Every request that flows through the ManyLayers gateway is recorded in the audit log. The log is tamper-evident: each entry’s hash includes the hash of the previous entry, forming a chain. Any modification to a past entry breaks the chain from that point forward — giving you confidence that your audit trail hasn’t been altered. This matters for compliance (SOC 2, GDPR, HIPAA), security investigations (“what did that API key actually send?”), and debugging (“why did that guardrail trigger?”).

What gets logged

For every gateway request, the audit log records:
  • Timestamp and request ID
  • The API key and team that made the request
  • The model and provider targeted
  • Token counts and estimated cost
  • HTTP status code and latency
  • Request and response bodies (if log_bodies: true, stored after PII redaction)
  • Which guardrails ran and their outcomes
  • The SHA-256 hash chained to the previous entry
When log_bodies: true, bodies are stored after PII redaction. Raw, pre-redaction content is never persisted — your users’ sensitive data stays out of the audit log.

Configuration

audit:
  retention_days: 90     # auto-prune entries older than N days
  log_bodies: true       # store request/response bodies (post-PII-redaction)
Set retention_days to match your compliance requirements. Entries older than the retention window are automatically pruned.

Querying the audit log

curl http://localhost:8180/admin/audit \
  -H "Authorization: Bearer $ADMIN_KEY"
The query endpoint supports filtering by team, date range, model, and status code. See the API Reference for full filter parameters.

Verifying audit integrity

Run an integrity check at any time to confirm the hash chain is intact:
curl http://localhost:8180/admin/audit/verify \
  -H "Authorization: Bearer $ADMIN_KEY"
The response indicates whether the chain is intact. A broken chain tells you exactly which entry was modified — useful for forensic investigation.

Use cases

Compliance audits — export audit entries for a date range to satisfy SOC 2 or regulatory requirements. Every AI interaction is on record. Security investigation — when you suspect a leaked key was used maliciously, query the audit log by API key to see exactly what was sent and received. Debugging guardrail behavior — check whether a guardrail triggered, what it matched, and whether it was in monitor or block mode. Cost attribution — use token counts in audit entries to attribute AI spend to specific teams, projects, or users beyond what aggregate metrics provide.

Next steps