> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.sessionboard.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List security events

> Sign-ins, sign-in failures, two-factor and passkey events, password resets and
session changes for the people in your organization. Covers events recorded
against the organization and those of its current members.
Sessionboard staff activity is not included. No retention limit.




## OpenAPI

````yaml /api-reference/openapi.yaml get /v1/logs/security-events
openapi: 3.1.0
info:
  title: Sessionboard Public API
  version: '1.0'
  description: >-
    REST API for managing sessions, speakers, contacts, sponsors, exhibitors,
    and event data on the Sessionboard platform.
  contact:
    name: Sessionboard Support
    email: support@sessionboard.com
  termsOfService: https://www.sessionboard.com/legal/terms-of-service
servers:
  - url: https://public-api.sessionboard.com
    description: US Region
  - url: https://public-api-eu.sessionboard.com
    description: EU Region
security:
  - ApiKey: []
  - BearerToken: []
tags:
  - name: Events
    description: Manage events on the platform.
  - name: Sessions
    description: Search and retrieve sessions within an event.
  - name: Session Writes
    description: >-
      Create, update, delete, and restore sessions. Requires the
      `write:sessions` scope.
  - name: Contact Writes
    description: >-
      Create, update, delete, and restore contacts. Requires the
      `write:contacts` scope.
  - name: Exhibitor Writes
    description: >-
      Create, update, delete, and restore exhibitors. Requires the
      `write:exhibitors` scope.
  - name: Sponsor Writes
    description: >-
      Create, update, delete, and restore sponsors. Requires the
      `write:sponsors` scope.
  - name: Field Writes
    description: >-
      Create, update, and delete custom fields. Requires the `write:fields`
      scope.
  - name: Speakers
    description: Search and retrieve speakers within an event.
  - name: Participants
    description: |
      Search and retrieve every contact holding a session role on an event —
      speakers, chairpersons, moderators and custom roles — with the roles
      each one holds, and list the event's participant roles.
  - name: Contacts
    description: Search and retrieve contacts at the organization or event level.
  - name: Sponsors
    description: Search and retrieve sponsors within an event.
  - name: Exhibitors
    description: Search and retrieve exhibitors within an event.
  - name: Event Settings
    description: >-
      Retrieve event configuration such as fields, tags, tracks, rooms, formats,
      levels, languages, and session statuses.
  - name: GDPR
    description: Manage GDPR data access and erasure requests.
  - name: Insights
    description: >-
      Query event data using SbQL, generate queries with AI, and manage
      dashboards.
  - name: Metadata Writes
    description: >-
      Create, update, and delete session metadata (rooms, tracks, tags, formats,
      levels, languages, statuses). Requires the `write:metadata` scope.
  - name: Agenda Planning
    description: >-
      Manage agenda drafts, draft sessions, scheduling rules, and evaluation
      personas. Requires the `write:events` scope.
  - name: Dashboards & Widgets
    description: >-
      Create, read, update, and delete dashboards and widgets at the event or
      organization level. Requires `write:events` scope for writes.
  - name: Reports & Queries
    description: >-
      Create, read, update, delete, and run saved SbQL queries/reports at the
      event or organization level. Requires `write:events` scope for writes.
  - name: Transcriptions
    description: >-
      Transcript text on sessions — fragments, summaries, insights, and
      translations. Requires `read:transcriptions` / `write:transcriptions`
      scopes.
  - name: Session Recordings
    description: >-
      Session audio files for recording archives (live capture or imported
      audio). Requires `read:transcriptions` / `write:transcriptions` scopes.
  - name: Media
    description: >-
      Upload video or audio files for automatic transcription. Requires
      `read:media` / `write:media` scopes.
  - name: Session Files
    description: >
      Documents attached to sessions (PDFs, PowerPoint, Word, images, and
      similar).

      Simple upload: `POST .../files/upload` (multipart, max 50 MB).

      Direct-to-storage: create → PUT → complete (max 500 MB).

      Requires `read:sessions` / `write:sessions` scopes.

      See the [Uploading session files](/guides/uploading-session-files) guide.
  - name: OAuth
    description: >-
      OAuth 2.1 endpoints for AI client authorization (Claude, ChatGPT). Mounted
      at `/oauth/` (not `/v1/`).
  - name: Log Export
    description: >
      Pull your organization's API request, security and audit logs into a SIEM

      such as Splunk, Microsoft Sentinel or Elastic. Requires a dedicated API
      token

      with the `read:audit_logs` scope, which can call nothing else.

      See the [Exporting logs to a SIEM](/guides/exporting-logs-to-a-siem)
      guide.
paths:
  /v1/logs/security-events:
    get:
      tags:
        - Log Export
      summary: List security events
      description: >
        Sign-ins, sign-in failures, two-factor and passkey events, password
        resets and

        session changes for the people in your organization. Covers events
        recorded

        against the organization and those of its current members.

