Returns one keyset page of the merged crypto, admin and authentication audit stream across every tenant, ordered server-side by (event_timestamp DESC, event_source, log_id DESC) and including platform-plane rows. Each row carries its tenant identifier. The stream is narrowed to the event sources the caller's scopes admit, and the set it was narrowed to is returned in admittedSources: audit.platform.crypto.read admits crypto, audit.platform.admin.read admits admin, audit.platform.auth.read admits auth, and audit.platform.all.read admits all three. A caller admitted to no source receives 403, never an empty page. Platform-tenant (ROOT) authentication is required in addition to the scope. Pagination is by opaque cursor: pass back nextCursor to continue, and read hasMore to learn whether more rows exist. There is no offset ceiling and no sort parameter - a cursor is valid only for the ordering it encodes. tenantIds filters within what the caller may already read; omitting it means every tenant. The applied window and the maximum this feed accepts are stated in appliedRange, and the scope-bar figures for that same window, filter set and source set in scopeBar.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||