---
search:
  tags:
    - timeline
    - GET
seo:
  description: >-
    What happened in the sandbox, for its org only: lifecycle calls and the…
    Reference for the GET /v1/sandboxes/{sandbox}/events endpoint in the pols.so
    API.
sidebar:
  label: The sandbox's timeline, newest first
  badge: GET
title: The sandbox's timeline, newest first
type: openapi-operation
---
What happened in the sandbox, for its org only: lifecycle calls and
the statuses the sandbox reached, commands run through exec (command
line, exit code and duration), desktop actions, who took control of
the desktop, and, when `capture_content` is enabled, the first and
last 4 KiB of command output, typed text, and screenshots with
thumbnails. Each event says who caused it. Content capture is off by
default.

Environment values, vault values and stdin are never recorded, nor
is the output of a command that received stdin: its stdout reads
`[output not recorded: command received stdin]`.
Before an event is stored, its command line, output, typed text and
errors are masked, best effort: the values of the sandbox's vault
entries (at least 4 bytes, as injected when the sandbox was created
and as they are now) and environment variables (at least 8 bytes,
the sandbox's and the command's own) become `[redacted NAME]`, and
common token formats become `[redacted]`: Authorization, Bearer and
Basic header values; `sk-`, `ghp_`, `gho_`, `github_pat_`, `xoxb-`
and `xoxp-` tokens; AWS access key IDs; PEM private keys; and the
values of `token`, `secret`, `password` and `api_key` pairs. Other
secrets in opted-in content may be recorded. The injected values are
held in memory only, so after a restart of the server a vault value
replaced since the sandbox was created is no longer masked.

Events are kept for `retention.events_days`, thumbnails for
`retention.screenshots_days`, and each org's timeline has a size cap
beyond which its oldest events are deleted. Deleting a sandbox
deletes its timeline, so a deleted sandbox has none. Page with
`before` set to `next_before`.

`GET /v1/sandboxes/{sandbox}/events`
