Skip to main content
theauth-go emits audit events via EmitAudit. Every event is stored in audit_events with an action string, a target ref, actor metadata (user, agent, org, IP, user-agent), and a redacted metadata map. The spelling of every action listed here is part of the v1.0 stability commitment. Existing actions keep their name and target shape through every minor release. New actions may be added in minor releases; callers must not switch exhaustively on action strings.

Identity and session events

Identity linking events (v2.3)

SCIM provisioning events

Organization events

RBAC events

Agent and delegation events (v2.0)

Admin surface events

Redaction

DefaultRedactor masks values at any nesting depth whose key (case-insensitive) matches: password, secret, token, code, refresh_token, access_token. The redacted value is replaced with "[REDACTED]". Override the redactor by setting AuditConfig.Redactor.

Querying audit events

Stats counters

Monitor audit pipeline health via a.Stats():
Last modified on October 7, 2026