List the workspace audit log
Returns display-safe audit entries newest first by default, paged by `beforeVersion`. Set `sortDirection=asc` and page with `afterVersion` for oldest first. Results are windowed to the plan's history retention. Requires `audit_log:read` (owners and admins) and a plan with the audit log feature (Business or above); other plans receive 403 `entitlement_feature_locked`.
Authorization
apiKey Workspace API key created in Workspace settings → API keys. Scopes on the key bound what it can read and write.
In: header
Path Parameters
Query Parameters
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/v1/workspaces/string/audit-log"{ "data": { "entries": [ { "id": "string", "workspaceId": "string", "version": 0, "type": "string", "category": "content", "actor": { "kind": "user", "id": "string", "displayName": "string" }, "onBehalfOf": { "kind": "user", "id": "string", "displayName": "string" }, "subjectType": "string", "subjectId": "string", "occurredAt": "string", "outcome": "succeeded", "changedFieldKeys": [ "string" ], "sourceAutomationRunId": "string", "sourceAutomationId": "string" } ], "hasMore": true, "nextCursor": 0, "retentionDays": 0 }}{ "_tag": "ApiNotFound", "error": "not_found", "message": "That item does not exist, or this key cannot see it.", "status": 404}{ "_tag": "ApiNotFound", "error": "not_found", "message": "That item does not exist, or this key cannot see it.", "status": 404}Catch up on workspace events
Returns the workspace's current event version plus the events after `afterVersion`, each projected down to what the caller is allowed to see, so a client that fell behind can resynchronize. Requires `workspace:read`. Pass `afterVersion` and `limit` as integer strings; a non-integer value is a validation error and an unknown workspace is not found.
Export the workspace audit log as CSV
Runs one bounded read (at most 5,000 rows) over the same filters as the list endpoint and returns the CSV inline with `truncated` set when more rows matched. Every export is itself recorded in the ledger as `audit_log.exported` with its filter scope. Requires `audit_log:read` and the audit log plan feature; send an `Idempotency-Key` to make retries safe.