Skip to main content
GET
List audit log entries

Authorizations

Authorization
string
header
required

Your Reason API key from Settings > API. New keys use reason_; legacy ara_ keys remain accepted. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:debug is privileged: it expands diagnostic session events only for organization owners/admins.

Path Parameters

orgId
string
required

Organization id or slug. Resolve it with GET /v3/self.

Query Parameters

limit
integer
default:50

Maximum entries to return (default 50, max 200).

before
string<date-time>

Return only entries created before this timestamp.

action
string

Return only entries with this exact action.

actor
string

Return only entries performed by this actor user id.

since
string<date-time>

Return only entries created at or after this ISO timestamp.

Response

200 - application/json

Audit log entries.

items
object[]
has_next_page
boolean
end_cursor
string | null

Pass back as after for the next page.

entries
object[]

Legacy twin of items.

next_before
string | null

Legacy twin of end_cursor.