---
title: "List audit logs"
method: GET
path: "/api/v1/audit_logs"
tags: ["Audit Log"]
---

# List audit logs

`GET /api/v1/audit_logs`

List audit log records for chosen objects and actions.

Only admin or organization group admins can access the log records.

## Query parameters

- `page_size` integer
- `cursor` string
- `object_type` 'document' | 'annotation' | 'user', required
- `action` string
- `object_id` integer
- `timestamp_before` string, date-time
- `timestamp_after` string, date-time
- `username` string

## Response `200`

OK

- object
  - `pagination` Pagination, required
    - `next` string, uri, nullable — URL for the next page of results. Contains an opaque signed `cursor` query parameter. Use this URL directly to fetch the next page — do not attempt to construct or modify the cursor value.
    - `previous` string, uri, nullable — URL for the previous page of results. Contains an opaque signed `cursor` query parameter. Use this URL directly to fetch the previous page — do not attempt to construct or modify the cursor value.
  - `results` AuditLog[], required
    - `organization_id` integer, required — ID of the organization
    - `timestamp` string, date-time, required — Timestamp of the log record.
    - `username` string, required — Username of the user that performed the action
    - `object_id` integer, required — ID of the object on which the action was performed
    - `object_type` 'document' | 'annotation' | 'user', required — Type of the object on which the action was performed
    - `action` string, required — Type of the action performed. Each `object_type` has different actions available. | object_type | Available actions | |-------------|-------------------| | document | create | | annotation | update-status | | user | create, delete, purge, update, destroy, app_load, reset-password, change-password | <Callout type="info"> `app_load` value represents records of when `api/v1/auth/user` endpoint was called. </Callout>
    - `content` AuditLogContent, required
      - `path` string — Partial URL path of the request
      - `method` string — Method of the request
      - `request_id` string — For a change triggered by an API request, the request's `X-Request-ID`; otherwise an internal correlation ID. Use this when contacting Rossum support with any related questions.
      - `status_code` integer — Status code of the response
      - `details` object — Details about the request (if available). For most cases, this field will be `{}`
        - `payload` object — Payload details of the request
          - `groups` string[] — Name of the user roles that were sent (if sent) in a request on a user object

## Other responses

- `400` — Invalid input data.
- `401` — The username/password is invalid or token is invalid (e.g. expired).
- `403` — Insufficient permission, missing authentication, invalid CSRF token and similar issue.
- `404` — The specified resource was not found.
- `409` — Conflict
- `429` — Request rate is too high, wait before sending more requests. See [Rate Limiting](/guides/overview#rate-limiting) for more details.
- `500` — Server failure while processing the request.
- `502` — Invalid response from the upstream server.
- `503` — We're temporarily offline for maintenance. Please try again later.
- `504` — Upstream server could not complete the request in time.

---

[API](https://skmtc.dev/rossum/apis/rossum-api.md) · [All operations](https://skmtc.dev/rossum/apis/rossum-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/rossum/rossum-api/revisions/f1b5a910991d/schema)
