Read an application's change timeline
const url = 'https://api.aletheia-ops.com/api/v1/applications/example/timeline';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.aletheia-ops.com/api/v1/applications/example/timeline \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Responses
Section titled “Responses”OK
/changes list response
object
One timeline row (summary-level fields only)
object
Normalized actor identity on a timeline change
object
Are the timeline filter-rail aggregations
object
One value/count pair
object
One value/count pair
object
One value/count pair
object
One value/count pair
object
One value/count pair
object
Freshness block on every timeline response (§2.2)
object
One per-scope ingestion freshness entry
object
Examplegenerated
{ "items": [ { "id": "example", "source_system": "example", "kind": "example", "occurred_at": "2026-04-15T12:00:00Z", "recorded_at": "2026-04-15T12:00:00Z", "actor": { "type": "example", "id": "example", "display": "example", "arn": "example" }, "actor_user_id": "example", "via": "example", "aws_account_id": "example", "region": "example", "event_name": "example", "summary": "example" } ], "next_cursor": "example", "total": 1, "facets": { "source_systems": [ { "value": "example", "count": 1 } ], "kinds": [ { "value": "example", "count": 1 } ], "vias": [ { "value": "example", "count": 1 } ], "aws_accounts": [ { "value": "example", "count": 1 } ], "regions": [ { "value": "example", "count": 1 } ] }, "freshness": { "cursors": [ { "aws_account_id": "example", "region": "example", "last_event_time": "2026-04-15T12:00:00Z", "status": "example" } ] }}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}The resource does not exist, or belongs to another organization. The two are deliberately indistinguishable.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "not_found", "message": "resource not found"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}