> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open.cx/llms.txt
> Use this file to discover all available pages before exploring further.

> List audit log events newest first, filtered by event, entity, actor or date, and paged by cursor or page number. Requires the audit-logs:read scope.

# List audit logs



## OpenAPI

````yaml get /audit-logs
openapi: 3.1.0
info:
  title: OpenCX API
  description: >

    OpenCX is an AI-powered, all-in-one platform for customer support and
    outbound communications.


    Use this API to manage your OpenCX organization's AI agents, actions,
    conversations, contacts, and more.


    To get started, generate a new API key from the dashboard.


    ## Authentication

    All API endpoints require authentication using a Bearer token. You can
    generate an API key from your OpenCX dashboard.


    ## Rate Limiting

    API requests are rate limited to ensure fair usage. The current limits are:

    - 100 requests per minute for standard endpoints

    - 1000 requests per minute for streaming endpoints


    ## Error Handling

    The API uses standard HTTP status codes and returns detailed error messages
    in the response body.
  version: 1.0-beta
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: http://localhost:8080
    description: Development
  - url: https://api.open.cx
    description: Production
security:
  - bearerAuth: []
paths:
  /audit-logs:
    get:
      summary: List audit logs
      description: >-
        Query the audit log to see who changed what and when, including teammate
        sign-ins and sign-outs. Returns change events newest first with
        before/after diffs. Page with `page`, or pass the `next_cursor` of the
        previous response as `cursor` for stable, faster paging.
      operationId: listAuditLogs
      parameters:
        - schema:
            type: string
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
          in: query
          name: startDate
          required: false
        - schema:
            type: string
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
          in: query
          name: endDate
          required: false
        - schema:
            anyOf:
              - type: string
                minLength: 1
              - minItems: 1
                type: array
                items:
                  type: string
                  minLength: 1
          in: query
          name: entityType
          required: false
          description: >-
            Repeat to match any of several. Known values: organization,
            chat_session, custom_session_status, chat_history, consumer, user,
            group, group_user, role, user_role, skill, user_skills, action,
            workflow, flow_variable, api_key, openapi_spec, twilio_credential,
            twitter_account, sunshine_integration, shopify_settings,
            airbyte_connection, email_channel, custom_domain, sequence,
            outbound_email, help_center, help_center_category,
            help_center_article, ai_instruction, website_data_source,
            pdf_data_source, ai_phone_agent, call_history, teammate_call,
            analytics, voc_insight, ai_evaluation, organization_model_version,
            organization_tags_definition, organization_draft_mode_settings,
            webhook_endpoint, agent_availability, csat_score, csat_settings,
            agent_assignment_settings, ai_context_custom_data_filters,
            alert_rule, pii_redaction_settings, security_notification_settings,
            mini_app, mini_app_version, mcp_server, mcp_connection,
            organization_secret.
        - schema:
            type: string
            minLength: 1
          in: query
          name: entityId
          required: false
        - schema:
            anyOf:
              - type: string
                minLength: 1
              - minItems: 1
                type: array
                items:
                  type: string
                  minLength: 1
          in: query
          name: eventType
          required: false
          description: >-
            Repeat to match any of several. Known values: create, update,
            delete, archive, restore, delete_multiple, unpublish, login, logout,
            password_change, password_reset, token_create, token_revoke,
            settings_update, handoff_settings_update,
            translation_settings_update, integration_connect, mcp_tool_call,
            access_token_retrieved, integration_disconnect, webhook_create,
            webhook_update, webhook_delete, permission_grant, permission_revoke,
            api_key_create, api_key_delete, twitter_chat_passcode_reveal,
            user_invite, user_invite_accept, user_remove, email_send,
            message_send, teammate_call_started, teammate_call_ended,
            conference_participant_invited, conference_participant_removed,
            session_takeover, session_assignee_update, organization_update,
            organization_ai_profile_update, organization_global_variable_delete,
            update_agent_availability_status, redaction, user_invite_delete,
            user_invite_resend, user_invite_link_copied, alert_rule.created,
            alert_rule.updated, alert_rule.deleted, publish, share.
        - schema:
            anyOf:
              - type: string
                enum:
                  - access
                  - agent_availability
                  - communication
                  - configuration
                  - data
                  - security
              - minItems: 1
                type: array
                items:
                  type: string
                  enum:
                    - access
                    - agent_availability
                    - communication
                    - configuration
