Provenance
Every change through the API shows up in the record history, with the actor and the plug mark “API”. Everyone in Bodo sees what an integration did.
What the record history shows
| Call with | History shows |
|---|---|
| a personal key | the person’s name and the mark “API”, for example: Erika Mustermann changed the email |
| a service account key | the service account’s name and the mark “API”, for example: service account CRM-Abgleich created a contact |
| an app’s OAuth token | the name of the consenting person, the mark “API” and the app |
The mark’s tooltip says “Executed through the API”. Which key and which call it was is not in the history but in the request detail.
From the call to the change
- Every answer carries
Request-Idin the header, every error answerrequestIdin the body as well. - In the request log under Settings › Interfaces › API keys you find the call by that id.
- The request detail shows the changes exactly this call recorded, with a link into the history.
The request log holds no bodies, no query values and no record ids. The link to the change only comes from Bodo’s own audit log.
Who sees what
| Who | Sees |
|---|---|
| Owner of a key | own keys, own calls, the exact reason of every rejection |
| Organization admin | all keys and the usage of the organization |
| Anyone who may read the record | the history with mark and actor |
| A key itself | only itself: `GET /v1/me` and `GET /v1/rate_limit`; no request log, no key list |
How long Bodo keeps the request log: Terms of use.