Gateway Call Log
The API Gateway records one row per call to a published API — including calls it refused — so you can see who used an API, what failed and how fast it was.
Each row records:
| Field | Meaning |
|---|---|
| When | Time of the call |
| Operation | The matched operationId (or the path, if no operation matched) |
| Method and path | The HTTP method and the requested path |
| User | The signed-in user the call was made for, from the caller identity (empty if none was sent) |
| Chat | The chat the call came from, when known |
| Status | The status returned to the caller |
| Upstream status | The upstream's own status code, when the call reached it |
| Error code | Why the gateway refused or failed the call (rate_limited, caller_forbidden, request_invalid, …) — see error codes |
| Duration | Total time in milliseconds |
Request and response bodies are never stored, so the log is safe to keep for APIs that handle personal or financial data.
Viewing calls
Open the API's edit page and scroll to Gateway calls. It shows the latest 50 calls and a 24-hour summary: total calls, errors (status 400 and above) and p95 duration. Click Refresh to update it.
Anyone who can read the API can see its call log; users outside the API's space can't. The same data is available from the API:
GET /api/v1/api-definitions/{id}/calls?limit=50&offset=0
{
"items": [
{
"operation_id": "getCustomer",
"method": "GET",
"path": "/customers/42",
"user_id": "8dc0525c-…",
"status_code": 200,
"upstream_status": 200,
"error_code": null,
"duration_ms": 184,
"created_at": 1791214847
}
],
"summary": { "since": 1791128447, "total": 312, "errors": 4, "p95_duration_ms": 640 }
}limit is capped at 200.
Retention
Rows older than 30 days are removed automatically. Change this with API_GATEWAY_CALL_LOG_RETENTION_DAYS. Deleting an API deletes its call log.
Related
- API Gateway — the pipeline and the error codes that appear in the log
- Gateway Policy & Security — the limits and checks that produce refusals
- Lifecycle, Versions & Audit Log — the separate audit log for changes to the API definition itself