doc Gen.

The API is for one company at a time. Every call reads or writes the events of that company only.

The Audit API runs on api.audit.metaforce.net. All paths below start with https:// and that host.

Authentication

Every call needs a bearer token in the Authorization header. Get the token as described in Authentication, and see REST API for the other Doc Gen APIs. You create the client id and client secret in Administration, under Integration, in API Clients. The Client Type you choose there decides what the token may do.

CallToken needs
Read eventsAn API client with Client Type Standard (scope api.external), or a signed-in company administrator.
Write an eventAn API client with Client Type Audit (scope api.audit). This type can only post events.

A call without a valid token gets 401. A token that is not allowed to make the call gets 403.

Read events

Search the events of your company. This is the call the Audit list uses.

POST /api/Audit

FieldTypeDescription
dateFromdateFirst day to include.
dateTodateLast day to include. The whole day is included.
levelnumberOptional. 1 is Information, 2 is Warning, 3 is Error.
sourcenumberOptional. The source number from the table further down.
searchtextOptional. Matches the event name only.
skipnumberHow many events to skip, for paging.
takenumberHow many events to return. When you leave it out or send 0, skip is ignored and the answer holds every matching event, so always send take when you page.

Dates count as whole days. The events come back newest first.

curl -X POST "https://api.audit.metaforce.net/api/Audit" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
  "dateFrom": "2026-09-01",
  "dateTo": "2026-09-30",
  "level": 1,
  "source": 2,
  "search": "Dialog definition",
  "skip": 0,
  "take": 15
}'

The answer holds the events of this page, the number of events that match in total, and how long the search took in seconds:

{
  "eventLogs": [
    {
      "id": "6abd66c5434ead4965395927",
      "createdDate": "2026-09-30T21:45:12Z",
      "logName": "Dialog definition folder added",
      "source": 2,
      "level": 1,
      "user": "Kari Nordmann",
      "category": "Administration",
      "gdpr": false,
      "description": { "Company": "Fjordbank AS" }
    }
  ],
  "totalRecords": 153,
  "searchTimeSeconds": 0.04
}

To read all events, call again with skip set to the number of events you have already read until you have totalRecords of them.

Read one event

GET /api/Audit/{id}

Returns one event with the same fields as in the list. Use the id from a search result. It needs the same token as a search. An id that does not exist in your company answers 400.

Write an event

Record an event from your own system. It appears in the Audit list like any other event.

POST /api/EventLogAudit

The token needs the scope api.audit, which an API client with Client Type Audit gets.

FieldRequiredDescription
customerIdYesThe id of your company.
logNameYesThe name of the event. This is what you search for and what the Event column shows.
userYesThe user the event belongs to.
sourceYesThe source number from the table below.
levelYes1 is Information, 2 is Warning, 3 is Error.
environmentIdNoThe environment the event belongs to.
eventIdNoA number or code for the event. Shown as Event ID.
opCodeNoShown as OpCode.
categoryNoShown as Category.
keywordsNoShown as Keyword.
computerNoShown as IP.
gdprNotrue when the event holds personal data. Shown as GDPR.
logDateUtcNoWhen the event happened, in UTC. It is stored with the event but not shown or returned. Logged and createdDate show when Audit received the event.
descriptionYes, in practiceA JSON object with facts about the event, shown in the Description card. Send at least {}. Do not add a Company value: Audit puts the name of your company in front of the first value you send.
curl -X POST "https://api.audit.metaforce.net/api/EventLogAudit" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
  "customerId": "YOUR-COMPANY-ID",
  "logName": "Payment reminder sent",
  "user": "Anna Andersson",
  "source": 9,
  "level": 1,
  "category": "Billing",
  "gdpr": true,
  "logDateUtc": "2026-09-30T08:30:00Z",
  "description": {
    "Customer": "Nordlys Forsikring AB",
    "Invoice": "2026-1042"
  }
}'

A successful call answers 200 with no body. An event without a description, or with a Company value in it, also gets 200 but is not stored, so check that your event appears in the Audit list the first time you send one. A call that misses a required field answers 400 with a message such as CustomerId not set, Event name not set or User not set.

Source numbers

NumberSource
1Doc Gen
2Smartforms
3DigitalSigning
4MFDX
5Viewpoint
6TextLibrary
7WebEditor
8IdentityServer
9Workflow
10MetaTool
11Archive
12PingDoxAdmin
13Support
14Metaforce Solution
15Custom
16Interact Admin

Events written with source 15, Custom, are stored, but the Source filter in the application does not offer it. See Events and sources for what the sources mean.

Limits and errors

AnswerMeaning
200The call worked.
400A required field is missing, a value is not valid, or the event id does not exist. The body says what is wrong.
401The token is missing or not valid.
403The token is valid but is not allowed to make this call, for example writing an event with a token that does not have the scope api.audit.

The API has no calls to change or delete events. Use log forwarding when you want every new event sent to your own system as it happens.