Security events

Endpoint POST /api/v1/events with a security object

A security event is an ordinary event with a security object. Blipit groups them by actor and address and applies the thresholds under Alerts. The Login attempts guide has the full example; this is the field reference.

1The security object

kind: login_failed, login_succeeded, login_blocked, password_reset_requested or privilege_granted. actor: the login name or email tried (required). actor_id: the resolved user id when known. ip: the client address. user_agent. database: which instance, for multi-database hosts. outcome: free text such as bad_password or unknown_user. target: for privilege_granted, who or what was granted.

json
{
  "kind": "login_failed",
  "actor": "admin",
  "ip": "203.0.113.42",
  "user_agent": "Mozilla/5.0",
  "outcome": "bad_password"
}

2Rules

Use a fresh event_id per attempt. Never include the password. Send with the secret key from the server that checks credentials.

3Responses

202 {id} accepted. 403 {reason: 'security_needs_secret_key'} when sent with a public key. 403 {reason: 'security_monitoring_not_in_plan'} on plans without security monitoring; back off for a while.

Good to know

  • Security events always keep their full payload and are exempt from snooze.
  • Odoo sends these on its own when Monitor interactive logins is ticked.

Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.