        Sessionboard staff activity is not included. No retention limit.
      operationId: list-log-security-events
      parameters:
        - $ref: '#/components/parameters/LogCursor'
        - $ref: '#/components/parameters/LogSince'
        - $ref: '#/components/parameters/LogLimit'
        - name: outcome
          in: query
          required: false
          schema:
            type: string
            enum:
              - success
              - failure
          description: Only successful or only failed events.
      responses:
        '200':
          description: One page of events, oldest first.
          headers:
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogPage'
        '400':
          description: >
            `VALIDATION_ERROR` for a bad parameter; `INVALID_CURSOR` for a
            cursor that is malformed or was issued for another stream or
            organization;

            `CURSOR_FILTER_MISMATCH` when the filters differ from the ones the
            cursor was issued with;

            `SINCE_BEFORE_RETENTION` when `since` is older than the stream
            keeps.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogExportError'
        '401':
          description: Missing, invalid, revoked or expired API token.
        '403':
          description: >-
            The token does not hold `read:audit_logs`, or it is an OAuth token.
            Log export accepts API tokens only.
        '410':
          description: >-
            `CURSOR_EXPIRED` — the cursor points before the start of retention.
            Restart from `since`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LogExportError'
        '429':
          description: Rate limited. 60 requests per minute per token; honor `Retry-After`.
      security:
        - ApiKey: []
components:
  parameters:
    LogCursor:
      name: cursor
      in: query
      required: false
      schema:
        type: string
        maxLength: 2048
      description: >
        `next_cursor` from the previous page. Store it after each page and send
        it back unchanged;

        it remembers your filters, so repeat the same filters with it.
    LogSince:
      name: since
      in: query
      required: false
      schema:
        type: string
        format: date-time
      description: >-
        Where to start when you have no cursor. Defaults to 24 hours ago.
        Ignored when `cursor` is sent.
    LogLimit:
      name: limit
      in: query
      required: false
      schema:
        type: integer
        minimum: 1
        maximum: 1000
        default: 500
      description: Events per page.
  headers:
    RateLimitLimit:
      description: Requests allowed in the current window.
      schema:
        type: integer
    RateLimitRemaining:
      description: Requests left in the current window.
      schema:
        type: integer
  schemas:
    LogPage:
      type: object
      required:
        - data
        - next_cursor
        - has_more
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/LogEvent'
        next_cursor:
          type: string
          description: >
            Send this as `cursor` on the next call. On an empty page it is the
            cursor you sent,

            so a caught-up poller keeps it and waits.
        has_more:
          type: boolean
          description: >-
            `true` when more events are ready now — fetch again immediately.
            `false` means wait before polling.
    LogExportError:
      type: object
      properties:
        error:
          type: string
          enum:
            - VALIDATION_ERROR
            - INVALID_CURSOR
            - CURSOR_FILTER_MISMATCH
            - SINCE_BEFORE_RETENTION
            - CURSOR_EXPIRED
        message:
          type: string
    LogEvent:
      type: object
      description: >
        One event, in the same shape on every stream. Events appear about a
        minute after they happen

        and are ordered by when Sessionboard recorded them, so a late-arriving
        event is never skipped.
      properties:
        id:
          type: string
          description: Stable event id. Use it to de-duplicate if you replay a page.
        stream:
          type: string
          enum:
            - api-requests
            - security-events
            - audit-trail
        occurred_at:
          type: string
          format: date-time
          description: When the event happened.
        ingested_at:
          type: string
          format: date-time
          description: When Sessionboard recorded it. Pages are ordered by this.
        action:
          type: string
          description: >-
            `GET /v1/events` for API requests, the event type (for example
            `login.password_ok` or `login.challenge_failed`) for security
            events, `<subject_type>.<operation>` for the audit trail.
          example: GET /v1/events
        outcome:
          type: string
          enum:
            - success
            - failure
            - unknown
        reason:
          type: string
          nullable: true
          description: Why it failed, when it did.
        actor:
          type: object
          properties:
            type:
              type: string
              description: >-
                `api_token`, `oauth_token` or `anonymous` for API requests;
                `user` or `admin` for security events; `user`, `system` or
                `rule` (an automation) for the audit trail.
            id:
              type: string
              nullable: true
            name:
              type: string
              nullable: true
            token_hint:
              type: string
              nullable: true
              description: Last characters of the token id, for API requests.
            user_email:
              type: string
              nullable: true
        src_ip:
          type: string
          nullable: true
        user_agent:
          type: string
          nullable: true
        status:
          type: integer
          nullable: true
          description: HTTP status, for API requests.
        duration_ms:
          type: integer
          nullable: true
          description: Response time, for API requests.
        target:
          type: object
          nullable: true
          properties:
            type:
              type: string
              example: event
            id:
              type: string
        details:
          type: object
          additionalProperties: true
          description: >-
            Stream-specific fields (for example `source` and `request_id` for
            API requests, `property` and `value` for the audit trail).
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-access-token
      description: >-
        Organization API token. Generate from Organization Settings → API
        Tokens.
    BearerToken:
      type: http
      scheme: bearer
      description: >-
        OAuth 2.1 access token. Obtained via the OAuth PKCE flow at
        `/oauth/token`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.