Audit Logs

List audit logs

List user actions and configuration changes within this organization.

get/organization/audit_logs

Query parameters

gtinteger

Return only events whose effective_at (Unix seconds) is greater than this value.

gteinteger

Return only events whose effective_at (Unix seconds) is greater than or equal to this value.

ltinteger

Return only events whose effective_at (Unix seconds) is less than this value.

lteinteger

Return only events whose effective_at (Unix seconds) is less than or equal to this value.

Return only events whose effective_at (Unix seconds) is in this range.

project_ids[]string[]

Return only events for these projects.

event_types[]AuditLogEventType[]

Return only events with a type in one of these values. For example, project.created. For all options, see the documentation for the audit log object.

actor_ids[]string[]

Return only events performed by these actors. Can be a user ID, a service account ID, or an api key tracking ID.

actor_emails[]string[]

Return only events performed by users with these emails.

resource_ids[]string[]

Return only events performed on these targets. For example, a project ID updated. For ChatGPT connector role events, use the workspace connector resource ID shown in details.id, such as <workspace_id>__<connector_id>.

tenant_onlyboolean

Return only tenant-scoped events associated with this organization. Required for tenant-scoped events such as role.bound_to_resource and role.unbound_from_resource. When true, all supplied event types must be tenant-scoped.

limitinteger

A limit on the number of objects to be returned. Limit can range between 1 and 100, and the default is 20.

afterstring

A cursor for use in pagination. after is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, ending with obj_foo, your subsequent call can include after=obj_foo in order to fetch the next page of the list.

beforestring

A cursor for use in pagination. before is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, starting with obj_foo, your subsequent call can include before=obj_foo in order to fetch the previous page of the list.

Response

Audit logs listed successfully.

object'list' required
first_idstring nullable
last_idstring nullable
has_moreboolean required

Example response

{
  "first_id": "audit_log-defb456h8dks",
  "last_id": "audit_log-hnbkd8s93s"
}

Changes

Changed in 15 of the 163 revisions of this API.9138187

    • ○

      added the non-success response with the status

      response-non-success-status-added

    • ○

      added the non-success response with the status

      response-non-success-status-added

    • ▲

      added to the //// response property oneOf list for the response status

      response-property-one-of-added

  • 8ad6af0ee4e124See the full diff
    • ●

      added the new external_storage.registered enum value to the // response property for the response status

      response-property-enum-value-added

    • ●

      added the new external_storage.removed enum value to the // response property for the response status

      response-property-enum-value-added

    • ○

      added the enum value external_storage.registered to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

    • ○

      added the enum value external_storage.removed to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

    • ○

      added the optional property // to the response with the status

      response-optional-property-added

    • ○

      added the optional property // to the response with the status

      response-optional-property-added

    • ○

      added the optional property / to the response with the status

      response-optional-property-added

  • 56297492effb22See the full diff
    • ●

      added the new tenant.trusted_access.application.submitted enum value to the // response property for the response status

      response-property-enum-value-added

    • ●

      added the new tenant.trusted_access.business_verification.started enum value to the // response property for the response status

      response-property-enum-value-added

    • ○

      added the enum value tenant.trusted_access.application.submitted to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

    • ○

      added the enum value tenant.trusted_access.business_verification.started to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

  • 0b6aa15de4b911See the full diff
    • ●

      added the new tenant.ads_account.onboarding.redemption enum value to the // response property for the response status

      response-property-enum-value-added

    • ○

      added the enum value tenant.ads_account.onboarding.redemption to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

    • ○

      added the non-success response with the status

      response-non-success-status-added

  • 63028c4d391611See the full diff
    • ●

      added the new tenant.workload_identity.access_token.issued enum value to the // response property for the response status

      response-property-enum-value-added

    • ○

      added the enum value tenant.workload_identity.access_token.issued to the property items/ of the query request parameter event_types[]

      request-parameter-property-enum-value-added

    • ●

      removed the optional property // from the response with the status

      response-optional-property-removed

    • ○

      added the optional property // to the response with the status

      response-optional-property-added