---
title: "Inspect Access History"
description: "Check retained app access and authority changes, understand missing records, and choose path privacy."
url: "https://tslink.md/docs/access-history"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/access-log.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Use local access history to see retained activity, denied requests and authority changes. Start with the app you operate:

```bash
tslink access log --app photos --since 24h
tslink access log --who alice@example.com --decision denied --limit 50 --json
tslink status --json
tslink doctor --json
```

`--who` matches login (ASCII case-insensitive), exact node or tag. `--since` accepts a positive Go duration or RFC3339; `--until` is RFC3339. Timestamp bounds are inclusive. Newest events come first; default limit 100, maximum 10,000. Summaries cover all retained matches before list truncation. Denials do not advance last allowed access. TCP open/close, lifecycle and MCP intent/completion records are events, not unique visitors or successful-operation counts.

MCP `access_log` and `access_summary` use the same filters. Reduced roles need explicit app grants: inventory access alone does not grant history or app access. Filtering precedes aggregation and truncation; mixed-app receipts require every affected app to be permitted.

## Interpret identity and receipts

HTTP/file records, TCP open/close, guest decisions and lifecycle/MCP receipts share the query. WhoIs attests login/node/tags where available; tagged nodes have no human login. Public Funnel uses `public`, not a verified person; guest link IDs and labels do not identify visitors. Unknown private callers retain only a coarse address prefix. Enrichment can be absent and does not imply fresh WhoIs on every proxy request.

Owner mutation receipts are also readable with:

```bash
tslink mcp-audit --json
```

A persisted intent precedes an MCP mutation; its completion has the same ID. A missing completion means **unknown outcome**. A failed intent write refuses the mutation; a failed completion write says effects may have occurred. Registry changes and lifecycle receipts are separate commits, so a post-commit receipt failure or crash may leave an authority change without its receipt. Inspect actual state before retrying.

## Choose path privacy

```bash
tslink access path photos prefix
tslink access path sensitive off
tslink access path photos inherit
tslink config set access-log-path-mode prefix
tslink config set access-log-enabled false
```

Default `prefix` records the first sanitized path segment. `full` opts into all sanitized segments and can retain app-specific sensitive names/bearer paths; use `off` where necessary. Queries/fragments and known TSLink bearer segments are removed. Headers, cookies, bodies, tokens, PINs and full URLs are not event fields. Global `off` overrides per-app settings; `inherit` clears the local override. Turning off daemon recording leaves retained history queryable and mutation receipts independently enabled. Per-app changes hot reload; global settings require a daemon restart.

## Retention and missing history

Daemon history lives in `~/.config/tslink/access-log/` with a bounded asynchronous queue. Defaults: 30 UTC calendar days including today, 64 MiB data cap, queue 1,024; oldest segments rotate out. A full queue or disk failure drops events while requests continue serving. Crashes can lose queued events; incomplete headers and tailnet-policy packets rejected before dispatch have no HTTP record. Current `status`/`doctor` reports drops, missing-history windows and stable errors; daemon liveness alone is not evidence of complete history.

The independent mutation journal `mcp-audit.json` rotates at 1,024 entries or 1 MiB and has different retention. Access-log health describes the daemon store, not this journal. History stays local and offers **no completeness, compliance or external log-shipping guarantee**. `tslink logs` remains useful for stderr daemon diagnostics, a separate surface.

Related: [MCP roles](https://tslink.md/docs/mcp-scopes.md) · [Guest links](https://tslink.md/docs/guest-links.md) · [Daemon](https://tslink.md/docs/daemon.md#structured-logging) · [Configuration](https://tslink.md/docs/configuration.md).

Sources: [TSLink access-log.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/access-log.md)
