> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mixlayer.com/api-reference/platform-api/audit-logs/list-audit-log/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mixlayer.com/_mcp/server. # List organization audit log entries GET https://api.mixlayer.com/v1/organizations/{org_id}/audit_log When authenticated with an API key, this operation requires `api-admin`. Reference: https://docs.mixlayer.com/api-reference/platform-api/audit-logs/list-audit-log ## Authentication - `Authorization` header (bearer token, required) — Console user session or Mixlayer API key supplied as a Bearer token. ## Request ### Path parameters - `org_id` (string, required) — Organization ID ### Query parameters - `after` (string, optional) — Return entries after this opaque cursor; mutually exclusive with `before`. - `before` (string, optional) — Return entries before this opaque cursor; mutually exclusive with `after`. - `limit` (integer, optional, default: 50) — Page size; values are clamped to 1 through 200. - `from` (datetime, optional) — Inclusive lower timestamp bound - `to` (datetime, optional) — Inclusive upper timestamp bound - `actor` (string, optional) — Exact principal actor - `resource_type` (string, optional) — Exact resource type - `resource_id` (string, optional) — Exact resource ID - `action` (string, optional) — Audit action prefix ## Response ### 200 Cursor-paginated audit log entries - `data` (list of AuditLogEntry, required) — Resources in the current page. - `end_cursor` (string, optional, nullable) — Cursor for the last resource, or null for an empty page. - `start_cursor` (string, optional, nullable) — Cursor for the first resource, or null for an empty page. ## Errors ### 400 Bad Request Error Query parameters are missing or invalid. - `error` (ApiErrorBody, required) — Structured error details. ### 401 Unauthorized Error Authentication is missing or invalid. - `error` (ApiErrorBody, required) — Structured error details. ### 403 Forbidden Error The authenticated principal cannot perform this operation. - `error` (ApiErrorBody, required) — Structured error details. ### 404 Not Found Error The requested resource is not visible to the authenticated principal. - `error` (ApiErrorBody, required) — Structured error details. ### 500 Internal Server Error An unexpected server or database error occurred. - `error` (ApiErrorBody, required) — Structured error details. ## Types ### AuditLogEntry One recorded organization audit event. - `action` (string, required) — Stable action name, such as `api_key.create`. - `actor` (string, required) — User, API key, or system principal that performed the action. - `created_at` (datetime, required) — Time the event was recorded. - `id` (string, required) — Stable audit event identifier. - `metadata` (any, required) — Non-secret action-specific context. - `resource_id` (string, required) — Identifier of the affected resource. - `resource_type` (string, required) — Resource category affected by the action. - `actor_ip` (string, optional, nullable) — Actor IP address, when available. - `organization_id` (string, optional, nullable) — Organization associated with the event, when applicable. ### ApiErrorBody Structured error details returned by the platform API. - `message` (string, required) — Human-readable error message. - `code` (string, optional, nullable) — Stable machine-readable error code, when available. - `details` (any, optional) — Error-specific structured context, when available. ## Examples **Response** ```json { "data": [ { "action": "string", "actor": "admin$/operator@example.com", "created_at": "2024-01-15T09:30:00Z", "id": "string", "metadata": null, "resource_id": "string", "resource_type": "string", "actor_ip": "string", "organization_id": "string" } ], "end_cursor": "string", "start_cursor": "string" } ``` **SDK Code** ```python import requests url = "https://api.mixlayer.com/v1/organizations/org_id/audit_log" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.mixlayer.com/v1/organizations/org_id/audit_log'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.mixlayer.com/v1/organizations/org_id/audit_log" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.mixlayer.com/v1/organizations/org_id/audit_log") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.mixlayer.com/v1/organizations/org_id/audit_log") .header("Authorization", "Bearer ") .asString(); ``` ```php request('GET', 'https://api.mixlayer.com/v1/organizations/org_id/audit_log', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ```