> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.instabase.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.instabase.com/_mcp/server.

# Get audit logs

POST https://aihub.instabase.com/api/v1/auditlogs
Content-Type: application/json

Retrieve audit logs based on specified filters. Returns a paginated list of audit log entries.This API operation is available for Enterprise-tier organizations with single-tenant environments. To use it you must have audit log access permissions. Contact Instabase Support to request access to audit logs for your organization.This API operation is not supported by the SDK but you can access it from Python by making direct REST calls, as shown in the sample code.

Reference: https://docs.instabase.com/api-sdk/api-reference/audit/get-audit-logs

## Authentication

- `Authorization` header (bearer token, required) — Bearer HTTP authentication.

## Request

### Body (application/json)

This endpoint expects an object.

- `start` (integer, optional, nullable) — Number of results to skip for pagination
- `size` (integer, optional, nullable) — Maximum number of results to return
- `log_type` (string, optional, nullable) — Type of audit log to filter by. Valid values include: - `account_v2`: User account creation logs - `api_v2`: API request logs - `app_deployment_run_v2`: Deployment run operation logs - `app_deployment_v2`: Deployment operation logs - `app_v2`: Automation app operation logs - `datasource_v2`: Data connection operation logs - `login_v2`: User login and authentication logs - `oauth2_v2`: OAuth token operation logs - `org_v2`: Organization role change logs - `org_secrets_v2`: Organization secrets operation logs - `perms_v2`: Membership and role change logs, for the organization, workspaces, and groups - `projects_v2`: Automation project operation logs - `review_v2`: Human review operation logs - `workspace_v2`: Workspace management operation logs For details about tracked operations, see [Viewing audit logs](/admin/audit-logs/).
- `email` (string, optional, nullable) — Filter logs by user email
- `start_time` (string, optional, nullable) — Start time in epoch milliseconds
- `end_time` (string, optional, nullable) — End time in epoch milliseconds

## Response

### 200

Successfully retrieved audit logs

- `status` (string, optional)
- `data` (V1AuditlogsPostResponsesContentApplicationJsonSchemaData, optional)

## Types

### V1AuditlogsPostResponsesContentApplicationJsonSchemaData

- `results` (list of V1AuditlogsPostResponsesContentApplicationJsonSchemaDataResultsItems, optional)

### V1AuditlogsPostResponsesContentApplicationJsonSchemaDataResultsItems

- `timestamp_millis` (string, optional) — Timestamp in epoch milliseconds
- `email` (string, optional) — User email associated with the log entry
- `user_ip` (string, optional) — IP address of the user
- `log_type` (string, optional) — Type of the audit log

## Examples

**Request**

```json
{}
```

**Response**

```json
{
  "status": "OK",
  "data": {
    "results": [
      {
        "timestamp_millis": "1682505600000",
        "email": "alice.smith@example.com",
        "user_ip": "203.0.113.42",
        "log_type": "login_v2"
      }
    ]
  }
}
```

**SDK Code**

```python without SDK
# SDK does not support this operation, so you
# must make REST calls using "requests" module
import requests

url = "https://aihub.instabase.com/api/v1/auditlogs"

headers = {
    "Authorization": "Bearer abcdefghijklmnopqrst1234567890",
    "IB-Context": "john.doe_acme.com"
}

# create the request payload
data = {
    "log_type": "org_secret",
    "size": 50,
    "start_time": "1749139277810",
    "start": 200
}

# make the POST request
response = requests.post(url, headers=headers, json=data)

# handle the response
if response.status_code == 200:
    audit_logs = response.json()
    print(f"Retrieved {len(audit_logs['data']['results'])} audit logs")
else:
    print(f"Error: {response.status_code} - {response.text}")

```

```javascript
const url = 'https://aihub.instabase.com/api/v1/auditlogs';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://aihub.instabase.com/api/v1/auditlogs"

	payload := strings.NewReader("{}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://aihub.instabase.com/api/v1/auditlogs")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://aihub.instabase.com/api/v1/auditlogs")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://aihub.instabase.com/api/v1/auditlogs', [
  'body' => '{}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://aihub.instabase.com/api/v1/auditlogs");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://aihub.instabase.com/api/v1/auditlogs")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```