Gazebo
    ServicesAgentsDocsSpecWritingPricing
    Log inSign up
    Log in

    Getting Started

    • Introduction
    • How Gazebo works
    • Core concepts
    • Quickstart

    Agent Access

    • Access profiles
    • Bearer tokens
    • Audit logs

    MCP

    • Overview
    • Cursor
    • Claude Code
    • Windsurf
    • Any MCP client
    • get_credential reference

    Open Standard

    • AIP Specification ↗

    Sharing Agents

    • Overview
    • Publishing an agent
    • The consent screen
    • Installing a shared agent
    • The identity stamp

    REST API

    • Authentication
    • Verification endpoint

    Security

    • Overview
    • Encryption model
    • Credential storage
    • Audit and compliance
    • Responsible disclosure
    Documentation

    Getting Started

    • Introduction
    • How Gazebo works
    • Core concepts
    • Quickstart

    Agent Access

    • Access profiles
    • Bearer tokens
    • Audit logs

    MCP

    • Overview
    • Cursor
    • Claude Code
    • Windsurf
    • Any MCP client
    • get_credential reference

    Open Standard

    • AIP Specification ↗

    Sharing Agents

    • Overview
    • Publishing an agent
    • The consent screen
    • Installing a shared agent
    • The identity stamp

    REST API

    • Authentication
    • Verification endpoint

    Security

    • Overview
    • Encryption model
    • Credential storage
    • Audit and compliance
    • Responsible disclosure
    DocsAgent AccessAudit logs

    Every credential access attempt — successful or denied — is recorded in the audit log. Logs are append-only and cannot be deleted from the dashboard.

    What gets logged

    EventLogged
    Successful get_credential callYes
    Denied get_credential call (wrong method)Yes
    Denied get_credential call (service not in profile)Yes
    get_identity callNo — read-only, no credentials returned
    list_audit_events callNo — reading logs doesn't create a log entry
    Agent bearer token validatedNo — only credential access is logged

    Log fields

    Each audit event contains:

    • Agent — the agent name and ID
    • Service — which service credential was requested
    • Method — the HTTP method the agent declared it intended to use
    • Outcome — success or denied
    • Denial reason — if denied: method_not_permitted, service_not_in_profile, or credential_not_found
    • Timestamp — UTC, millisecond precision

    Viewing logs

    Go to Logs in the Gazebo dashboard. You can filter by:

    • Agent
    • Service
    • Outcome (success / denied)
    • Date range

    Filtering by agent

    Each agent's detail page shows only that agent's audit events — useful for reviewing a specific agent's behavior before or after a policy change.

    Retention

    Audit logs are retained for the lifetime of your account. There is no automatic expiry.

    Using logs for incident response

    If you suspect a credential was misused:

    1. Check the audit log for the relevant service — look for unexpected methods or access outside normal hours
    2. Revoke the agent immediately (delete it from the Agents page)
    3. Rotate the underlying API key if the access pattern indicates it may have been forwarded to a third party
    4. Review the agent's access profile — tighten method restrictions before re-issuing

    Explore Gazebo

    Gazebo gives each agent an independent access boundary around your agent credentials, with controls for approval, auditing, and revocation.

    Scoped identities for AI agentsGive every agent only the credentials it needs.Credential security and audit controlsSee how access is protected, recorded, and revoked.
    Bearer tokensOverview
    Gazebo

    IAM for AI agents. Scoped credentials, access policies, and audit trails — without rotating keys.

    Product

    • Pricing
    • Status

    Explore

    • Services
    • Agents
    • Workflows
    • Integrations

    Content

    • Writing
    • Topics
    • Blog
    • Docs

    Free Tools

    • Scanner

    Company

    • About
    • hello@gazebohq.com
    • security@gazebohq.com

    © 2026 Gazebo. All rights reserved.

    PrivacyTermsSecurity