MonetaryAI / Docs
API ReferenceAudit

Daily audit activity statistics

Whole-tenant daily counts, independent of journal filters. Defaults to today in Asia/Tashkent. Bounds use local midnight, including DST. totalActions equals createdRecords+updatedRecords+deletedRecords+otherActions. Company permission: `getAuditStatistics`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.

GET
/api/v1/audit-events/statistics

Authorization

bearerAuth
headerAuthorizationBearer <token>

Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.

Query Parameters

date?string

Calendar day yyyy-MM-dd; omitted means today in timezone

Formatdate
timezone?string

IANA timezone

Default"Asia/Tashkent"

Response Body

OK

*/*
  1. response
createdRecords?integer
Formatint64
date?string
Formatdate
deletedRecords?integer
Formatint64
otherActions?integer
Formatint64
timezone?string
totalActions?integer
Formatint64
updatedRecords?integer
Formatint64
curl -X GET 'https://api.monetaryai.uz/api/v1/audit-events/statistics'
{  "createdRecords": 0,  "date": "2019-08-24",  "deletedRecords": 0,  "otherActions": 0,  "timezone": "string",  "totalActions": 0,  "updatedRecords": 0}

Get safe audit-event metadata GET

Same safe fields as the journal; raw payload is never exposed. Other-tenant IDs return 404. Company permission: `getAuditEvent`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.

Exchange credentials for a token pair POST

On the configured central host, email/password selects the oldest active membership. On tenant hosts, the tenant is taken from the host, not the body. A user of one tenant cannot authenticate against another tenant's subdomain. Repeated failures, from one address or against one account, are answered with 429 and Retry-After. When email 2FA is enabled, valid credentials without challengeId/code return 202 and queue an eight-digit code to the stored account email. Repeat this same login with password, challengeId and code to receive tokens. Codes expire in five minutes, permit five guesses and require provider acknowledgement. No tokens are issued at the challenge step. For Google Authenticator, 202 channel=TOTP requires repeating login with email, password and totpCode (six digits) or one unused recoveryCode. For TOTP, challengeId and expiresAt are null and no email is sent. On the second-factor submission, supply exactly one factor: paired email challengeId/code, totpCode, or recoveryCode; mixed factors return 400. A TOTP is accepted once across all memberships; wait for the next 30-second code after enrollment. Five Authenticator factor attempts per five minutes are permitted. The backend returns accessToken/refreshToken in the 200 JSON body, not browser cookies. The Next.js frontend BFF stores them in HttpOnly cookies and handles browser redirects; this backend endpoint does not redirect.