Skip to content

Security and audit

List sign-ins

Returns sign-in attempts of the workspace’s members, newest first, one page at a time. Each one says how the person signed in, whether it worked (and why not), where it came from and whether the device or country was new for that account.

GET/api/v1/security/logins
  • Bearer API key
  • Scope: admin only
  • or app session
  • Workspace: X-Tenant-ID (optional with a key)

Headers

  • Authorizationstringrequired

    Your API key as Bearer <key>. The word Bearer and the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.

    Constraints
    Keys start with pk_live_ and are 56 characters long.
    Example
    Bearer pk_live_…
  • X-Tenant-IDuuidoptional

    Workspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Query parameters

  • user_iduuidoptional

    Only this teammate (their user id, user_id in the members list).

  • resultenumoptional

    success or failure. Leave it out for both.

    Example
    failure
  • fromtimestampoptional

    Only entries from this time on. RFC 3339 (2026-10-01T00:00:00Z) or a date (2026-10-01).

    Example
    2026-10-01
  • totimestampoptional

    Only entries before this time (exclusive). RFC 3339 or a date: to include all of 8 October, send to=2026-10-09.

  • cursorstringoptional

    The next_cursor of the previous page, unchanged. Leave it out to get the first page.

  • limitintegeroptional

    Items per page.

    Constraints
    At most 200.
    Default
    50
    Example
    50

Response

200 OKapplication/json

  • itemsarray<LoginEvent>

    Sign-ins, newest first.

    Show child attributesHide child attributes15
    • idstring

      Sign-in id.

    • user_iduuidnullable

      The account that signed in or was tried. null when no account matched.

    • user_namestring

      Name of that account, or "".

    • emailstring

      Email address used to sign in.

    • methodenum

      password, google, invite (signed in by accepting an invite) or signup (signed in by creating the account).

    • resultenum

      success or failure.

    • reasonenum

      Why a sign-in failed: bad_password, unknown_account (no account with this email), disabled (the account is disabled), google_conflict (the email is linked to a different Google account) or google_unverified (Google has not verified the email). "" for successful sign-ins.

    • ipstring

      IP address the attempt came from.

    • locationstring

      City and country of the IP address, for example Ljubljana, SI, or only the country (SI). "" when unknown.

    • countrystring

      Two-letter country code of the IP address, or "".

    • citystring

      City of the IP address, or "".

    • devicestring

      Browser and operating system, for example Chrome on macOS, or "".

    • new_deviceboolean

      true when the account had not signed in from this device before.

    • new_countryboolean

      true when the account had not signed in from this country before.

    • created_attimestamp

      When it happened (RFC 3339).

  • next_cursorstring

    Send it as cursor to get the next page. An empty string ("") means this is the last page.

Status codes

  • 200OK. One page of sign-ins.
  • 400Bad request. A filter is malformed: invalid from or invalid to (neither RFC 3339, YYYY-MM-DD nor unix seconds), invalid user_id, invalid result or invalid cursor. A session request without a workspace gets workspace required (X-Tenant-ID).
  • 401Unauthorized. The API key is unknown, revoked or expired (invalid or expired API key), or there is no key and no signed-in session (unauthorized).
  • 403Forbidden. The API key does not have the admin scope (this endpoint needs an API key with the admin scope: read and write keys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address, code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace, forbidden).
  • 500Server error. Something went wrong on our side. Retry with backoff.

Whose sign-ins are returned?

  • Owners, admins and admin API keys get the sign-ins of every member of the workspace. Filter one person with user_id.
  • Agents signed in to the app only get their own sign-ins: user_id is always set to themselves.

How do I page through the list?

Items come newest first, limit at a time (50 by default, at most 200). While next_cursor is not empty, call the endpoint again with the same filters and cursor=<next_cursor>. An empty next_cursor ("") means you have the last page.