Concepts

Usage and the request log

See how your integrations are doing, and find any request by its ID.

Oatmilk records every request made with an API key or an AI app, so you can see how an integration is doing and find out why a request failed without adding logging of your own. Open Developers › Usage for the trends and Developers › Request log for each request.

What is recorded

For each request Oatmilk keeps:

  • the request ID it returned in X-Request-Id
  • when it arrived and how long it took
  • the action, and whether it came through the REST API (GET or POST) or an AI app over MCP
  • the HTTP status and, for a failure, its error code
  • the API key it used, or the AI app and the person signed in to it

Oatmilk never records what a request sent or what it answered, and never the key itself. Requests are kept for 30 days.

A request refused before Oatmilk knows which company it's for, such as one with no key or a key that doesn't exist, isn't recorded anywhere. A request with a valid key that lacks a permission is recorded against that key, so you can see it was refused.

Who sees what

Administrators see every request made in the company. Everyone else sees the requests made with their own keys and their own AI app connections.

Usage

Developers › Usage shows the last day, 7 days or 30 days:

  • requests per day, split into those that worked, client errors (4xx) and server errors (5xx)
  • the error rate and the median and 95th percentile response times
  • the keys and apps that sent the most requests, the busiest actions and the most common error codes
  • for administrators, webhook deliveries: how many were delivered or failed each day, response times, each endpoint's success rate and why deliveries failed

Find a request

Paste an X-Request-Id into Developers › Request log to find that request. You can also filter the log by result, by key or app, and by whether it came through the REST API or MCP. Open a request to see its error code, with a link to what the code means, and the action's reference page.

From your code

The same figures are actions, so a monitoring job can read them with a key that has the api_keys:manage permission:

Shell
curl "https://app.getoatmilk.com/api/v1/accounting/developers.usage?days=7" \
  -H "Authorization: Bearer $OATMILK_API_KEY"

curl "https://app.getoatmilk.com/api/v1/accounting/developers.requests.list?status=server_error&limit=10" \
  -H "Authorization: Bearer $OATMILK_API_KEY"

Administrators can read webhook delivery figures with webhooks.deliveries.stats. See developers.usage, developers.requests.list and webhooks.deliveries.stats for every field.