Skip to content

Audit Log


Endpoints

GET       /audit_logs
GET       /audit_logs/all
GET       /audit_logs/:id

An audit log is an immutable record of an action in your account: who did what, when, from where and through which channel. Creating, changing, deleting, cloning, sharing or viewing an object, running a workflow and signing in all produce a record. Nobody can change or delete a record after it is written, so the endpoints accept GET only.

What a user can read depends on their role:

Endpoint Permission Scope
GET /audit_logs VIEW USER A sub-user sees their own records. The account owner sees every record of the account.
GET /audit_logs/all VIEW ALL USERS Every record of the account, from every user.
GET /audit_logs/:id VIEW USER One record, with what changed. Same scope as GET /audit_logs.

The audit log object

What an audit log object looks like?

{
  "id": "audl_e1f32edffa310b4235095b28c",
  "created": 1783024653,
  "updated": 1783024653,
  "activity": "File Created",
  "operation": "CREATE",
  "source": "API",
  "status": "SUCCESS",
  "entity_id": "file_NpvMpQuE6fmhWx39Em3Xrfqwg",
  "entity_type": "File",
  "entity_name": "New Text Document.txt",
  "workspace": "main",
  "workflow_id": null,
  "workflow_name": null,
  "workflow_execution_id": null,
  "user_email": "user@everysk.com",
  "proxy_admin_email": null,
  "credential_id": "sid_sCGBAdTb",
  "credential_type": "API_KEY",
  "ip": "127.0.0.1",
  "user_agent": "insomnia/13.0.2",
  "user_agent_pretty": "Unknown OS - Unknown Browser",
  "location": {
    "country": "",
    "region": "",
    "city": "",
    "cityLatLong": ""
  },
  "viewed_ids": null
}
Property Description
id string Unique identifier of the audit log entry. Starts with audl_.
created timestamp Time of the action. Measured in seconds since the Unix epoch, UTC.
updated timestamp Always equal to created, since records are never updated.
activity string A readable description of the action, for example File Created, Portfolio Updated, Workflow Execution Started or Sign In.
operation string The type of operation. See operation.
source string Where the action started. See source.
status string The result of the action. See status.
entity_id string The identifier of the object the action affected, such as a portfolio, a file or a report.
entity_type string The type of the affected object. See entity_type.
entity_name string The name of the affected object at the time of the action. Can be null in older records and for objects without a name.
workspace string The workspace of the action, for example main.
workflow_id string The workflow, when the action ran inside one. Otherwise null.
workflow_name string The workflow name, when it applies. Otherwise null.
workflow_execution_id string The workflow execution. Groups every action of one run. null when it does not apply.
user_email string The e-mail of the user who performed the action. Automatic actions from WORKER, WORKFLOW_BRIDGE, SCHEDULER and INTEGRATION carry System.
proxy_admin_email string When an administrator acts on behalf of another user, the administrator's e-mail. user_email then holds the user acted for. Otherwise null.
credential_id string The credential the request used: the account SID (sid_ prefix) for an API key, the client ID for OAuth2.
credential_type string API_KEY, OAUTH2 or null when no credential applies.
ip string The source IP address of the request.
user_agent string The raw client identification, for example insomnia/13.0.2.
user_agent_pretty string A readable Operating System - Browser version of user_agent. Unknown OS - Unknown Browser when it cannot be identified.
location object The approximate origin, estimated from the IP: country (for example BR), region (for example RS), city and cityLatLong. The subfields are "" when the location cannot be determined, such as on a local network.
viewed_ids array For batch VIEW operations, the identifiers of the objects one read returned. Otherwise null.

operation

Value Meaning
CREATE An object was created.
UPDATE An object was changed.
DELETE An object was deleted.
EXECUTE An execution started, such as a workflow.
CLONE An object was cloned.
SHARE An object was shared.
VIEW An object was viewed or read.
LOGIN A user signed in.
LOGOUT A user signed out.

source

Value Meaning
PLATFORM The web application.
API The REST API.
SDK The Python SDK.
WORKER A background process.
INTEGRATION An integration.
WORKFLOW_BRIDGE The bridge between workflow executions.
SCHEDULER A schedule.
UNKNOWN The origin could not be identified.

status

Value Meaning
SUCCESS The action completed. This is the default.
ERROR The action of an authenticated user failed, for example with HTTP 400, 404, 429 or 500.
DENIED The action was refused for lack of permission (HTTP 401 for an authenticated user, or 403).

