Skip to main content
Audit Logs

List audit logs

Returns a list of audit log events in your organization using cursor-based pagination (newest first).

GET
/v2/audit-logs

Query Parameters

  • limit - Number of events to return (1-100, default 10)
  • cursor - Cursor from a previous response for pagination
  • action - Filter by action type (e.g. webhook.deleted, security.sso_enabled)
  • domain - Filter by domain/category (e.g. security, messenger)
  • startDate - Filter events created on or after this ISO 8601 datetime
  • endDate - Filter events created on or before this ISO 8601 datetime

Filtering by Action

The action parameter filters by event type. Each action follows the {domain}.{verb} convention. See the action enum in this schema for the full list of supported values.

Examples:

  • ?action=security.sso_enabled — only SSO enablement events
  • ?action=webhook.deleted — only webhook deletion events

Filtering by Domain

Use the domain parameter to narrow results to one category of audit event.

Examples:

  • ?domain=security — only security-related audit events
  • ?domain=messenger — only messenger-related audit events

Filtering by Date Range

Use startDate and endDate together or individually to narrow results to a time window.

Examples:

  • ?startDate=2025-01-01T00:00:00Z&endDate=2025-01-31T23:59:59Z — January 2025 only
  • ?startDate=2025-06-01T00:00:00Z — from June 1st onward

Pagination

Results are ordered by createdAt descending (newest first). Use the nextCursor value from each response as the cursor parameter in the next request to paginate forward.

GET /v2/audit-logs?limit=20
→ { "nextCursor": "eyJ..." }

GET /v2/audit-logs?limit=20&cursor=eyJ...
→ { "nextCursor": null }   ← no more results

Metadata

The metadata field contains event-specific details (e.g. before/after state for updates). Its shape depends on the action type and is not strictly modeled in the schema — treat it as a free-form object.

Response Format

Returns a list object with:

  • object - Always "list"
  • data - Array of audit log objects
  • nextCursor - Cursor for the next page, or null if no more results

Audit Log Object

Each audit log includes:

  • id - Unique event identifier (UUID)
  • correlationId - Groups related events from a single operation (e.g. bulk import)
  • action - What happened (e.g. webhook.deleted)
  • domain - Category the action belongs to (e.g. integrations)
  • description - Human-readable description
  • actor - Who performed the action (id, type, email, name, apiKey)
  • resource - What was affected (type, id, name)
  • request - Request context (ipAddress, userAgent)
  • metadata - Event-specific payload
  • createdAt - When the event occurred

Version Availability

This endpoint is only available in API version 2026-01-01.nova and newer.

Authorizationstringheaderrequired

API key as Bearer token. Use: Authorization: Bearer sk_...

limitintegerquerydefault:10

A limit on the number of objects to be returned, between 1 and 100.

Required range: 1 <= x <= 100
Example: 10
cursorstringquery

An opaque cursor for pagination. Use the nextCursor value from a previous response to fetch the next page of results.

Maximum string length: 512
Example: eyJpZCI6IjUwN2YxZjc3YmNmODZjZDc5OTQzOTAxMSJ9
actionenum<string>query

