# Search the audit trail

`GET https://evohub.io/api/v1/evotrail/audit`

Part of the [EvoTrail API](https://docs-dev.evohub.io/evotrail.md) reference · operationId `searchAuditTrail`.

Events from every product the key may read, newest first. Filters combine.
Paged by cursor: pass `next_cursor` back as `cursor` while `has_more` is true.
The list rows leave out `before`, `after` and `metadata`; read one event for
those.

**Permission (API-key scope):** `evotrail:audit:read`. Each product's rows also need that product's `*:audit:read`; Catalog's rows are for owners and administrators only.

## Authorization

Any one of:

- `bearerAuth` (evotrail:audit:read)
- `apiKeyHeader` (evotrail:audit:read)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Query parameters

- `product` (array of Product): Only these products; repeat it (`product=oncall&product=uptime`) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.
- `actor_id` (string, max length 200): Who did it: a user, API key or agent id.
- `actor_type` (string, one of `user`, `api_key`, `agent`, `system`, `evohub_staff`)
- `action` (string, max length 200, pattern `^[a-z0-9_.]+\*?$`, example `member.*`): An exact action, or a prefix ending in `*` (`alert.*`). Lower case, digits, `_` and `.`.
- `resource_type` (string, max length 200)
- `resource_id` (string, max length 200)
- `team_id` (string, max length 200): Events on resources of this team.
- `request_id` (string, max length 200): Every event one API request caused.
- `ip` (string): An IPv4 or IPv6 address.
- `class` (string, one of `audit`, `activity`)
- `from` (string, example `2026-09-10`): `YYYY-MM-DD` (UTC) or RFC 3339. Default 30 days before `to`.
- `to` (string, example `2026-10-09`): `YYYY-MM-DD` (inclusive) or RFC 3339. Default now.
- `limit` (integer, default `50`, min 1, max 200)
- `cursor` (string): `next_cursor` from the previous page.

## Responses

### 200 — A page of events.

Content type: `application/json`

Type: `object`

- `data` (object, required)
  - `items` (array of AuditEvent)
    - `id` (string (uuid), required)
    - `event_id` (string, required): The producing product's own id for the event.
    - `source` (string, required): The service that reported it.
    - `product` (Product, required, one of `organization`, `oncall`, `uptime`, `status`, `docs`, `changelog`, `board`, `retro`, `support`, `catalog`, `evotrail`)
    - `team_id` (string | null): The team the resource belongs to.
    - `actor` (object, required)
      - `type` (string, one of `user`, `api_key`, `agent`, `system`, `evohub_staff`)
      - `id` (string | null)
      - `name` (string | null)
      - `teams` (array of string | null)
    - `action` (string, required): `<resource>.<verb>`, for example `alert.acknowledged` or `member.role_changed`.
    - `class` (string, required, one of `audit`, `activity`): `audit` is a change to configuration or access (kept 365 days); `activity` is day-to-day work (kept 90 days).
    - `resource` (object, required)
      - `type` (string | null)
      - `id` (string | null)
      - `name` (string | null)
    - `request_id` (string | null)
    - `ip` (string | null): Kept 90 days.
    - `user_agent` (string | null): Kept 90 days.
    - `occurred_at` (string (date-time), required)
    - `has_details` (boolean, required): Whether `before`, `after` or `metadata` exist; read the single event to get them.
    - `before` (any): The resource before the change (single-event read only). Secrets are masked by the producer.
    - `after` (any): The resource after the change (single-event read only).
    - `metadata` (any): Anything else the product recorded (single-event read only).
  - `next_cursor` (string): Absent on the last page.
  - `has_more` (boolean)
  - `products` (array of Product): The products searched.
  - `from` (string (date-time))
  - `to` (string (date-time))
- `success` (boolean, required, value `true`)

### 400 — A range or filter is not valid (`VALIDATION_ERROR`); the message names it.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 403 — The key lacks the EvoTrail scope, or may read none of the products asked for (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.
- `success` (boolean, value `false`)

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/evotrail/audit' \
  -H 'Authorization: Bearer <TOKEN>'
```
