Service account tokens
GET /v1/service-account-tokens/activity shows every privileged call made with your tokens
Every public-API call writes an activity row, which gives you an audit trail scoped to service-account tokens — who (which token), what (method and path), and how it ended (status code), plus the caller IP.
Reading it#
GET /v1/service-account-tokens/activity returns { "activity": [...] }, newest first, limit defaulting to 50 and clamped between 1 and 200. Each entry carries the tokenId, the scope used, method, path, statusCode, ip, and createdAt — for example read / GET / /v1/public-api/domains / 200.
What it is good for#
- Leak detection — calls from IPs you do not recognize, or paths you never integrated.
- Unused credentials — pair an activity-free token with its
lastUsedAt(shown on the token list) and retire it. - Scope tuning — if a token only ever exercises
read, consider droppingwriteat the next rotation.
Activity rows are written best-effort: a successful request is never failed because logging failed, and the log is only queryable through this tenant-scoped endpoint (there is no screen for it — see Rotate or revoke for the token list it complements).