Filter audit logs by action type

Available options: auth.login, auth.logout, auth.login_failed, auth.password_reset_requested, auth.password_changed, auth.mfa_enabled, auth.mfa_disabled, auth.sso_login, auth.password_reset_completed, auth.unauthorized_method, auth.recovery_code_regenerated, auth.sso_enforcement_blocked, auth.sso_enforcement_session_invalidated, auth.managed_account_link_blocked, auth.cross_org_invite_accepted, auth.sso_enforcement_shadow, teammate.invited, teammate.joined, teammate.removed, teammate.email_changed, teammate.name_changed, teammate.seat_changed, teammate.deactivated, teammate.invite_changed, teammate.invite_deleted, teammate.scim_provisioned, teammate.scim_deprovisioned, teammate.scim_unlinked, teammate.scim_relinked, teammate.scim_operation_blocked, teammate.scim_seat_capacity_blocked, teammate.scim_email_updated, teammate.scim_exclusion_list_updated, teammate.restored, teammate.scim_restored, teammate.scim_auto_claimed, teammate.scim_claim_role_preserved, teammate.permanently_removed, teammate.availability_changed, teammate.assignment_limit_changed, member.role_changed, organization.owner_transferred, article.created, article.updated, article.body_edited, article.published, article.unpublished, article.deleted, changelog.created, changelog.published, changelog.deleted, changelog.unpublished, help_center_api.spec_created, help_center_api.spec_updated, help_center_api.spec_deleted, help_center_api.source_synced, help_center_api.published, help_center_api.draft_discarded, help_center_api.settings_changed, settings.name_changed, settings.branding_updated, settings.custom_domain_changed, settings.language_changed, settings.timezone_changed, settings.email_settings_changed, settings.help_center_updated, settings.moderation_changed, settings.voting_changed, settings.statuses_updated, settings.boards_updated, settings.privacy_changed, settings.subdomain_changed, settings.subdomain_change_requested, settings.grace_period_changed, security.scim_override_blocked, security.sso_enabled, security.sso_disabled, security.sso_configured, security.sso_jit_provisioning_blocked, security.directory_sync_enabled, security.directory_sync_disabled, security.directory_sync_reconciled, security.two_factor_enforced, security.auth_method_changed, security.ip_allowlist_changed, security.ip_allowlist_blocked, security.identity_verification_changed, security.sso_url_changed, security.sso_jit_provisioning_changed, security.sso_enforcement_enabled, security.sso_enforcement_disabled, security.dsync_group_mappings_changed, security.dsync_mapping_priority_changed, security.user_banned, security.user_unbanned, integration.installed, integration.uninstalled, integration.configured, webhook.created, webhook.updated, webhook.deleted, webhook.secret_rotated, api_key.created, api_key.regenerated, api_key.deleted, organization.deletion_scheduled, organization.deletion_cancelled, data.export_initiated, data.import_initiated, data.bulk_delete, data.user_data_deleted, data.csv_exported, billing.plan_changed, billing.plan_cancelled, billing.seat_limit_changed, billing.seat_activated, billing.ai_resolution_price_changed, workflow.created, workflow.activated, workflow.deactivated, workflow.deleted, workflow.updated, messenger.look_and_feel_changed, messenger.spaces_changed, messenger.language_changed, messenger.platform_availability_changed, messenger.search_browse_changed, messenger.email_collection_changed, messenger.welcome_message_changed, messenger.launcher_changed, messenger.inbound_conversations_changed, messenger.office_hours_changed, messenger.identity_verification_changed, messenger.privacy_policy_changed, brand.created, brand.updated, brand.deleted, brand.messenger_look_and_feel_changed, brand.messenger_launcher_changed, brand.messenger_welcome_message_changed, brand.messenger_privacy_policy_changed, brand.default_changed, ai_agent.enabled, ai_agent.disabled, ai_agent.identity_changed, ai_agent.customization_changed, ai_agent.guidance_changed, ai_agent.multilingual_changed, ai_agent.data_context_changed, ai_agent.training_file_created, ai_agent.training_file_updated, ai_agent.training_file_deleted, ai_agent.qna_created, ai_agent.qna_updated, ai_agent.qna_deleted, email.sending_address_created, email.sending_address_updated, email.sending_address_deleted, email.domain_registered, email.domain_deleted, email.reply_to_changed, email.ignored_address_added, email.ignored_address_removed
Example: webhook.deleted
domainenum<string>query

Filter audit logs by domain/category

Available options: authentication, team_management, permissions, articles, changelog, workspace_settings, security, integrations, data_management, billing, workflows, messenger, brands, ai_agent, email_config
Example: security
startDatestring | nullquery

Filter events created on or after this ISO 8601 datetime

Example: 2025-01-01T00:00:00.000Z
endDatestring | nullquery

Filter events created on or before this ISO 8601 datetime

Example: 2025-12-31T23:59:59.999Z
Featurebase-Versionenum<string>header

API version for this request. Defaults to your organization's configured API version if not specified.

Available options: 2026-08-19.orbit, 2026-01-01.nova, 2025-12-12.clover
Example: 2026-08-19.orbit

Response

application/json

Success

dataobject[]required

Array of audit log events

nextCursorstring | nullrequired

Cursor for fetching the next page. Null if there are no more results.

Example: eyJjcmVhdGVkQXQiOiIyMDI1LTA2LTE1VDEwOjMwOjAwLjAwMFoiLCJpZCI6IjUwN2YxZjc3YmNmODZjZDc5OTQzOTAxMSJ9
objectenum<string>required

Object type identifier

Available options: list
Example: list