Security and audit
List audit events
Returns the workspace’s audit events, newest first, one page at a time: every sign-in, message sent, export, team, key and connection change, with the teammate or API key that did it. Owners and admins only (and admin API keys).
- Bearer API key
- Scope:
adminonly - or app session
- Workspace:
X-Tenant-ID(optional with a key)
Headers
AuthorizationstringrequiredYour API key as
Bearer <key>. The wordBearerand the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.X-Tenant-IDuuidoptionalWorkspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass
?tenant=<id>instead.
Query parameters
user_iduuidoptionalOnly this teammate (their user id,
user_idin the members list).api_key_iduuidoptionalOnly actions done with this API key (its
id, not the key itself).actionstringoptionalOnly this action, for example
member.role_changed. End it with*to match a prefix:message.*returnsmessage.sent,message.editedandmessage.deleted.fromtimestampoptionalOnly entries from this time on. RFC 3339 (
2026-10-01T00:00:00Z) or a date (2026-10-01).totimestampoptionalOnly entries before this time (exclusive). RFC 3339 or a date: to include all of 8 October, send
to=2026-10-09.cursorstringoptionalThe
next_cursorof the previous page, unchanged. Leave it out to get the first page.limitintegeroptionalItems per page.
Response
200 OKapplication/json
itemsarray<AuditEvent>Audit events, newest first.
Show child attributesHide child attributes14
idstringEvent id.
actionstringWhat happened, for example
message.sent. See the list of actions below.actor_typeenumuser,api_keyorsystem.actor_user_iduuidnullableThe teammate who did it, when
actor_typeisuser.actor_api_key_iduuidnullableThe API key that did it, when
actor_typeisapi_key.actor_namestringName of the teammate or API key, or
""for the system.viaenumweb(the app),api(an API key) orsystem.resource_typestringKind of thing acted on, for example
conversation, or"".resource_idstringIts id, or
"".detailobjectSmall extra facts that depend on the action, such as
endpoint,count,conversation_id,role,from_role,to_role,email,area,method,rowsorscope. Never message text.{}when there are none.ipstringIP address of the request, or
"".user_agentstringUser agent of the request, or
"".devicestringBrowser and operating system read from it, for example
Chrome on macOS.created_attimestampWhen it happened (RFC 3339).
next_cursorstringSend it as
cursorto get the next page. An empty string ("") means this is the last page.
Status codes
- 200OK. One page of audit events.
- 400Bad request. A filter is malformed:
invalid fromorinvalid to(neither RFC 3339,YYYY-MM-DDnor unix seconds),invalid user_id,invalid resultorinvalid cursor. A session request without a workspace getsworkspace required (X-Tenant-ID). - 401Unauthorized. The API key is unknown, revoked or expired (
invalid or expired API key), or there is no key and no signed-in session (unauthorized). - 403Forbidden. The API key does not have the
adminscope (this endpoint needs an API key with the admin scope:readandwritekeys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address,code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace,forbidden). The audit log is for owners and admins: agents signed in to the app always get403(admin required). - 500Server error. Something went wrong on our side. Retry with backoff.
Which actions are recorded?
| Action | When |
|---|---|
auth.login, auth.login_failed, auth.logout | A member signed in, failed to sign in, or signed out. |
session.revoked, session.revoked_others | A session was signed out, or a member signed out all their other sessions. |
message.sent, attachment.sent | A text message or a file was sent. |
message.edited, message.deleted | A sent message was edited or deleted for everyone. |
conversation.opened, conversation.assigned | A conversation was opened, or assigned to a teammate. |
api.fetch | An API key read data (detail.endpoint and detail.count). |
api_key.created, api_key.updated, api_key.revoked | An API key was created, its IP allowlist changed, or it was revoked. |
api_key.ip_denied | An API key was used from an IP address outside its allowed_ips. |
member.invited, member.added, member.removed, member.role_changed | Team changes (detail.email, detail.role, detail.from_role, detail.to_role). |
invite.revoked, invite.resent | A pending invite was revoked or sent again. |
whatsapp.connect, whatsapp.pair_phone, whatsapp.disconnect, whatsapp.logged_out | Linking a number by QR code or phone number, unlinking it, or the phone logging the link out. |
channel.saved, channel.deleted | Cloud API channel settings were saved or removed. |
settings.changed | Workspace settings changed (detail.area). |
export.contacts_csv, export.participants_csv, export.audit_csv | Contacts, group members or the audit log were downloaded as CSV (detail.rows). |
actor_type and via say who did it: a teammate in the app (user, web), an API key (api_key, api) or whatsappx.si itself (system). Handle action names you do not recognise: new ones may be added.
Can entries be changed?
No. The audit log is append-only: entries cannot be edited or deleted from the app or the API. detail never holds message text.
How do I page through the list?
Items come newest first, limit at a time (50 by default, at most 200). While next_cursor is not empty, call the endpoint again with the same filters and cursor=<next_cursor>. An empty next_cursor ("") means you have the last page.