Read the admin-panel activity log
Every admin-portal request an operator made, newest first: sign-ins, page reads and mutations, each with the operator email, the access tier they held at the time, the route, the HTTP status and whether it was allowed, denied or errored. Filter by rolling time window (24h / 7d / 30d / all — rolling rather than calendar, so it means the same thing in every time zone), operator, kind and outcome. Requires dual auth: X-Admin-API-Key + JWT; read-only accounts may read it.
curl -X GET "https://api.spkey.co/admin/activity?range=24h&actor=example_string&kind=sign-in&outcome=allowed&limit=42&offset=null" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
-H "X-API-Key: YOUR_API_KEY"
import requests
import json
url = "https://api.spkey.co/admin/activity?range=24h&actor=example_string&kind=sign-in&outcome=allowed&limit=42&offset=null"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)",
"X-API-Key": "YOUR_API_KEY"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://api.spkey.co/admin/activity?range=24h&actor=example_string&kind=sign-in&outcome=allowed&limit=42&offset=null", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)",
"X-API-Key": "YOUR_API_KEY"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api.spkey.co/admin/activity?range=24h&actor=example_string&kind=sign-in&outcome=allowed&limit=42&offset=null", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
req.Header.Set("X-API-Key", "YOUR_API_KEY")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.spkey.co/admin/activity?range=24h&actor=example_string&kind=sign-in&outcome=allowed&limit=42&offset=null')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
request['X-API-Key'] = 'YOUR_API_KEY'
response = http.request(request)
puts response.body
{
"total": 3.14,
"limit": 3.14,
"offset": 3.14,
"hasMore": true,
"range": "24h",
"from": "null",
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/admin/activity
Target server for requests. Edit to use your own host.
JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.
API key for B2B organization access. Provided during organization onboarding.
Rolling window back from now. Default 7d.
Exact operator email.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.
API Key for authentication. API key for B2B organization access. Provided during organization onboarding.
Query Parameters
Exact operator email.
sign-insign-in-deniedreadmutatealloweddeniederrorResponses
24h7d30dall