> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List credential access logs

> Returns the tenant credential access-log entries in keyset order (performedAt DESC). Optional filters: credentialId, actorId, operation, and an inclusive from / exclusive to RFC3339 window. Hash-chain fields are never projected.



## OpenAPI

````yaml en/openapi/v3-current/sta.yaml get /v1/audit/credential-access-logs
openapi: 3.1.0
info:
  description: >-
    API for Lerian STA — the participant-side rail that connects the institution
    to Banco Central do Brasil's STA (Sistema de Transferencia de Arquivos)
    file-exchange system. It covers outbound and inbound file transfers, BACEN
    credential management, inbound source polling configuration, and the tenant
    trust-store for message-signing certificates.
  title: Lerian STA API
  version: v1.0.0
servers:
  - url: https://sta.sandbox.lerian.net
security:
  - BearerAuth: []
paths:
  /v1/audit/credential-access-logs:
    get:
      tags:
        - audit
      summary: List credential access logs
      description: >-
        Returns the tenant credential access-log entries in keyset order
        (performedAt DESC). Optional filters: credentialId, actorId, operation,
        and an inclusive from / exclusive to RFC3339 window. Hash-chain fields
        are never projected.
      operationId: listCredentialAccessLogs
      parameters:
        - description: Opaque keyset pagination cursor from a prior response
          explode: false
          in: query
          name: cursor
          schema:
            description: Opaque keyset pagination cursor from a prior response
            type: string
        - description: Page size; clamped to [1,100] by the service (default 25)
          explode: false
          in: query
          name: limit
          schema:
            description: Page size; clamped to [1,100] by the service (default 25)
            examples:
              - 25
            format: int64
            type: integer
        - description: Filter by credential UUID
          explode: false
          in: query
          name: credentialId
          schema:
            description: Filter by credential UUID
            examples:
              - 018f3b2a-0c1d-7a2b-9e4f-1a2b3c4d5e6f
            type: string
        - description: Filter by actor id
          explode: false
          in: query
          name: actorId
          schema:
            description: Filter by actor id
            type: string
        - description: Filter by operation label
          explode: false
          in: query
          name: operation
          schema:
            description: Filter by operation label
            examples:
              - READ
            type: string
        - description: Inclusive lower bound (RFC3339)
          explode: false
          in: query
          name: from
          schema:
            description: Inclusive lower bound (RFC3339)
            examples:
              - '2026-01-01T00:00:00Z'
            type: string
        - description: Exclusive upper bound (RFC3339)
          explode: false
          in: query
          name: to
          schema:
            description: Exclusive upper bound (RFC3339)
            examples:
              - '2026-02-01T00:00:00Z'
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponseCredentialAccessLogDTO'
          description: OK
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    ListResponseCredentialAccessLogDTO:
      additionalProperties: false
      properties:
        data:
          items:
            $ref: '#/components/schemas/CredentialAccessLogDTO'
          type:
            - array
            - 'null'
        nextCursor:
          type: string
      required:
        - data
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    CredentialAccessLogDTO:
      additionalProperties: false
      properties:
        actorId:
          type: string
        actorName:
          type: string
        credentialId:
          type: string
        id:
          type: string
        operation:
          type: string
        payload:
          additionalProperties: {}
          type: object
        performedAt:
          format: date-time
          type: string
        result:
          type: string
        sourceIp:
          type: string
      required:
        - id
        - credentialId
        - operation
        - actorId
        - actorName
        - performedAt
        - result
        - payload
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````