Audit Log¶
Endpoints
An audit log is an immutable record of an action in your account: who did what, when, from where and through which channel. Creating, changing, deleting, cloning, sharing or viewing an object, running a workflow and signing in all produce a record. Nobody can change or delete a record after it is written, so the endpoints accept GET only.
What a user can read depends on their role:
| Endpoint | Permission | Scope |
|---|---|---|
GET /audit_logs |
VIEW USER |
A sub-user sees their own records. The account owner sees every record of the account. |
GET /audit_logs/all |
VIEW ALL USERS |
Every record of the account, from every user. |
GET /audit_logs/:id |
VIEW USER |
One record, with what changed. Same scope as GET /audit_logs. |
The audit log object¶
What an audit log object looks like?
{
"id": "audl_e1f32edffa310b4235095b28c",
"created": 1783024653,
"updated": 1783024653,
"activity": "File Created",
"operation": "CREATE",
"source": "API",
"status": "SUCCESS",
"entity_id": "file_NpvMpQuE6fmhWx39Em3Xrfqwg",
"entity_type": "File",
"entity_name": "New Text Document.txt",
"workspace": "main",
"workflow_id": null,
"workflow_name": null,
"workflow_execution_id": null,
"user_email": "user@everysk.com",
"proxy_admin_email": null,
"credential_id": "sid_sCGBAdTb",
"credential_type": "API_KEY",
"ip": "127.0.0.1",
"user_agent": "insomnia/13.0.2",
"user_agent_pretty": "Unknown OS - Unknown Browser",
"location": {
"country": "",
"region": "",
"city": "",
"cityLatLong": ""
},
"viewed_ids": null
}
| Property | Description |
|---|---|
id string |
Unique identifier of the audit log entry. Starts with audl_. |
created timestamp |
Time of the action. Measured in seconds since the Unix epoch, UTC. |
updated timestamp |
Always equal to created, since records are never updated. |
activity string |
A readable description of the action, for example File Created, Portfolio Updated, Workflow Execution Started or Sign In. |
operation string |
The type of operation. See operation. |
source string |
Where the action started. See source. |
status string |
The result of the action. See status. |
entity_id string |
The identifier of the object the action affected, such as a portfolio, a file or a report. |
entity_type string |
The type of the affected object. See entity_type. |
entity_name string |
The name of the affected object at the time of the action. Can be null in older records and for objects without a name. |
workspace string |
The workspace of the action, for example main. |
workflow_id string |
The workflow, when the action ran inside one. Otherwise null. |
workflow_name string |
The workflow name, when it applies. Otherwise null. |
workflow_execution_id string |
The workflow execution. Groups every action of one run. null when it does not apply. |
user_email string |
The e-mail of the user who performed the action. Automatic actions from WORKER, WORKFLOW_BRIDGE, SCHEDULER and INTEGRATION carry System. |
proxy_admin_email string |
When an administrator acts on behalf of another user, the administrator's e-mail. user_email then holds the user acted for. Otherwise null. |
credential_id string |
The credential the request used: the account SID (sid_ prefix) for an API key, the client ID for OAuth2. |
credential_type string |
API_KEY, OAUTH2 or null when no credential applies. |
ip string |
The source IP address of the request. |
user_agent string |
The raw client identification, for example insomnia/13.0.2. |
user_agent_pretty string |
A readable Operating System - Browser version of user_agent. Unknown OS - Unknown Browser when it cannot be identified. |
location object |
The approximate origin, estimated from the IP: country (for example BR), region (for example RS), city and cityLatLong. The subfields are "" when the location cannot be determined, such as on a local network. |
viewed_ids array |
For batch VIEW operations, the identifiers of the objects one read returned. Otherwise null. |
operation¶
| Value | Meaning |
|---|---|
CREATE |
An object was created. |
UPDATE |
An object was changed. |
DELETE |
An object was deleted. |
EXECUTE |
An execution started, such as a workflow. |
CLONE |
An object was cloned. |
SHARE |
An object was shared. |
VIEW |
An object was viewed or read. |
LOGIN |
A user signed in. |
LOGOUT |
A user signed out. |
source¶
| Value | Meaning |
|---|---|
PLATFORM |
The web application. |
API |
The REST API. |
SDK |
The Python SDK. |
WORKER |
A background process. |
INTEGRATION |
An integration. |
WORKFLOW_BRIDGE |
The bridge between workflow executions. |
SCHEDULER |
A schedule. |
UNKNOWN |
The origin could not be identified. |
status¶
| Value | Meaning |
|---|---|
SUCCESS |
The action completed. This is the default. |
ERROR |
The action of an authenticated user failed, for example with HTTP 400, 404, 429 or 500. |
DENIED |
The action was refused for lack of permission (HTTP 401 for an authenticated user, or 403). |
ERROR and DENIED are recorded for authenticated users acting through the PLATFORM or the API. Automatic actions (WORKER, WORKFLOW_BRIDGE, SCHEDULER, INTEGRATION) are always SUCCESS.
