What gets logged
For every gateway request, the audit log records:- Timestamp and request ID
- The API key and team that made the request
- The model and provider targeted
- Token counts and estimated cost
- HTTP status code and latency
- Request and response bodies (if
log_bodies: true, stored after PII redaction) - Which guardrails ran and their outcomes
- The SHA-256 hash chained to the previous entry
When
log_bodies: true, bodies are stored after PII redaction. Raw, pre-redaction content is never persisted — your users’ sensitive data stays out of the audit log.Configuration
retention_days to match your compliance requirements. Entries older than the retention window are automatically pruned.
Querying the audit log
Verifying audit integrity
Run an integrity check at any time to confirm the hash chain is intact:Use cases
Compliance audits — export audit entries for a date range to satisfy SOC 2 or regulatory requirements. Every AI interaction is on record. Security investigation — when you suspect a leaked key was used maliciously, query the audit log by API key to see exactly what was sent and received. Debugging guardrail behavior — check whether a guardrail triggered, what it matched, and whether it was in monitor or block mode. Cost attribution — use token counts in audit entries to attribute AI spend to specific teams, projects, or users beyond what aggregate metrics provide.Next steps
- Configure metrics for real-time dashboards
- Review guardrails that generate audit events
- Set up teams and permissions to control who can query audit data