curl --request GET \
--url https://getunblocked.com/api/v1/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "https://getunblocked.com/api/v1/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://getunblocked.com/api/v1/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://getunblocked.com/api/v1/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://getunblocked.com/api/v1/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://getunblocked.com/api/v1/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://getunblocked.com/api/v1/audit-logs")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"eventId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2026-10-03T16:03:21Z",
"eventType": "<string>",
"actor": {
"type": "Person",
"name": "<string>",
"email": "jsmith@example.com",
"provider": "<string>"
},
"action": [
"Added GitHub as a data source"
],
"provider": "<string>",
"dataSource": {
"name": "<string>"
},
"userAgent": "<string>",
"client": "<string>"
}
]{
"status": 400
}{
"status": 400
}{
"status": 400
}{
"status": 400
}List Audit Logs
List audit logs for the authenticated team in ascending creation order.
Use since to start at an inclusive date-time or after to continue from a
previous page. Supplying both parameters returns HTTP 400.
Each page with audit logs includes a next link, even if the page is not
full. Follow that link until the response is empty. Then stop and retry
the same URL when you poll again. Cursors use stable keyset pagination
and never expire.
Authentication behavior:
- Personal Access Token (PAT) keys: Team admins can export all audit logs for their team; non-admin members receive 403 Forbidden.
- Team-wide API keys: All audit logs for the team are returned.
curl --request GET \
--url https://getunblocked.com/api/v1/audit-logs \
--header 'Authorization: Bearer <token>'import requests
url = "https://getunblocked.com/api/v1/audit-logs"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://getunblocked.com/api/v1/audit-logs', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://getunblocked.com/api/v1/audit-logs",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://getunblocked.com/api/v1/audit-logs"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://getunblocked.com/api/v1/audit-logs")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://getunblocked.com/api/v1/audit-logs")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"eventId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2026-10-03T16:03:21Z",
"eventType": "<string>",
"actor": {
"type": "Person",
"name": "<string>",
"email": "jsmith@example.com",
"provider": "<string>"
},
"action": [
"Added GitHub as a data source"
],
"provider": "<string>",
"dataSource": {
"name": "<string>"
},
"userAgent": "<string>",
"client": "<string>"
}
]{
"status": 400
}{
"status": 400
}{
"status": 400
}{
"status": 400
}Authorizations
The API key to authenticate requests. Obtainable from the web dashboard.
Query Parameters
Limit used to constrain results of list operations. When not specified a default limit of 25 is used.
A maximum limit is applied to the results, so the server may respond with fewer results than requested; clients must not use this as a signal that this is the final page of results.
1 <= x <= 200Opaque cursor for continuing after a previous page. Follow the URL marked rel="next"
in the Link response header to obtain it; do not construct or parse the cursor.
Opaque cursor to be used for paging in a forward or backward direction. Cursors are stateless and so they never expire.
1 - 10000Include audit logs created at or after this RFC 3339 date-time. Use this to
start an export; use after on subsequent pages. Cannot be combined with after.
"2026-10-03T00:00:00Z"
Response
OK
Unique identifier for this event.
Time this audit log was created, formatted as an RFC 3339 date-time with a UTC offset.
"2026-10-03T16:03:21Z"
The machine-readable audit event kind (for example, DataSourceAdded).
New values may be added over time, so consumers should accept unknown values.
The person, API key, data source, or system process that initiated this action.
Show child attributes
Show child attributes
Human-readable action lines in display order. This wording may change; use eventType for programmatic classification.
One human-readable line describing the action; lines appear in display order.
Integration provider associated with the event, using the Provider name (for example, GitHub), when applicable.
The associated data source, if this action concerns one.
Show child attributes
Show child attributes
HTTP User-Agent header of the request that triggered the event, when available.
Unblocked client that triggered the event (for example, Dashboard), when available.