The credentials route builds a change list ('ghl:updated', 'stripe:disconnected') and writes an integration.credentials_changed audit row with the actor and org. The secret values are deliberately excluded.
Also called: who changed the API key · audit trail · compliance log
- 1A save or disconnect is processed.
- 2A changed[] array records the integration and the direction.
- 3logAudit writes the row with actor name, user id and org id.
- 4Credential caches are dropped so the next call uses the new values.
The inline comment states the driver: 'Audit the credential change (which integration, connect vs disconnect — NEVER the secret values). Satisfies the ISP control that integration-credential changes are logged.'
- Credential changes were invisible after the fact.
- A security policy required logged credential changes.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →