Record admin-panel activity (internal — called by admin-portal)
Appends a batch of admin-panel activity records: one R2 audit object and one D1 row each, idempotent on the record id. Authenticated by X-Admin-API-Key alone — the caller is the admin-portal, not an operator, and the denied-sign-in records it reports are by definition ones whose JWT this worker refuses.
curl -X POST "https://api.spkey.co/admin/activity" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
-H "X-API-Key: YOUR_API_KEY" \
-d '{
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
}'
import requests
import json
url = "https://api.spkey.co/admin/activity"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)",
"X-API-Key": "YOUR_API_KEY"
}
data = {
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
}
response = requests.post(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://api.spkey.co/admin/activity", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)",
"X-API-Key": "YOUR_API_KEY"
},
body: JSON.stringify({
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
}`)
req, err := http.NewRequest("POST", "https://api.spkey.co/admin/activity", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
req.Header.Set("X-API-Key", "YOUR_API_KEY")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.spkey.co/admin/activity')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
request['X-API-Key'] = 'YOUR_API_KEY'
request.body = '{
"records": [
{
"id": "example_string",
"occurredAt": "example_string",
"actor": "example_string",
"access": "full",
"kind": "sign-in",
"action": "example_string",
"method": "null",
"path": "null",
"query": "null",
"status": "null",
"outcome": "allowed",
"durationMs": "null",
"detail": "null"
}
]
}'
response = http.request(request)
puts response.body
{
"success": true,
"recorded": 3.14
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/admin/activity
Target server for requests. Edit to use your own host.
JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.
API key for B2B organization access. Provided during organization onboarding.
The media type of the request body
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.
API Key for authentication. API key for B2B organization access. Provided during organization onboarding.
Body
Responses
Rows written to the D1 projection.