List tenant security events
GET/security/events
Returns security events across all tenants or scoped to the current admin's accessible tenants. Events cover failed login attempts, brute force detections, session anomalies, and policy violations. Use for platform-wide security monitoring and alerting.
Request
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
tenant_id | string | No | Filter events to a specific tenant. |
severity | string | No | Filter by event severity. One of: |
from | string (date-time) | No | Start of the event range (ISO 8601, inclusive). |
limit | integer | No | Default: |
Responses
200 List of security events
Content type application/json, array of object · SecurityEventV1.
| Field | Type | Required | Description |
|---|---|---|---|
id | integer | No | |
tenant_id | string, nullable | No | Tenant affected by the event. Null for platform-level events. |
event_type | string | No | Security event type (e.g. "brute_force_detected", "login_anomaly", "session_hijack_detected"). |
severity | string | No | One of: |
source_ip | string, nullable | No | IP address associated with the security event. |
user_agent | string, nullable | No | |
metadata | object | No | Contextual data relevant to this security event type. |
occurred_at | string (date-time) | No |
Example
[
{
"id": 9201,
"tenant_id": "acme",
"event_type": "brute_force_detected",
"severity": "critical",
"source_ip": "198.51.100.42",
"user_agent": "python-requests/2.31.0",
"metadata": {
"attempts": 12,
"locked_user": "user@acme.example.test"
},
"occurred_at": "2026-04-08T08:12:00Z"
}
]
Example request
Paths are relative to the control-plane API base URL ($BASE_URL below).
curl -X GET "$BASE_URL/security/events" \
-H "Accept: application/json"