Key Concepts
- Scope required —
audit-logs:read - Event —
event_typesays what happened (login,logout,create,update,api_key_create, …).entity_typeandentity_idsay what it happened to - Actor —
actor_typeisuser,systemorapi. For an API key,api_keynames the key and who created it - Changes —
changes.beforeandchanges.afterhold the fields that changed, when the event has them - Read-only — entries can’t be edited or deleted
Sign-ins and sign-outs
A sign-in is an event withentity_type: "user" and event_type: "login". metadata.method says how the teammate signed in: google, microsoft, sso, partner, password or other. For sso, metadata.sso_provider_id names the connection.
A sign-out has event_type: "logout". metadata.reason says why it ended:
metadata.user_email always names the teammate, including when the system ended the sign-in. ip_address and user_agent are the request that signed in or out, when there was one.
Filtering
Every filter is optional, and filters combine.eventType, entityType and eventCategory accept one value, or the same parameter repeated to match any of several:
entityId to follow one thing, for example a workflow with entityType=workflow&entityId=<workflow id>. Use userId to follow one teammate: everything they did, plus the sign-outs the system ended for them.
Paging
Responses carrypagination (total, page, limit, totalPages) and next_cursor.
- Cursor paging (recommended) — pass
next_cursorback ascursoruntil it isnull. Events written while you page never shift the pages, so nothing is skipped or read twice. Whencursoris set,pageis ignored - Page numbers —
pageandlimitkeep working. Pages can shift if new events arrive between requests
limit is 20 by default and at most 100. page must be at least 1, and cursor must come from this workspace. Anything else is a 400.