---
title: "Read Firewall Actions by Project"
method: GET
path: "/v1/security/firewall/events"
tags: ["security"]
---

# Read Firewall Actions by Project

`GET /v1/security/firewall/events`

Retrieve firewall actions for a project Rule names are resolved against the project's *current* active firewall configuration and the team's active rulesets, so a rule that has since been renamed reports its new name and one that has been deleted reports `null`. System rules such as `sys_dos_mitigation` and `ip_blocking` have no configured name and always report `null`.

## Query parameters

- `projectId` string, required
- `startTimestamp` number
- `endTimestamp` number
- `hosts` string
- `teamId` string
- `slug` string

## Response `200`

- object
  - `actions` object[], required
    - `ruleName` string, nullable, required
    - `startTime` string, required
    - `endTime` string, required
    - `isActive` false | true, required
    - `action_type` string, required
    - `action` string, required
    - `ruleId` string, nullable, required
    - `host` string, required
    - `public_ip` string, required
    - `count` number, required

## Other responses

- `400` — One of the provided values in the request query is invalid.
- `401` — The request is not authorized.
- `403` — You do not have permission to access this resource.
- `404`
- `408`
- `410`
- `500`

## Changes

- **2026-08-31** `e31ea8d3c1e7` — 1 info
  - added the non-success response with the status `408`
- **2026-08-24** `895544ebf14c` — 6 info
  - the endpoint scheme security `bearerToken` was added to the API
  - added the new optional `query` request parameter `slug`
  - added the new optional `query` request parameter `teamId`
  - added the required property `actions/items/action` to the response with the `200` status
  - …2 more
- **2026-07-21** `2ae10ee9d21c` — 1 info
  - added the non-success response with the status `410`

[Change history](https://skmtc.dev/vercel/apis/api/changes/v1/security/firewall/events/get.md)

---

[API](https://skmtc.dev/vercel/apis/api.md) · [All operations](https://skmtc.dev/vercel/apis/api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/vercel/api/revisions/e31ea8d3c1e7/schema)
