Skip to content
Everruns Cloud is open in early access. Run agents without operating the platform.

List audit logs for the caller's organization. Supports domain, action, actor, and event-type filters.

GET
/v1/orgs/{org}/audit-logs
curl --request GET \
--url https://app.everruns.com/api/v1/orgs/example/audit-logs
org
required
string

Prefixed public identifier

limit
integer format: int64

Max entries to return (default 50, max 200).

before
string format: date-time

Cursor: return entries created before this timestamp.

event_type
string

Filter by event type prefix (e.g. “auth.login”) — legacy.

actor_id
string format: uuid

Filter by actor UUID.

domain
string

Filter by audit domain (“management” or “agent”).

action
string

Filter by action string (e.g. “management.member.invited”).

Success

Media typeapplication/json

Response wrapper for list endpoints. All list endpoints return responses wrapped in a data field.

object
data
required

Array of items returned by the list operation.

Array<object>

Domain-level audit log view. Mirrors AuditLogRow but omits org_id (derived from the caller) and formats IDs as strings, matching the shape returned by the HTTP and MCP adapters.

object
action
required

What happened, as <domain>.<resource>.<verb>.

string
actor_id

UUID of the user who acted, when a user did.

string | null
created_at
required

Timestamp when this resource was created (RFC 3339).

string format: date-time
domain
required

Audit domain: management for org administration, agent for agent activity.

string
event_type
required

Legacy event type, kept for older filters.

string
id
required

Prefixed public identifier. See ID Schema.

string
ip_address

Client IP address of the request, when known.

string | null
metadata
required

Free-form metadata attached to this resource.

target_id

Identifier of the resource the entry is about.

string | null
target_type

Kind of resource the entry is about.

string | null
Example
{
"data": [
{
"action": "management.member.invited",
"actor_id": "01933b5a-0000-7000-8000-000000000001",
"domain": "management",
"event_type": "auth.login",
"target_type": "member"
}
]
}