GET · Account & access
List audit events
List audit events
/api/v1/audit-log
This scope is inferred from the method and the endpoint's group — the OpenAPI document does
not carry one per operation. The wire is authoritative; whoami reports what your
token actually holds.
Description
The acting account's audited calls, newest first, with changes[] before/after for writes. Requires the audit:read scope. Returns a data[] page of {id, requestId, action, tool, surface, target, changes, success, errorCode, status} with hasMore, nextCursor and total.
Query parameters
| Name | Type | Description |
|---|---|---|
action
|
string | Up to 128 characters. |
tool
|
string | Up to 128 characters. |
surface
|
enum |
One of mcp, rest.
|
since
|
string · date-time | |
until
|
string · date-time | |
limit
|
integer | Page size for a collection. Range 1–100. |
Responses
A 200 response returns the shape shown in the rail.
Every non-2xx response is an RFC 7807 problem with a stable
code.
Commonly returned errors
The codes this operation reaches on its own path: the auth stack, its own validation and
ownership checks, and the transport. Not a closed set — a shared code from the
full registry can still surface. Each links to the code’s own page,
the same URL its type dereferences to.