curl --request GET \
--url https://public-api.sessionboard.com/v1/logs/audit-trail \
--header 'x-access-token: <api-key>'import requests
url = "https://public-api.sessionboard.com/v1/logs/audit-trail"
headers = {"x-access-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-access-token': '<api-key>'}};
fetch('https://public-api.sessionboard.com/v1/logs/audit-trail', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/logs/audit-trail",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/logs/audit-trail"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-access-token", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://public-api.sessionboard.com/v1/logs/audit-trail")
.header("x-access-token", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/logs/audit-trail")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-access-token"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"stream": "api-requests",
"occurred_at": "2023-11-07T05:31:56Z",
"ingested_at": "2023-11-07T05:31:56Z",
"action": "GET /v1/events",
"outcome": "success",
"reason": "<string>",
"actor": {
"type": "<string>",
"id": "<string>",
"name": "<string>",
"token_hint": "<string>",
"user_email": "<string>"
},
"src_ip": "<string>",
"user_agent": "<string>",
"status": 123,
"duration_ms": 123,
"target": {
"type": "event",
"id": "<string>"
},
"details": {}
}
],
"next_cursor": "<string>",
"has_more": true
}{
"error": "VALIDATION_ERROR",
"message": "<string>"
}{
"error": "VALIDATION_ERROR",
"message": "<string>"
}List audit trail
Every recorded change to your organization’s data — who changed which record,
which property, and (by default) the new value. action is
<subject_type>.<operation>, for example session.update. No retention limit.
curl --request GET \
--url https://public-api.sessionboard.com/v1/logs/audit-trail \
--header 'x-access-token: <api-key>'import requests
url = "https://public-api.sessionboard.com/v1/logs/audit-trail"
headers = {"x-access-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-access-token': '<api-key>'}};
fetch('https://public-api.sessionboard.com/v1/logs/audit-trail', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/logs/audit-trail",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/logs/audit-trail"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-access-token", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://public-api.sessionboard.com/v1/logs/audit-trail")
.header("x-access-token", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/logs/audit-trail")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-access-token"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "<string>",
"stream": "api-requests",
"occurred_at": "2023-11-07T05:31:56Z",
"ingested_at": "2023-11-07T05:31:56Z",
"action": "GET /v1/events",
"outcome": "success",
"reason": "<string>",
"actor": {
"type": "<string>",
"id": "<string>",
"name": "<string>",
"token_hint": "<string>",
"user_email": "<string>"
},
"src_ip": "<string>",
"user_agent": "<string>",
"status": 123,
"duration_ms": 123,
"target": {
"type": "event",
"id": "<string>"
},
"details": {}
}
],
"next_cursor": "<string>",
"has_more": true
}{
"error": "VALIDATION_ERROR",
"message": "<string>"
}{
"error": "VALIDATION_ERROR",
"message": "<string>"
}Authorizations
Organization API token. Generate from Organization Settings → API Tokens.
Query Parameters
next_cursor from the previous page. Store it after each page and send it back unchanged;
it remembers your filters, so repeat the same filters with it.
2048Where to start when you have no cursor. Defaults to 24 hours ago. Ignored when cursor is sent.
Events per page.
1 <= x <= 1000Comma-separated record types to include, for example session,contact.
"session,contact"
Set false to omit changed values (details.value) — useful when the SIEM must not hold personal data.
Response
One page of events, oldest first.
Show child attributes
Show child attributes
Send this as cursor on the next call. On an empty page it is the cursor you sent,
so a caught-up poller keeps it and waits.
true when more events are ready now — fetch again immediately. false means wait before polling.

