# List the Status audit log

`GET https://evohub.io/api/v1/status-audit-logs`

Part of the [Status API](https://docs-dev.evohub.io/status.md) reference · operationId `listStatusAuditLogs`.

Who changed what in Status, newest first, for the whole organization (not
narrowed by team). Paged with `limit` and `offset`.

**Permission (API-key scope):** `status:audit:read`.

## Authorization

Any one of:

- `bearerAuth` (status:audit:read)
- `apiKeyHeader` (status:audit:read)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Query parameters

- `limit` (integer, default `50`, min 1, max 200): Page size. A value over 200 gives 200; one that is not a positive number gives 50.
- `offset` (integer, default `0`, min 0)

## Responses

### 200 — The entries.

Content type: `application/json`

Type: `object`

- `data` (array of AuditLog, required)
  - `id` (string (uuid))
  - `org_id` (string)
  - `actor_user_id` (string): The user or API key that did it; `system` for EvoHub itself.
  - `action` (string): `resource.verb`, for example `page.created`, `component.status_changed`, `incident.resolved`, `subscriber.deleted`, `domain.added`.
  - `resource_type` (string, one of `page`, `component`, `incident`, `maintenance`, `subscriber`, `org`)
  - `resource_id` (string)
  - `metadata` (object)
    - Other keys: any
  - `created_at` (string (date-time))
- `success` (boolean, required, value `true`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/status-audit-logs' \
  -H 'Authorization: Bearer <TOKEN>'
```
