TraxAuditEntry

NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See API Security.

Immutable record describing one GraphQL request, including one the endpoint policy refused. Built by the listener and passed in batches to ITraxAuditSink.WriteAsync.

Signature

public sealed record TraxAuditEntry(
    string PrincipalId,
    string? PrincipalType,
    string? OperationName,
    string Document,
    JsonObject? Variables,
    long DurationMs,
    DateTimeOffset Timestamp,
    bool Success,
    string? ErrorText,
    IReadOnlyDictionary<string, string>? Metadata = null
);

Fields

FieldNotes
PrincipalIdFrom trax:principal-id claim (qualified by scheme, {scheme}:{id}), or TraxAuditOptions.DefaultPrincipalId when absent.
PrincipalTypeFrom trax:principal-type claim. apikey, jwt, or similar. null for anonymous.
OperationNameThe GraphQL operation name, if any.
DocumentThe GraphQL document with every string literal replaced by "" and every numeric literal by 0; field names, aliases, input field names, booleans, enum values and null are kept. Past TraxAuditOptions.MaxDocumentLength it is cut to that length, marked ...[truncated], and followed by [selected fields: Type.field, ...]: every field the compiled operation selects, after fragment expansion, each schema coordinate listed once.
VariablesWhat the registered ITraxAuditRedactor returned, as a JsonObject. null by default: the default redactor records no variables.
DurationMsElapsed request time in milliseconds.
TimestampUTC when the request started, NOT when the entry was persisted.
SuccessFalse on exception, GraphQL errors in the result, or a refusal by the endpoint policy.
ErrorTextJoined error messages or the exception message, as written; not redacted. Not authorized. for a request the endpoint policy refused.
MetadataBag for host-provided extras (request IP, tenant ID, correlation ID). Not populated by the default listener.