What Sesame Logs
Sesame captures the following event types in the audit trail:- Proxied HTTP requests — Target hostname, HTTP method, URL path, HTTP status code returned by the upstream API, and a UTC timestamp for every request the broker forwards on behalf of an agent.
- Approval and denial events — Agent ID, target hostname, requested HTTP method and path pattern, the decision made (approved or denied), and the timestamp of that decision.
- Revocation events — Which agent was deactivated or which specific hostname grant was revoked, the identity of the actor who initiated the revocation, and the timestamp.
- Administrative actions — Policy changes, secret updates, agent creation, and other account-level operations that affect broker behavior.
What Sesame Does Not Log
To protect the confidentiality of your data and your users’ data, Sesame deliberately excludes the following from all log entries:
- Request bodies — The payload your agent sends to the upstream API is never recorded.
- Credential and secret values — API keys, tokens, and other secrets are redacted at the proxy level before any log entry is written. A credential value can never appear in the audit trail.
- Response bodies — The data returned by the upstream API to your agent is never stored by Sesame.