                    - data
                    - security
          in: query
          name: eventCategory
          required: false
          description: Repeat to match any of several.
        - schema:
            type: number
          in: query
          name: actorId
          required: false
        - schema:
            type: integer
            exclusiveMinimum: 0
            maximum: 9007199254740991
          in: query
          name: userId
          required: false
          description: >-
            Events by or about this teammate: everything they did, plus
            sign-outs the system ended for them.
        - schema:
            type: string
            enum:
              - api
              - system
              - user
          in: query
          name: actorType
          required: false
        - schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          in: query
          name: cursor
          required: false
          description: >-
            `next_cursor` from the previous response. When set, `page` is
            ignored.
        - schema:
            default: 1
            type: integer
            minimum: 1
            maximum: 9007199254740991
          in: query
          name: page
          required: false
        - schema:
            default: 20
            type: integer
            minimum: 1
            maximum: 100
          in: query
          name: limit
          required: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditLogsPublicResponse'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDto'
components:
  schemas:
    AuditLogsPublicResponse:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: '#/components/schemas/AuditLogsPublicResponse'
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/AuditLogPublicDto'
        pagination:
          type: object
          properties:
            total:
              type: number
            page:
              type: number
            limit:
              type: number
            totalPages:
              type: number
          required:
            - total
            - page
            - limit
            - totalPages
          additionalProperties: false
        next_cursor:
          anyOf:
            - type: string
            - type: 'null'
          description: Pass as `cursor` to fetch the next page; null on the last page.
      required:
        - data
        - pagination
        - next_cursor
      additionalProperties: false
    ErrorDto:
      type: object
      properties:
        statusCode:
          type: integer
        message:
          type: string
        error:
          type: string
    AuditLogPublicDto:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: '#/components/schemas/AuditLogPublicDto'
      type: object
      properties:
        id:
          type: string
        org_id:
          type: string
        actor_id:
          anyOf:
            - type: number
            - type: 'null'
        actor_type:
          type: string
          enum:
            - api
            - system
            - user
        actor_email:
          anyOf:
            - type: string
            - type: 'null'
        actor_name:
          anyOf:
            - type: string
            - type: 'null'
        api_key:
          anyOf:
            - $ref: '#/components/schemas/AuditLogApiKeyActorDto'
            - type: 'null'
        entity_type:
          type: string
        entity_id:
          type: string
        event_type:
          type: string
        event_category:
          type: string
          enum:
            - access
            - agent_availability
            - communication
            - configuration
            - data
            - security
        changes:
          anyOf:
            - type: object
              properties:
                before:
                  type: object
                  propertyNames:
                    type: string
                  additionalProperties:
                    anyOf:
                      - {}
                      - type: 'null'
                after:
                  type: object
                  propertyNames:
                    type: string
                  additionalProperties:
                    anyOf:
                      - {}
                      - type: 'null'
              additionalProperties: false
            - type: 'null'
        metadata:
          anyOf:
            - type: object
              propertyNames:
                type: string
              additionalProperties:
                anyOf:
                  - {}
                  - type: 'null'
            - type: 'null'
        created_at:
          type: string
          format: date-time
        ip_address:
          anyOf:
            - type: string
            - type: 'null'
        user_agent:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - id
        - org_id
        - actor_id
        - actor_type
        - actor_email
        - actor_name
        - api_key
        - entity_type
        - entity_id
        - event_type
        - event_category
        - changes
        - metadata
        - created_at
        - ip_address
        - user_agent
      additionalProperties: false
    AuditLogApiKeyActorDto:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: '#/components/schemas/AuditLogApiKeyActorDto'
      type: object
      properties:
        id:
          type: string
        name:
          anyOf:
            - type: string
            - type: 'null'
        created_by_name:
          anyOf:
            - type: string
            - type: 'null'
        created_by_email:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - id
        - name
        - created_by_name
        - created_by_email
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````