APIAudit events
List audit events
List audit events for the organization.
GET
List audit events for the organization.
ApiKeyAuthheader
AuthorizationBearer <token>Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.
Required permission
view_auditaction?array<>action_not?array<>mcp_id?array<>mcp_id_not?array<>agent_instance_id?array<>agent_instance_id_not?array<>agent_slug?array<string>agent_slug_not?array<string>user_id?array<>user_id_not?array<>user_group?array<string>user_group_not?array<string>agent_tag_id?array<>resource_tag_id?array<>connection_id?stringFormat
uuidpolicy_id?stringFormat
uuidstart_time?stringInclusive lower bound; events with a timestamp >= start_time. Defaults to 30 days ago when omitted.
Format
date-timeend_time?stringExclusive upper bound; events with a timestamp < end_time. Defaults to now when omitted.
Format
date-timecursor?stringFormat
uuidlimit?integerFormat
int32Range
1 <= value <= 100Default
20The request has succeeded.
application/json- response
items*array<>next_cursor?stringPass as the cursor to fetch the next page; absent when there are no more results.
Format
uuidcurl -X GET "https://example.com/audit-events"{ "items": [ { "id": null, "org_id": null, "action": "mcp.created", "actor_type": "user", "actor_id": null, "actor_display_name": "string", "resource_type": "mcp", "resource_id": null, "resource_display_name": "string", "resources": { "mcp_id": null, "mcp_display_name": "string", "agent_instance_id": null, "agent_instance_display_name": "string", "agent_slug": "string", "user_id": null, "user_display_name": "string", "connection_id": null, "policy_id": null, "policy_display_name": "string", "dlp_rule_id": null, "dlp_rule_display_name": "string", "rate_limit_rule_id": null, "rate_limit_rule_display_name": "string", "tag_id": null, "tag_display_name": "string", "tool_key": "string" }, "context": { "device": "string", "os": "string", "browser": "string", "ip": "string", "city": "string", "country": "string", "user_agent": "string", "trace_id": "string" }, "changes": [ { "type": "create", "path": "string", "from": null, "to": null } ], "payload": { "display_name": "string", "slug": "string", "origin": "catalog" }, "created_at": "2019-08-24T14:15:22Z" } ], "next_cursor": null}