Skip to main content
SecurityAudit & SIEMv1.0.0OpenAPI 3.1

Every API and MCP call is recorded with the client, the end user or AI agent it acted for, the operation, the resource, and the authorization outcome. Supports investigations, privacy reviews, and continuous monitoring.

Reference design by Iron Brick LLC. Not an official government system; endpoints and data models are adapted to each agency's systems of record during implementation.

Base URLs
  • https://dev.ironbrick.us/sandbox/audit/v1 Iron Brick sandbox (synthetic data; free developer account)
  • https://{agency-gateway}/audit/v1 Agency deployment (behind the agency API gateway)

OpenAPI YAML JSON

Authentication

Send an OAuth 2.0 bearer token from POST https://dev.ironbrick.us/oauth/token in the Authorization header. Your application must hold the scope listed on each operation. How authentication works.

ScopeGrants
audit:readRead audit events

GET /audit-events

Query audit events · requires scope audit:read

Parameters
NameInTypeDescription
actorquerystring
actorTypequerystring
resourcequerystring
outcomequerystring
from requiredquerystring
toquerystring
cursorquerystringPagination cursor from a previous response.
limitqueryintegerMaximum items to return.
Responses
200A page of audit events
400Invalid request
401Missing or invalid access token
403Caller lacks the required scope
Example request
curl -X GET "https://dev.ironbrick.us/sandbox/audit/v1/audit-events" \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "data": [
    {
      "auditId": "AUD-9930012",
      "occurredAt": "2026-09-30T14:22:05Z",
      "clientId": "partner-portal-prod",
      "actor": "adjudicator-0442",
      "actorType": "ai_agent",
      "operation": "cases.getCase",
      "resource": "CASE-2026-004817",
      "outcome": "allowed",
      "requestId": "3f1c9a52-7c1e-4f3e-9d2a-0b8e5f6a1c44"
    }
  ],
  "page": {
    "nextCursor": "eyJvZmZzZXQiOjUwfQ",
    "limit": 50
  }
}

POST /audit-exports

Export to SIEM or file · requires scope audit:read

Starts an export of audit events in JSON Lines or CEF for Splunk and other SIEM platforms.

Request body application/json
json
{
  "from": "2026-09-01T00:00:00Z",
  "to": "2026-09-30T23:59:59Z",
  "format": "cef",
  "destination": "splunk-hec"
}
Responses
202Export started
400Invalid request
401Missing or invalid access token
403Caller lacks the required scope
Example request
curl -X POST "https://dev.ironbrick.us/sandbox/audit/v1/audit-exports" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"from": "2026-09-01T00:00:00Z", "to": "2026-09-30T23:59:59Z", "format": "cef", "destination": "splunk-hec"}'

Schemas

AuditEvent

FieldTypeDescription
auditIdstring
occurredAtstring (date-time)
clientIdstring
actorstringEnd user or agent the call was made for.
actorTypestring (user | system | ai_agent)
operationstring
resourcestring
outcomestring (allowed | denied | error)
requestIdstring (uuid)