Audit log and keys
Audit log
Every action in the Vault is recorded: writes, reveals, API calls, policy changes, key rotations and every refusal. Each entry shows what happened, on which secret, by whom, when, and whether it was allowed or refused and why. Secret values never appear in the log.
In the Console: Vault → Audit log (owners and admins). From the API: vault.audit.list, newest first.
| Input | Meaning |
|---|---|
path | Only entries for this secret |
outcome | allowed, denied or error |
since | Only entries from this time (ISO-8601) |
limit | Default 100, at most 500 |
Encryption
Every value is encrypted with a key unique to your organization. That key is itself protected by a hardware-backed master key. Values are never stored in plain text.
Rotate the key
Rotating creates a new key for your organization. New values use it. Existing versions keep working. The rotation is recorded in the audit log.
In the Console: Vault → Encryption key → Rotate data key (owners and admins). From the API: vault.key.rotate.
To move an existing secret onto the new key, write a new version of it.