ERROR and DENIED are recorded for authenticated users acting through the PLATFORM or the API. Automatic actions (WORKER, WORKFLOW_BRIDGE, SCHEDULER, INTEGRATION) are always SUCCESS.

entity_type

The main types are Portfolio, Report, File, Datastore, CustomSecurity, Workspace, UserApp, Secrets, WorkerTemplate, Workflow and User. Sign-in and sign-out events carry UserEvent, and the start of a workflow execution carries WorkflowExecution.

List audit logs

Returns a list of audit log entries, most recent first. GET /audit_logs returns the records in the caller's scope. GET /audit_logs/all takes the same parameters and returns every record of the account.

To list the audit logs of a period, run the following:

curl "https://api.everysk.com/v2/audit_logs?start=20260801&end=20260831&page_size=100" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -G

The above call returns the following JSON object:

{
  "audit_logs": [
    {
      "id": "audl_e1f32edffa310b4235095b28c",
      "created": 1783024653,
      "updated": 1783024653,
      "activity": "File Created",
      "operation": "CREATE",
      "source": "API",
      "status": "SUCCESS",
      "entity_id": "file_NpvMpQuE6fmhWx39Em3Xrfqwg",
      "entity_type": "File",
      "entity_name": "New Text Document.txt",
      "workspace": "main",
      ...
    },
    ...
  ],
  "next_page_token": null
}

HTTP Request

GET /audit_logs

GET /audit_logs/all

HTTP Parameters

Parameter Description
start string optional, default is null Returns records from this date onward. 20260831 starts at the first instant of the day. 20260831 12:55:51 starts at that second.
end string optional, default is null Returns records up to this date. 20260831 runs to the last instant of the day. 20260831 18:00:00 runs to the end of that second.
date_time string optional, default is null Sets start and end to the same value. With a day, such as 20260901, it returns that day.
page_size integer optional, default is 10 Set the number of objects that will be listed per page.
page_token string optional, default is null The token defines which page will be returned to the user. For further information, please check out our pagination guide.

The period filters the record's updated_on date. Dates use the YYYYMMDD or YYYYMMDD HH:MM:SS format, in UTC, and both bounds are inclusive. Any other format, such as 2026-08-31 or ISO 8601, returns 400.

A time contains a space, so encode it in the URL. With curl, pass the parameters with --data-urlencode:

curl https://api.everysk.com/v2/audit_logs \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  --data-urlencode "start=20260831 12:00:00" \
  --data-urlencode "end=20260831 18:00:00" \
  -G

Retrieve an audit log

Retrieves one audit log entry by its id, with what the action changed on the object.

To retrieve an audit log, run the following:

curl https://api.everysk.com/v2/audit_logs/audl_e1f32edffa310b4235095b28c \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -G

The above call returns the following JSON object:

{
  "entity": {
    "id": "audl_e1f32edffa310b4235095b28c",
    "activity": "File Created",
    ...
  },
  "diff_formatted": {
    "added": {"field_x": "value_x"},
    "removed": {"field_y": "value_y"},
    "modified": {"field_z": {"before": "old value", "after": "new value"}}
  },
  "before": {...},
  "after": {...}
}
Property Description
entity object The audit log entry, with the same properties as in the list.
diff_formatted object What changed: added and removed fields, and modified fields with their value before and after.
before object The state of the object before the action.
after object The state of the object after the action.

Sensitive fields are left out of before and after. A record that does not exist, or that belongs to another user you are not allowed to see, returns 404 with the message Audit log not found..

HTTP Request

GET /audit_logs/:id