curl --request GET \
--url http://localhost:8080/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "http://localhost:8080/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://localhost:8080/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "8080",
CURLOPT_URL => "http://localhost:8080/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://localhost:8080/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://localhost:8080/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:8080/audit-logs")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"org_id": "<string>",
"actor_id": 123,
"actor_type": "api",
"actor_email": "<string>",
"actor_name": "<string>",
"api_key": {
"id": "<string>",
"name": "<string>",
"created_by_name": "<string>",
"created_by_email": "<string>"
},
"entity_type": "<string>",
"entity_id": "<string>",
"event_type": "<string>",
"event_category": "access",
"changes": {
"before": {},
"after": {}
},
"metadata": {},
"created_at": "2023-11-07T05:31:56Z",
"ip_address": "<string>",
"user_agent": "<string>"
}
],
"pagination": {
"total": 123,
"page": 123,
"limit": 123,
"totalPages": 123
},
"next_cursor": "<string>"
}{
"statusCode": 123,
"message": "<string>",
"error": "<string>"
}List audit logs
List audit log events newest first, filtered by event, entity, actor or date, and paged by cursor or page number. Requires the audit-logs:read scope.
curl --request GET \
--url http://localhost:8080/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "http://localhost:8080/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://localhost:8080/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "8080",
CURLOPT_URL => "http://localhost:8080/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://localhost:8080/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://localhost:8080/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:8080/audit-logs")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"org_id": "<string>",
"actor_id": 123,
"actor_type": "api",
"actor_email": "<string>",
"actor_name": "<string>",
"api_key": {
"id": "<string>",
"name": "<string>",
"created_by_name": "<string>",
"created_by_email": "<string>"
},
"entity_type": "<string>",
"entity_id": "<string>",
"event_type": "<string>",
"event_category": "access",
"changes": {
"before": {},
"after": {}
},
"metadata": {},
"created_at": "2023-11-07T05:31:56Z",
"ip_address": "<string>",
"user_agent": "<string>"
}
],
"pagination": {
"total": 123,
"page": 123,
"limit": 123,
"totalPages": 123
},
"next_cursor": "<string>"
}{
"statusCode": 123,
"message": "<string>",
"error": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Query Parameters
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$Repeat to match any of several. Known values: organization, chat_session, custom_session_status, chat_history, consumer, user, group, group_user, role, user_role, skill, user_skills, action, workflow, flow_variable, api_key, openapi_spec, twilio_credential, twitter_account, sunshine_integration, shopify_settings, airbyte_connection, email_channel, custom_domain, sequence, outbound_email, help_center, help_center_category, help_center_article, ai_instruction, website_data_source, pdf_data_source, ai_phone_agent, call_history, teammate_call, analytics, voc_insight, ai_evaluation, organization_model_version, organization_tags_definition, organization_draft_mode_settings, webhook_endpoint, agent_availability, csat_score, csat_settings, agent_assignment_settings, ai_context_custom_data_filters, alert_rule, pii_redaction_settings, security_notification_settings, mini_app, mini_app_version, mcp_server, mcp_connection, organization_secret.
11Repeat to match any of several. Known values: create, update, delete, archive, restore, delete_multiple, unpublish, login, logout, password_change, password_reset, token_create, token_revoke, settings_update, handoff_settings_update, translation_settings_update, integration_connect, mcp_tool_call, access_token_retrieved, integration_disconnect, webhook_create, webhook_update, webhook_delete, permission_grant, permission_revoke, api_key_create, api_key_delete, twitter_chat_passcode_reveal, user_invite, user_invite_accept, user_remove, email_send, message_send, teammate_call_started, teammate_call_ended, conference_participant_invited, conference_participant_removed, session_takeover, session_assignee_update, organization_update, organization_ai_profile_update, organization_global_variable_delete, update_agent_availability_status, redaction, user_invite_delete, user_invite_resend, user_invite_link_copied, alert_rule.created, alert_rule.updated, alert_rule.deleted, publish, share.
1Repeat to match any of several.
access, agent_availability, communication, configuration, data, security Events by or about this teammate: everything they did, plus sign-outs the system ended for them.
x <= 9007199254740991api, system, user next_cursor from the previous response. When set, page is ignored.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$1 <= x <= 90071992547409911 <= x <= 100Was this page helpful?