Skip to main content
GET
Query Audit Logs

Permissions

Requires Territory admin or Organization admin permission.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

from
string<uuid>
required

Audit log ID to begin fetching from.

take
integer
required

Number of audit log entries to fetch, max 1000

log_type
string

Optional filter to return only logs of a specific type. For Microsoft add-in activity, use add-in-specific log types such as user:word_add_in_docx_drafting or user:outlook_add_in_ask. See the Audit Logs Guide for a complete list of log types.

Example:

"auth:login"

Response

List of audit log entries

data
object
required

Optional metadata for certain event types.

id
string<uuid>
required

Unique identifier for the log entry.

Example:

"0194f5c5-2021-75ae-b202-f049fca9dce2"

ip
string
required

IP address of the actor.

Example:

"0.0.0.0"

timestamp
string<date-time>
required

Date when the event occurred in ISO format.

Example:

"2025-02-11T16:08:44.324452"

type
string
required

Type of audit log event. Microsoft add-in activity is returned through the same Audit Log API, with event types such as user:word_add_in_docx_drafting and user:outlook_add_in_ask. We may add more types at any time, so in developing and maintaining your code, you should not assume that only these types exist. For a complete list of all audit log types and their descriptions, see the Audit Logs Guide.

Example:

"admin:fetch_workspace_history"

user
string
required

Email of the user who triggered the event.

Example:

"user@example.com"

user_agent
string
required

User agent of the actor who triggered the event.

Example:

"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"