Introduction
Read the workspace activity ledger, understand every action and scope, and connect facts to webhook delivery.
What logs are
Logs are Hoko's workspace activity ledger. Each row is a compact fact: an action happened to a record, an actor caused it, and Hoko recorded it at a specific time. Logs are designed for audit, investigation, and connecting a business change to its optional webhook deliveries.
Logs are not click analytics, request/access logs, a database backup, a before-and-after snapshot, or a copy of the changed record. They do not require a webhook. A committed action can appear in Logs without any delivery, and a receiver failure does not undo the logged action.
Use Webhooks for outbound payloads and receiver verification. Use the Logs help guide for the dashboard workflow.
Identifiers
Log exports use bare 26-character ULIDs. Examples use typed placeholders such as <log_id> and <link_id>; actual exports contain the corresponding public IDs. Storage identifiers are not part of the public contract, and the dashboard resolves records and actors into useful names wherever possible.
Access, history, and scale
Open Dashboard → Integrations → Logs when the feature is enabled in the deployment. The view requires an active account with owner membership in every active collection of the workspace, with at least one active collection. Blocked or deleted memberships do not qualify. Results are workspace-wide, not limited to the selected collection. There is no plan gate and no public log-reading API; an API key cannot authorize this dashboard view.
The history window is a viewable allowance, separate from analytics retention and webhook-delivery inspection. Downgrades hide older entries without deleting them; upgrades reveal additional history only if it is still retained. Recording supported activity continues regardless of the viewing allowance, and logs do not consume tracked-click or tracked-event quota.
The API uses bounded cursor pagination rather than loading the full ledger. Results are newest first, with at most 50 facts per page. The older-results cursor is based on the last row's timestamp and ID, so loading another page does not require an offset scan or a total-count query. Filters are applied before the page is returned.
Event catalog
The event catalog is shared with Webhooks and is the source vocabulary for the Logs scope and action filters.
Stored fields and presentation
The persisted log fact contains exactly seven fields. The dashboard may resolve a link and actor for display, and may join retained webhook deliveries, but those enrichments do not change the log fact itself.
There is no arbitrary payload column, raw form dump, password, signing secret, or before/after value. Logs cannot reconstruct or restore a deleted record. A failed transaction does not leave a successful-change log.
Browse, filter, and inspect
- Select the workspace you want to inspect, then open Integrations → Logs. 2. Start with the newest page. Use the resource filter to narrow by scope, then the action filter to choose one action within that scope. 3. Select a row to inspect its resolved record, actor, operation, and related webhook deliveries. 4. Use Load older activity to request the next cursor page. Use Back to newest when browsing older history. 5. Clear the filters when no matching activity appears. No results can mean the action was never recorded, falls outside the plan window, or is not available in this workspace view.
The viewer presents the action in user language while preserving the exact dotted value in the detail sheet. For links, the record can resolve to its short ID and destination. For actors, Hoko resolves a profile name/avatar or an API-key name; a missing actor means the system performed the action.
Webhook delivery relationship
A log can exist without a delivery. When an eligible active subscription matches the action, Hoko associates a delivery row with the log. Every webhook event uses the same thin payload: event ID, type, creation time, affected record ID, and workspace ID. lead.created and sale.created do not carry extra conversion fields. See Webhooks.
No delivery shown does not mean the action failed. There may have been no eligible subscription, publication may have been disabled, the action may not be deliverable, or the endpoint may have been deleted. For a pending, Unconfirmed, or failed delivery, choose More options → Resend. Pending reuses attempt 1, Unconfirmed requires a five-minute cooldown, and failed creates the next attempt number. A successful delivery cannot be resent from the dashboard.
Export, retention, and privacy
With data export access (Business or above), select visible rows and choose Download selected. The button shows the number of selected rows. The JSON export is an array containing only those rows from the current page:
[
{
"id": "<log_id>",
"occurredAt": "2026-08-25T10:11:12.000Z",
"action": "link.created",
"recordId": "<link_id>",
"actorId": "<profile_id>",
"operationId": "<operation_id>"
}
]Downloads do not fetch hidden history, resolved display data, or delivery details. Treat IDs as sensitive business data. There are no edit, delete, or restore controls. Deleting an endpoint removes its delivery history, not ordinary log facts; deleting a workspace can remove its associated logs. Hoko keeps delivery history for the workspace lifetime unless its endpoint or workspace is deleted.
Boundaries and troubleshooting
Logs show facts actually recorded by enabled application flows. They are not a retroactive narrative of all existing records, a database backup, or a guarantee that every external or direct database change is captured. If access is denied, verify workspace-wide owner membership, the active collection requirement, and deployment availability; a plan upgrade does not bypass the owner or deployment checks.
If a known action is missing, check the selected workspace, the action's history window, the active filters, and whether the originating mutation committed. If a webhook is missing while the log exists, troubleshoot the endpoint and its delivery state in Webhooks; do not treat the absence of a delivery as evidence that the action failed.