Skip to content

Audit log ​

Routes are relative to <PUBLIC_BASE_URL>; request and response bodies are JSON unless stated otherwise. Authentication, scopes, pagination and the error format are described in the REST API guides.

GET /api/v1/admin/audit ​

Read the audit log

Most recent first, cursor-paginated. Filters: action, actor, lower date bound. Read-only by design: the only deletion is the retention purge. An unreadable cursor returns the first page.

Access — Member session or API key with scope admin:read (administrator role required).

Parameters

NameInTypeRequired
actionquerystringno
actorquerystring (uuid)no
sincequerystring (date-time)no
cursorquerystringno
limitqueryintegerno

Responses

200 — A page of entries.

FieldTypeRequired
entriesobject[]yes
nextCursorstring | nullyes
JSON Schema
json
{
  "type": "object",
  "properties": {
    "entries": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid",
            "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
          },
          "at": {
            "type": "string",
            "format": "date-time",
            "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$"
          },
          "actorKind": { "type": "string", "enum": [ "member", "system", "webhook" ] },
          "actorMemberId": {
            "anyOf": [
              {
                "type": "string",
                "format": "uuid",
                "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
              },
              { "type": "null" }
            ]
          },
          "action": { "type": "string", "minLength": 1 },
          "targetKind": { "type": "string", "minLength": 1 },
          "targetId": {
            "anyOf": [ { "type": "string", "minLength": 1 }, { "type": "null" } ]
          },
          "details": {
            "type": "object",
            "propertyNames": { "type": "string" },
            "additionalProperties": {}
          },
          "ip": {
            "anyOf": [ { "type": "string", "minLength": 1 }, { "type": "null" } ]
          }
        },
        "required": [
          "id",
          "at",
          "actorKind",
          "actorMemberId",
          "action",
          "targetKind",
          "targetId",
          "details",
          "ip"
        ],
        "additionalProperties": false
      }
    },
    "nextCursor": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }
  },
  "required": [ "entries", "nextCursor" ],
  "additionalProperties": false
}

400 — The request does not match its schema.

401 — No valid session or API key (auth.unauthenticated).

403 — Refused: insufficient role (auth.forbidden), missing scope (api_key.scope_missing, details.required names it) or a route closed to API keys (api_key.session_required).

429 — The API key exceeded its rate limit (api_key.rate_limited); Retry-After says when to retry.

Error codes — request.bad_request. The common codes (request.bad_request, auth.unauthenticated, api_key.scope_missing, api_key.rate_limited…) apply to every route; see Errors.