> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List org audit log

> List audit log entries for a workspace

Requires the `audit:read` scope.



## OpenAPI

````yaml /conduit/openapi/api.yaml get /conduit.v1.ConduitService/ListOrgAuditLog
openapi: 3.1.0
info:
  title: Conduit API
  version: v1
  description: |
    Machine-to-machine API for Conduit workspaces. Authenticate a
    workspace API client with OAuth 2.0 client credentials at
    `/oauth/token`, then call these methods with the resulting bearer token.
    Read-only methods are documented as `GET`, with their JSON request encoded
    in the `message` query parameter. Mutating methods use `POST` with a JSON
    body. The server also accepts `POST` for reads. See the API guide for
    auth, scopes, and error handling.
servers:
  - url: https://conduit.example.com
    description: Your Conduit instance — replace with your CONDUIT_BASE_URL
security:
  - bearerAuth: []
tags:
  - name: connectors
    x-group: Connectors
    description: Create and manage connectors and the workspace's Pipedream configuration.
  - name: policies-and-groups
    x-group: Policies & groups
    description: Allow policies, groups, group membership, and effective-access debugging.
  - name: members
    x-group: Members
    description: Read the workspace's member roster.
  - name: single-sign-on
    x-group: Single sign-on
    description: Read sanitized workspace identity-provider configuration.
  - name: provisioning
    x-group: Provisioning
    description: Read sanitized SCIM metadata, provisioning rules, and resource mappings.
  - name: workspace-settings
    x-group: Workspace settings
    description: Change general workspace settings.
  - name: audit-log
    x-group: Audit log
    description: Read the workspace audit log.
paths:
  /conduit.v1.ConduitService/ListOrgAuditLog:
    get:
      tags:
        - audit-log
      summary: List org audit log
      description: |-
        List audit log entries for a workspace

        Requires the `audit:read` scope.
      operationId: ListOrgAuditLog
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
        - name: message
          in: query
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListOrgAuditLogRequest'
        - name: encoding
          in: query
          required: true
          schema:
            $ref: '#/components/schemas/encoding'
        - name: base64
          in: query
          schema:
            $ref: '#/components/schemas/base64'
        - name: compression
          in: query
          schema:
            $ref: '#/components/schemas/compression'
        - name: connect
          in: query
          schema:
            $ref: '#/components/schemas/connect'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListAuditLogResponse'
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    conduit.v1.ListOrgAuditLogRequest:
      type: object
      properties:
        organizationId:
          type: string
          title: organization_id
        limit:
          type:
            - integer
            - string
          title: limit
          format: int64
        offset:
          type:
            - integer
            - string
          title: offset
          format: int64
        filters:
          $ref: '#/components/schemas/conduit.v1.AuditLogFilters'
          title: filters
      title: ListOrgAuditLogRequest
      additionalProperties: false
    encoding:
      title: encoding
      enum:
        - proto
        - json
      description: Define which encoding or 'Message-Codec' to use
    base64:
      type: boolean
      title: base64
      description: >-
        Specifies if the message query param is base64 encoded, which may be
        required for binary data
    compression:
      title: compression
      enum:
        - identity
        - gzip
        - br
      description: Which compression algorithm to use for this request
    connect:
      title: connect
      enum:
        - v1
      description: Define the version of the Connect protocol
    conduit.v1.ListAuditLogResponse:
      type: object
      properties:
        entries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.AuditLogEntry'
          title: entries
      title: ListAuditLogResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    conduit.v1.AuditLogFilters:
      type: object
      properties:
        startTime:
          type:
            - integer
            - string
          title: start_time
          format: int64
          description: unix seconds, inclusive lower bound on created_at (0 = open)
        endTime:
          type:
            - integer
            - string
          title: end_time
          format: int64
          description: unix seconds, inclusive upper bound on created_at (0 = open)
        actor:
          type: string
          title: actor
          description: exact actor (email) match ('' = any)
        eventPrefixes:
          type: array
          items:
            type: string
          title: event_prefixes
          description: >-
            Event prefixes to OR together. A row matches when its event equals a
            prefix
             or sits under it as a namespace, e.g. "config.connector" matches
             config.connector.created/updated/deleted; "config.connector.created" matches
             only that leaf. Empty = all events.
      title: AuditLogFilters
      additionalProperties: false
      description: >-
        AuditLogFilters narrows a list query. Every field is optional; an unset
        field
         (0 / empty) is a no-op, so the same filters apply identically to the instance
         and per-workspace reads.
    conduit.v1.AuditLogEntry:
      type: object
      properties:
        id:
          type:
            - integer
            - string
          title: id
          format: int64
        event:
          type: string
          title: event
          description: e.g. "config.mcp_server.created"
        actor:
          type: string
          title: actor
        organizationId:
          type: string
          title: organization_id
        targetType:
          type: string
          title: target_type
          description: e.g. "mcp_server"
        targetId:
          type: string
          title: target_id
          description: e.g. the server name
        details:
          type: string
          title: details
          description: JSON of semantic fields
        ip:
          type: string
          title: ip
        createdAt:
          type:
            - integer
            - string
          title: created_at
          format: int64
        actorUserId:
          type: string
          title: actor_user_id
          description: >-
            The acting user's id — the join key to telemetry's user.id. Empty
            for
             anonymous, SCIM and system actors, and for rows written before it existed.
        traceId:
          type: string
          title: trace_id
          description: >-
            The trace and span the action ran under, when it was traced. The
            trace id
             can be one the caller supplied (an inbound traceparent is honored); the
             span id is always the server's. The trace may no longer exist in the
             telemetry backend (retention) or may never have been exported.
        spanId:
          type: string
          title: span_id
      title: AuditLogEntry
      additionalProperties: false
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque

````