entity_type¶
The main types are Portfolio, Report, File, Datastore, CustomSecurity, Workspace, UserApp, Secrets, WorkerTemplate, Workflow and User. Sign-in and sign-out events carry UserEvent, and the start of a workflow execution carries WorkflowExecution.
List audit logs¶
Returns a list of audit log entries, most recent first. GET /audit_logs returns the records in the caller's scope. GET /audit_logs/all takes the same parameters and returns every record of the account.
To list the audit logs of a period, run the following:
The above call returns the following JSON object:
{
"audit_logs": [
{
"id": "audl_e1f32edffa310b4235095b28c",
"created": 1783024653,
"updated": 1783024653,
"activity": "File Created",
"operation": "CREATE",
"source": "API",
"status": "SUCCESS",
"entity_id": "file_NpvMpQuE6fmhWx39Em3Xrfqwg",
"entity_type": "File",
"entity_name": "New Text Document.txt",
"workspace": "main",
...
},
...
],
"next_page_token": null
}
HTTP Request
GET /audit_logs
GET /audit_logs/all
HTTP Parameters
| Parameter | Description |
|---|---|
start string |
optional, default is null Returns records from this date onward. 20260831 starts at the first instant of the day. 20260831 12:55:51 starts at that second. |
end string |
optional, default is null Returns records up to this date. 20260831 runs to the last instant of the day. 20260831 18:00:00 runs to the end of that second. |
date_time string |
optional, default is null Sets start and end to the same value. With a day, such as 20260901, it returns that day. |
page_size integer |
optional, default is 10 Set the number of objects that will be listed per page. |
page_token string |
optional, default is null The token defines which page will be returned to the user. For further information, please check out our pagination guide. |
The period filters the record's updated_on date. Dates use the YYYYMMDD or YYYYMMDD HH:MM:SS format, in UTC, and both bounds are inclusive. Any other format, such as 2026-08-31 or ISO 8601, returns 400.
A time contains a space, so encode it in the URL. With curl, pass the parameters with --data-urlencode:
curl https://api.everysk.com/v2/audit_logs \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
--data-urlencode "start=20260831 12:00:00" \
--data-urlencode "end=20260831 18:00:00" \
-G
Retrieve an audit log¶
Retrieves one audit log entry by its id, with what the action changed on the object.
To retrieve an audit log, run the following:
The above call returns the following JSON object:
{
"entity": {
"id": "audl_e1f32edffa310b4235095b28c",
"activity": "File Created",
...
},
"diff_formatted": {
"added": {"field_x": "value_x"},
"removed": {"field_y": "value_y"},
"modified": {"field_z": {"before": "old value", "after": "new value"}}
},
"before": {...},
"after": {...}
}
| Property | Description |
|---|---|
entity object |
The audit log entry, with the same properties as in the list. |
diff_formatted object |
What changed: added and removed fields, and modified fields with their value before and after. |
before object |
The state of the object before the action. |
after object |
The state of the object after the action. |
Sensitive fields are left out of before and after. A record that does not exist, or that belongs to another user you are not allowed to see, returns 404 with the message Audit log not found..
HTTP Request
GET /audit_logs/:id