Skip to content

Provenance

Provenance

Every change through the API shows up in the record history, with the actor and the plug mark “API”. Everyone in Bodo sees what an integration did.

What the record history shows

Call withHistory shows
a personal keythe person’s name and the mark “API”, for example: Erika Mustermann changed the email
a service account keythe service account’s name and the mark “API”, for example: service account CRM-Abgleich created a contact
an app’s OAuth tokenthe name of the consenting person, the mark “API” and the app

The mark’s tooltip says “Executed through the API”. Which key and which call it was is not in the history but in the request detail.

From the call to the change

  1. Every answer carries Request-Id in the header, every error answer requestId in the body as well.
  2. In the request log under Settings › Interfaces › API keys you find the call by that id.
  3. The request detail shows the changes exactly this call recorded, with a link into the history.
The request log holds no bodies, no query values and no record ids. The link to the change only comes from Bodo’s own audit log.

Who sees what

WhoSees
Owner of a keyown keys, own calls, the exact reason of every rejection
Organization adminall keys and the usage of the organization
Anyone who may read the recordthe history with mark and actor
A key itselfonly itself: `GET /v1/me` and `GET /v1/rate_limit`; no request log, no key list

How long Bodo keeps the request log: Terms of use.