Logs relating to the wrap API route

The fields described below belong to logs about the wrap API route. This route enables key wrapping.

Field

Description

Type

Examples

api_route

URL slug of the API route.

String

"/api/v1/{tenantId}/wrap"

user_agent

User agent used in the request.

String

"Chrome/27.0.1453.110"

source_address

Network traffic source (client requesting the connection).

String

"172.16.16.212"

http_status

HTTP response code that indicates the status of the request to the proxy.

Integer

Prescribed values:

"200", "400", "401", "405", "413", "415", "500"

request_payload

Data relating to the HTTP request.

Object


  reason

JSON string providing additional context about the operation. 

String

"{client:’drive’ op:’update’}"

    authorization_token

JWT guaranteeing that the user is allowed to wrap a key for ‘resource_name’.

It contains the information below:

Object


 

email: e-mail address of the user that the authorization token concerns.

String

"alice@domain.eu"

 

email_type: Origin of the user's email address.

  • google: Google accounts (default value),

  • google-visitor: account verified by Google,

  • customer-idp: IDP account.

String

 

 

role: role requested in the authorization token.

Prescribed value: "writer"

String

 

 

resource_name: resource identifier.

String

"6Bhds6BhdRkqt3Rkqt36Bhd"

 

perimeter_id: identifier to conduct verifications of authentication and authorization requests.

String

"s6Bhds6BhdRkqt3Rkqt3"

 

kacls_url: URL of the KACLS.

String

"https://someserver.eu"

       

iss: identifies the service that generates the JWT (issuer).

String

"www.google.com"

 

aud: identifies the recipient of the JWT (audience).

String array

"s6BhdRkqt3"

 

exp: identifies the expiry time after which the JWT must no longer be accepted.

Integer (timestamp in seconds)

"1694617320"

 

iat: identifies the date on which the JWT was created (issued at).

Integer (timestamp in seconds)

"1694617320"

authentication_token

JWT generated by a third-party tool that guarantees the user’s identity.

It contains the information below:

Object


 

claims: standard user data provided by the IDP.

  • email: e-mail address of the user that the authentication token concerns.

  • google_email: email address of the Google account of the user that the authentication token concerns.

  • iss: identifies the service that generates the JWT (issuer).

  • aud: identifies the recipient of the JWT (audience).

  • exp: identifies the expiry time after which the JWT must no longer be accepted.

  • iat: identifies the date on which the JWT was created (issued at).

 

 

 

String

 

String

String array

Integer (timestamp in seconds)

Integer (timestamp in seconds)

 

 

 

"username@domain.eu"

 

 

 

"www.onelogin.com"

"s6BhdRkqt3"

 

 

"1694617320"

 

 

"1694617320"

 

number_of_custom_claims: number of custom claims included in the authentication token.

Integer

2

additional_data

Additional data.
It contains the information below:

Object


   

wrap_properties: data relating to the wrap operation.

Object


 

kek_id: identifier of the KEK used.

String

"bbc9cd0b-803c-4d9c-93f9-b43bdfc0bf96"

        

version: Version of the wrap operation.

Integer

1

       

mode: Mode used for the wrap operation.

  • persistence: Persistence mode used

Object

 

 

String

 

 

 

 

"json_file"

        

cse_version: version of the service during the wrap operation.

String

"1.0.23458"

  authentication_mode: authentication mode used for the wrap operation.

String

"local-configuration", "admin-configuration", "cse-configuration"
  authentication_domain: domain used for authentication.

String

"domain.com"