Skip to main content
GET
List audit logs

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

startDate
string<date-time>
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
endDate
string<date-time>
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
entityType

Repeat to match any of several. Known values: organization, chat_session, custom_session_status, chat_history, consumer, user, group, group_user, role, user_role, skill, user_skills, action, workflow, flow_variable, api_key, openapi_spec, twilio_credential, twitter_account, sunshine_integration, shopify_settings, airbyte_connection, email_channel, custom_domain, sequence, outbound_email, help_center, help_center_category, help_center_article, ai_instruction, website_data_source, pdf_data_source, ai_phone_agent, call_history, teammate_call, analytics, voc_insight, ai_evaluation, organization_model_version, organization_tags_definition, organization_draft_mode_settings, webhook_endpoint, agent_availability, csat_score, csat_settings, agent_assignment_settings, ai_context_custom_data_filters, alert_rule, pii_redaction_settings, security_notification_settings, mini_app, mini_app_version, mcp_server, mcp_connection, organization_secret.

Minimum string length: 1
entityId
string
Minimum string length: 1
eventType

Repeat to match any of several. Known values: create, update, delete, archive, restore, delete_multiple, unpublish, login, logout, password_change, password_reset, token_create, token_revoke, settings_update, handoff_settings_update, translation_settings_update, integration_connect, mcp_tool_call, access_token_retrieved, integration_disconnect, webhook_create, webhook_update, webhook_delete, permission_grant, permission_revoke, api_key_create, api_key_delete, twitter_chat_passcode_reveal, user_invite, user_invite_accept, user_remove, email_send, message_send, teammate_call_started, teammate_call_ended, conference_participant_invited, conference_participant_removed, session_takeover, session_assignee_update, organization_update, organization_ai_profile_update, organization_global_variable_delete, update_agent_availability_status, redaction, user_invite_delete, user_invite_resend, user_invite_link_copied, alert_rule.created, alert_rule.updated, alert_rule.deleted, publish, share.

Minimum string length: 1
eventCategory

Repeat to match any of several.

Available options:
access,
agent_availability,
communication,
configuration,
data,
security
actorId
number
userId
integer

Events by or about this teammate: everything they did, plus sign-outs the system ended for them.

Required range: x <= 9007199254740991
actorType
enum<string>
Available options:
api,
system,
user
cursor
string<uuid>

next_cursor from the previous response. When set, page is ignored.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
page
integer
default:1
Required range: 1 <= x <= 9007199254740991
limit
integer
default:20
Required range: 1 <= x <= 100

Response

Default Response

data
object[]
required
pagination
object
required
next_cursor
string | null
required

Pass as cursor to fetch the next page; null on the last page.