theauth-go emits audit events via EmitAudit. Every event is stored in audit_events with an action string, a target ref, actor metadata (user, agent, org, IP, user-agent), and a redacted metadata map.
The spelling of every action listed here is part of the v1.0 stability commitment. Existing actions keep their name and target shape through every minor release. New actions may be added in minor releases; callers must not switch exhaustively on action strings.
Identity and session events
Identity linking events (v2.3)
SCIM provisioning events
Organization events
RBAC events
Agent and delegation events (v2.0)
Admin surface events
Redaction
DefaultRedactor masks values at any nesting depth whose key (case-insensitive) matches: password, secret, token, code, refresh_token, access_token. The redacted value is replaced with "[REDACTED]".
Override the redactor by setting AuditConfig.Redactor.
Querying audit events
Stats counters
Monitor audit pipeline health via a.Stats():
Last modified on October 7, 2026