> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Tamper Events

> Endpoint the macOS guardian / Windows service POST local tamper logs to.

Persisted as high-severity audit records so SOC tooling and the Devices
UI can surface attempts to disable the agent.



## OpenAPI

````yaml /api-reference/openapi.json post /api/runtime-security/agent/tamper-events
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/agent/tamper-events:
    post:
      tags:
        - runtime-security-agent
      summary: Tamper Events
      description: |-
        Endpoint the macOS guardian / Windows service POST local tamper logs to.

        Persisted as high-severity audit records so SOC tooling and the Devices
        UI can surface attempts to disable the agent.
      operationId: tamper_events_api_runtime_security_agent_tamper_events_post
      parameters:
        - name: X-Blindsight-Device-Token
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Blindsight-Device-Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TamperEventBatch'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    TamperEventBatch:
      properties:
        events:
          items:
            $ref: '#/components/schemas/TamperEvent'
          type: array
          title: Events
      type: object
      title: TamperEventBatch
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    TamperEvent:
      properties:
        kind:
          type: string
          maxLength: 64
          title: Kind
        detail:
          anyOf:
            - type: string
              maxLength: 2000
            - type: 'null'
          title: Detail
        occurred_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Occurred At
      type: object
      required:
        - kind
      title: TamperEvent
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````