> For the complete documentation index, see [llms.txt](https://detected.gitbook.io/detected-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://detected.gitbook.io/detected-docs/audit-logs.md).

# Audit Logs

A record of actions performed on profiles in your account, including who performed each action and when.

## List audit logs

> Returns audit log entries across all profiles in your account. Use \`profile\_id\` to see the entries for a single profile, and the other query parameters to filter the results.\
> \
> This endpoint is paginated. Use the \`page\` parameter to request further pages. The \`meta\` and \`links\` objects in the response describe the current page and link to the others.

```json
{"openapi":"3.0.0","info":{"title":"Detected API","version":"v2"},"tags":[{"name":"Audit Logs","description":"A record of actions performed on profiles in your account, including who performed each action and when."}],"servers":[{"url":"https://api.detected.app/api/v2/public","description":"Production"}],"security":[{"AccessToken":[]}],"components":{"securitySchemes":{"AccessToken":{"type":"http","description":"The API uses OAuth 2.0. Request an access token from `POST /oauth/token` with the client ID and client secret of your integration client, and your account slug. Send the access token in the `Authorization` header of every request, in the format `Authorization: Bearer <access_token>`. The access token carries the scopes set on your integration client in the dashboard. Access tokens expire. When one expires, request a new one.","bearerFormat":"OAuth 2.0 access token","scheme":"bearer"}},"parameters":{"order_by":{"name":"order_by","in":"query","description":"Direction to sort the results in: `asc` for ascending or `desc` for descending. Use it together with `sort_by`; it has no effect if `sort_by` is omitted. The default is `asc`.","schema":{"type":"string","enum":["desc","asc"]}},"page":{"name":"page","in":"query","description":"Page number of the results to return, starting from 1. The number of items per page is returned in `meta.per_page`.","schema":{"type":"integer","minimum":1}}},"headers":{"X-RateLimit-Limit":{"description":"Maximum number of requests allowed in the rate limit window.","schema":{"type":"number","nullable":false}},"X-RateLimit-Remaining":{"description":"Number of requests remaining in the current rate limit window.","schema":{"type":"number","nullable":false}},"Retry-After":{"description":"Number of seconds to wait before making another request. Returned when the rate limit has been reached.","schema":{"type":"number","nullable":false}},"X-RateLimit-Reset":{"description":"Unix timestamp (in seconds) at which the rate limit resets. Returned when the rate limit has been reached.","schema":{"type":"number","nullable":false}}},"schemas":{"AuditLogResource":{"title":"Audit Log Resource","required":["id","profile_id","profile_name","actioned_at","performed_by","auth_type","application","resource","action","reason"],"properties":{"id":{"description":"Audit log ID.","type":"integer","nullable":false},"profile_id":{"description":"UUID of the profile the audit log belongs to.","type":"string","nullable":false},"profile_name":{"description":"Name of the profile the audit log belongs to.","type":"string","nullable":true},"actioned_at":{"description":"Date and time the action was performed.","type":"string","nullable":false},"performed_by":{"description":"Name of the user or system that performed the action.","type":"string","nullable":false},"auth_type":{"description":"Authentication type used.","type":"string","nullable":true},"application":{"description":"Application that triggered the action.","type":"string","nullable":false},"resource":{"description":"Type of resource the action was performed on, for example `Company Profile`.","type":"string","nullable":false},"action":{"description":"Action that was performed, for example `updated`.","type":"string","nullable":false},"reason":{"description":"Reason for the action.","type":"string","nullable":true}},"type":"object"},"LinksResource":{"title":"Links Resource","properties":{"first":{"description":"URL of the first page of results.","type":"string","nullable":false},"last":{"description":"URL of the last page of results.","type":"string","nullable":false},"prev":{"description":"URL of the previous page of results, or null if there is none.","type":"string","nullable":false},"next":{"description":"URL of the next page of results, or null if there is none.","type":"string","nullable":false}},"type":"object"},"MetaResource":{"title":"Meta Resource","properties":{"current_page":{"description":"Number of the current page.","type":"number","nullable":false},"from":{"description":"Position of the first item on this page, counted across all pages.","type":"number","nullable":false},"last_page":{"description":"Number of the last page.","type":"number","nullable":false},"links":{"description":"Pagination links, including links to the previous and next pages.","type":"array","items":{"properties":{"url":{"description":"URL of the page, or `null` if there is no such page.","type":"string","nullable":false},"label":{"description":"Text to display for the link, for example a page number or \"Previous\".","type":"string","nullable":false},"active":{"description":"Whether this link is for the current page.","type":"boolean","nullable":false}},"type":"object"},"nullable":false},"path":{"description":"Base URL of the endpoint, without query parameters.","type":"string","nullable":false},"per_page":{"description":"Number of items per page.","type":"number","nullable":false},"to":{"description":"Position of the last item on this page, counted across all pages.","type":"number","nullable":false},"total":{"description":"Total number of items across all pages.","type":"number","nullable":false}},"type":"object"}},"responses":{"401":{"description":"Unauthorized. The access token is missing, invalid or has expired.","content":{"application/json":{"schema":{"properties":{"message":{"description":"A human-readable description of the error.","type":"string"}},"type":"object"}}}},"403":{"description":"Forbidden. Your access token is valid, but you do not have permission to access this resource.","content":{"application/json":{"schema":{"properties":{"message":{"description":"A human-readable description of the error.","type":"string"}},"type":"object"}}}},"429":{"description":"Too Many Requests. You have exceeded the rate limit. Wait for the number of seconds given in the `Retry-After` header before trying again.","headers":{"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"Retry-After":{"$ref":"#/components/headers/Retry-After"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"}},"content":{"application/json":{"schema":{"properties":{"message":{"description":"A human-readable description of the error.","type":"string"}},"type":"object"}}}}}},"paths":{"/audit-logs":{"get":{"tags":["Audit Logs"],"summary":"List audit logs","description":"Returns audit log entries across all profiles in your account. Use `profile_id` to see the entries for a single profile, and the other query parameters to filter the results.\n\nThis endpoint is paginated. Use the `page` parameter to request further pages. The `meta` and `links` objects in the response describe the current page and link to the others.","operationId":"ceddc720e6c247a7e91f21536456e799","parameters":[{"$ref":"#/components/parameters/order_by"},{"name":"sort_by","in":"query","description":"The field to sort the results by. Use it together with `order_by` to choose the direction; if `order_by` is omitted, results are sorted in ascending order (`asc`). If `sort_by` is omitted, results are returned sorted by `actioned_at` in descending order (newest first).\n\nSupported fields:\n- `id`\n- `actioned_at`\n- `action`\n- `performed_by`\n","required":false,"schema":{"type":"string"}},{"$ref":"#/components/parameters/page"},{"name":"profile_id","in":"query","description":"Filter by the UUID of a profile.","schema":{"type":"string","format":"uuid"}},{"name":"action","in":"query","description":"Filter by the action performed, for example `created`, `updated` or `viewed`.","schema":{"type":"string"}},{"name":"performed_by","in":"query","description":"Filter by the name of the user or system that performed the action.","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","headers":{"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"}},"content":{"application/json":{"schema":{"properties":{"data":{"description":"List of audit log entries","type":"array","items":{"$ref":"#/components/schemas/AuditLogResource"}},"links":{"$ref":"#/components/schemas/LinksResource"},"meta":{"$ref":"#/components/schemas/MetaResource"}},"type":"object"}}}},"401":{"$ref":"#/components/responses/401"},"403":{"$ref":"#/components/responses/403"},"429":{"$ref":"#/components/responses/429"}}}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://detected.gitbook.io/detected-docs/audit-logs.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
