Browse the api reference

List Graph Mutations

get/v1/graphs/{graph_id}/audit/mutations

Part of Graph Audit.

Every call that changed this graph, newest first: REST operations, external MCP clients, and in-app AI operator runs. Each entry names the operation, the outcome, who made it and with which credential, and the objects it touched. Arguments are not stored, only their SHA-256 fingerprint. Requires graph admin.

Authentication

Authenticate in any one of these ways — not all of them:

  • API key in the X-API-Key header.
  • Bearer token in the Authorization header.

Path parameters

NameTypeDescription
graph_idrequiredstringGraph identifier

Constraints: matches ^(kg[a-f0-9]{16,}(?:_[a-zA-Z0-9]{1,20})?|sec(?:_[a-zA-Z0-9]{1,20})?|library)$

Query parameters

NameTypeDescription
surfaceoptionalstringOnly calls from this surface

One of: api, mcp, operator

operation_nameoptionalstringOnly this operation or MCP tool
user_idoptionalstringOnly calls made as this user
operation_idoptionalstringOnly calls from this REST operation or operator run
sinceoptionalstring (date-time)Only calls at or after this time
untiloptionalstring (date-time)Only calls before this time
cursoroptionalstringThe `next_cursor` of the previous page
limitoptionalintegerEntries per page

Default: 50

Constraints: 1–200

Example request

curl
curl -X GET "https://api.robosystems.ai/v1/graphs/{graph_id}/audit/mutations" \
  -H "X-API-Key: $ROBOSYSTEMS_API_KEY"

Responses

200 Successful Response

FieldTypeDescription
graph_idrequiredstring
entriesrequiredMutationAuditEntry[]

One mutating call on the graph.

MutationAuditEntry fields
FieldTypeDescription
idrequiredstring

Audit entry identifier

occurred_atrequiredstring (date-time)

When the call finished

surfacerequiredstring

Where the call came from: 'api' for a REST operation, 'mcp' for an external MCP client, 'operator' for an in-app AI operator run such as the console's /do

One of: api, mcp, operator

operation_namerequiredstring

The operation or MCP tool that ran

statusrequiredstring

Whether the call succeeded; a failed call changed nothing it reports

One of: completed, failed

error_codeoptionalstring

Why a failed call failed

duration_msrequirednumber

How long the call took

user_idoptionalstring

The user the call ran as

auth_methodoptionalstring

How the caller authenticated, for example 'api_key' or 'oauth'

api_key_prefixoptionalstring

The first characters of the API key used, when one was

request_idoptionalstring

The HTTP request that made the call

operation_idoptionalstring

The REST operation's envelope id, or the operator run's operation id: every write an operator run makes shares it

operator_typeoptionalstring

The operator that made the call, for surface 'operator'

arguments_fingerprintoptionalstring

SHA-256 of the call's arguments. The arguments themselves are not stored

object_idsoptionalstring[]

Identifiers of the objects the call touched

next_cursoroptionalstring

Pass as cursor for the next, older page; null on the last page

StatusMeaning
400Invalid request
401Authentication required
403Access denied
404Resource not found
422Validation Error
429Rate limit exceeded
500Internal server error