Skip to content
LOG-081 Logs, Records & Provider Evidence

Could an API generate account activity?

Yes. An application programming interface, or API, can generate account activity without a person using the normal website or application interface.

APIs allow software systems to communicate directly with one another.

Avoid this assumption: That an account event must have been created by a person clicking through the service’s user interface. It may have come from software.

An API can retrieve records, upload files, send messages, create users, change settings and perform many of the same actions available through a graphical interface. It may authenticate using a user token, API key, service account or application identity.

The log may therefore show a user account even though an integration, script or third-party application performed the action. Existing consent or delegated permission may allow the software to act for long periods without another login.

Investigators should identify whether the event came through the normal interface, mobile application or API. Ask for the client application, token type, application ID, scopes or permissions and request identifier.

Preserve API gateway, application, identity-provider and audit records. Look for regular patterns, machine user agents, repeated request structures and activity continuing when the user was absent.

An API event is not automatically benign. Attackers may misuse stolen tokens or create malicious applications. But the presence of a user account in the record does not prove direct interaction.

Where attribution matters, determine who authorised the application, who controlled its credentials and what system made the actual request.

Operational takeaway

An API can perform substantial activity under a user or application identity, so investigators must distinguish software-generated requests from direct human use of the account.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.