Session logs are a paid feature.If you’re using Infisical Cloud, they’re available under the Enterprise Tier. If you’re self-hosting Infisical, contact [email protected] to purchase an enterprise license to use them.
Setting up session logs
Go to Settings under Agent Vault and select Set Up Session Logs on the Session Logs card:- Turn on Enable.
- Pick the AWS Connection whose credentials write the records. It can be one from your organization or one created in Agent Vault, or select Create New Connection to add one.
- Enter the Bucket and Region of an S3 bucket you’ve already created.
- Optionally set a Key Prefix, so session logs sit under one path in a bucket you use for other things.
- Select Save.

- IAM policy
- CORS rule
Attach this identity policy (not a bucket policy) to the user or role the connection authenticates as:
Viewing session logs
Go to Sessions and select View Session Logs on the session’s row. You can filter and search the requests, and while the session is active, new logs keep appearing.
Reading session logs through the API
Reading session logs through the API
The API returns a session’s logs as chunks. A chunk is one encrypted batch of records that a proxy uploaded to your bucket. You can read a session’s logs if you created the session or you’re an Agent Vault admin.This Node.js script reads the newest page of a session’s logs:The script runs outside a browser, so the bucket’s CORS rule doesn’t apply to it.To receive new logs as they arrive, pass the response’s
1
Call the endpoint that lists session logs. It returns the newest chunks first. To get older chunks, call it again with the response’s
nextCursor as cursor.2
Download each chunk from its
presignedGetUrl within 5 minutes, before the URL expires. If presignedGetUrl is null, either the chunk is in a bucket other than the current one, or sessionLogs.storageUnavailable says why the chunk can’t be downloaded right now.3
Check that the SHA-256 digest of the downloaded bytes, as base64 without padding, matches
ciphertextSha256. If the digests differ, the chunk was changed after the proxy uploaded it.4
Decrypt the chunk with AES-256-GCM. The key is
sessionLogs.sessionKey and the IV is the chunk’s iv, both base64 decoded. The associated data is the SHA-256 digest of <sessionId>|<chunkId>|v1. The last 16 bytes of the chunk are the authentication tag.5
Parse the decrypted bytes as JSON. Each chunk holds an array of records, and
decision holds the outcome in lowercase:liveCursor as cursor to the endpoint that tails session logs, then keep calling it with each response’s nextCursor. If hasMore is true, call again right away. Otherwise, wait a few seconds before the next call. The same chunk can appear in more than one response, so skip any chunkId you’ve already read.What gets recorded
Each request produces one record with:
The outcome is one of four:
Request and response bodies, headers, and query strings aren’t recorded.
Managing session logs
Connections
Session logs use one AWS connection at a time, which you pick in the Session Logs dialog. It can be one created in Agent Vault or one your organization already has under Integrations. See AWS connection for how to create one. To update its AWS credentials, open the menu next to Configure on the Session Logs card and select Edit AWS Credentials. For an organization connection, update the credentials under Integrations instead. To add or delete Agent Vault’s AWS connections, select Manage Connections from the same menu: