Observability
Activity logging, audit trails, diagnostic logs, notifications, health checks, and backups.
Activity log
A durable record of who did what:
- Sign-ins and failed attempts
- Terminal sessions (with optional per-keystroke capture, off by default)
- Admin and config changes
- API mutations
| Endpoint | Who | What |
|---|---|---|
GET /api/admin/activity | admin | Everything, filterable by user, type, and date, with cursor pagination. |
GET /api/account/activity | any user | Their own history, as actor or as the on-behalf-of subject. |
GET /api/admin/activity/verify | admin | Walks the tamper-evident hash chain and reports the first broken row. |
Tamper-evident: each row carries the previous row's hash, forming a chain, so after-the-fact edits or deletions are detectable. Old entries are pruned on a schedule. The activity writer is a supervised background worker.
Audit logging
A separate structured audit trail of all API mutations, written to logs/audit.jsonl with rotation and sensitive-data redaction. Off by default; enable and tune with CPTR_AUDIT_LOG_LEVEL and related variables (see Configuration). Some paths (/api/chats, /v1/chat) are excluded by default.
Diagnostic logging
Configurable structured application logs — text or JSON — via CPTR_LOG_LEVEL and CPTR_LOG_FORMAT. Optionally capture full upstream model requests to logs/upstream-requests.jsonl with CPTR_LOG_UPSTREAM_REQUESTS=1 for debugging provider issues.
Notifications
| Browser notifications | For task completion, approval requests, and answers AI Labs needs from you. Clicking one opens the relevant chat. |
| Notification targets | Named webhook or messaging-bot targets for chat events, so a finished task can ping a channel. |
| Update notifications | A toast when a new version of AI Labs is available. |
notify tool | The agent can send a notification to a configured target itself. |
Configure targets in Settings → Notifications.
Health checks
| Endpoint | Reports |
|---|---|
GET /api/health | Liveness. HEAD on any page returns 200 for uptime probes. |
GET /api/health/detailed | Database round-trip time, the state of each background worker (automation scheduler, timer worker, activity writer), and remaining disk space. |
The Docker image ships a HEALTHCHECK against /api/health.
Backups
Opt in with CPTR_BACKUP=1 and the SQLite database streams continuously to a replica through Litestream, with automatic restore on a fresh volume. Mount a ./backups directory (or configure a remote target in litestream.yml). See Configuration.