> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getunblocked.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Audit Logs

> List audit logs for the authenticated team in ascending creation order.
Use `since` to start at an inclusive date-time or `after` to continue from a
previous page. Supplying both parameters returns HTTP 400.

Each page with audit logs includes a `next` link, even if the page is not
full. Follow that link until the response is empty. Then stop and retry
the same URL when you poll again. Cursors use stable keyset pagination
and never expire.

**Authentication behavior:**
- **Personal Access Token (PAT) keys**: Team admins can export all audit logs
  for their team; non-admin members receive 403 Forbidden.
- **Team-wide API keys**: All audit logs for the team are returned.




## OpenAPI

````yaml https://getunblocked.com/api/v1/public-api.json get /audit-logs
openapi: 3.0.3
info:
  contact:
    email: help@getunblocked.com
    name: Unblocked
  description: >
    The Unblocked Public API offers seamless collection for managing custom data
    sources through a structured set of endpoints.

    It allows users to create collections and organize and upload documents.


    # Base URL

    The base URL for all requests is:


    ```jsx

    https://getunblocked.com/api/v1

    ```


    # Authentication

    Authentication requires an API key, obtainable from the web dashboard,

    which must be included in the `Authorization` request header for all
    endpoints.


    ```bash

    curl -X GET https://getunblocked.com/api/v1/collections \
         -H "Authorization: Bearer YOUR_API_KEY"
    ```


    # Rate Limits & Quotas


    **Resource Limits:**

    - Collections: Maximum 25 per team

    - Request Size: Maximum 10MB per request

    - Pagination: 1-200 items per page (default: 25)


    **Answers API:**

    - Daily Limit: 1000 questions per day per team

    - Quota Reset: Midnight PST

    - Exceeding the limit returns a 429 Too Many Requests error


    **Field Constraints:**

    - Collection name: 1-32 characters

    - Collection description: 1-4096 characters
  title: Unblocked Public API Reference
  version: v1
  x-logo:
    url: https://avatars.githubusercontent.com/u/91906527?s=300
    altText: Unblocked
servers:
  - url: https://getunblocked.com/api/v1
security:
  - ApiKeyBearerAuth: []
tags:
  - description: >
      Ask Unblocked questions and retrieve answers asynchronously. Submit a
      question using the PUT endpoint and poll for the response using the GET
      endpoint.
    name: Answers
  - description: >
      A collection in Unblocked allows you to organize related documents from
      various data sources, such as customer support tools, knowledge bases, and
      internal wikis, which are not natively supported by Unblocked.


      You can create multiple collections to manage documents from different
      sources.


      You have the ability to list, create, update, and delete them as needed.


      Deleting a collection will also remove all the associated documents.
    name: Collections
  - description: >
      Retrieve context from the data sources connected to Unblocked, including
      code, pull requests, issues, messages, and documentation.


      Research produces a synthesized answer with supporting sources. Search
      endpoints return relevant sources from a single content space. Query
      endpoints return the issues or pull requests matching a natural-language
      query with optional filters. The get endpoint retrieves URL content
      directly.


      **Authentication behavior:**

      - **Personal Access Token (PAT) keys**: Requests are attributed to the
      key's user

      - **Team-wide API keys**: Requests are attributed to the team
    name: Context
  - description: >
      A document contains content that Unblocked uses to answer questions. Each
      document is associated with a collection, so you must create a collection
      before adding documents. Documents used to provide answers will appear as
      references in the Unblocked interface.


      You can create and delete documents as needed.
    name: Documents
  - description: >
      Retrieve a feed of team events for downstream ingestion into a security

      information and event management (SIEM) system. The feed currently
      includes

      audit logs. Poll the feed to collect new events.
    name: Security Events
paths:
  /audit-logs:
    get:
      tags:
        - Security Events
      summary: List Audit Logs
      description: >
        List audit logs for the authenticated team in ascending creation order.

        Use `since` to start at an inclusive date-time or `after` to continue
        from a

        previous page. Supplying both parameters returns HTTP 400.


        Each page with audit logs includes a `next` link, even if the page is
        not

        full. Follow that link until the response is empty. Then stop and retry

        the same URL when you poll again. Cursors use stable keyset pagination

        and never expire.


        **Authentication behavior:**

        - **Personal Access Token (PAT) keys**: Team admins can export all audit
        logs
          for their team; non-admin members receive 403 Forbidden.
        - **Team-wide API keys**: All audit logs for the team are returned.
      operationId: listAuditLogs
      parameters:
        - description: >
            Limit used to constrain results of list operations. When not
            specified a default limit of 25 is used.


            A maximum limit is applied to the results, so the server may respond
            with fewer results than requested; clients must not use this as a
            signal that this is the final page of results.
          in: query
          name: limit
          required: false
          schema:
            format: int32
            maximum: 200
            minimum: 1
            type: integer
        - description: >
            Opaque cursor for continuing after a previous page. Follow the URL
            marked `rel="next"`

            in the Link response header to obtain it; do not construct or parse
            the cursor.
          in: query
          name: after
          required: false
          schema:
            $ref: '#/components/schemas/Cursor'
        - description: >
            Include audit logs created at or after this RFC 3339 date-time. Use
            this to

            start an export; use `after` on subsequent pages. Cannot be combined
            with `after`.
          explode: true
          in: query
          name: since
          required: false
          schema:
            example: '2026-10-03T00:00:00Z'
            format: date-time
            type: string
          style: form
      responses:
        '200':
          content:
            application/json:
              schema:
                description: >-
                  Audit logs in export order. An empty array means there are no
                  matching audit logs on this page.
                items:
                  $ref: '#/components/schemas/AuditLog'
                type: array
          description: OK
          headers:
            link:
              $ref: '#/components/headers/Link'
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
          description: Error response
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
          description: Error response
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
          description: Error response
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
          description: Error response
components:
  schemas:
    Cursor:
      description: >
        Opaque cursor to be used for paging in a forward or backward direction.
        Cursors are stateless and so they never expire.
      maxLength: 10000
      minLength: 1
      type: string
    AuditLog:
      description: A team audit log.
      properties:
        eventId:
          description: Unique identifier for this event.
          format: uuid
          type: string
        timestamp:
          description: >-
            Time this audit log was created, formatted as an RFC 3339 date-time
            with a UTC offset.
          example: '2026-10-03T16:03:21Z'
          format: date-time
          type: string
        eventType:
          description: >
            The machine-readable audit event kind (for example,
            `DataSourceAdded`).

            New values may be added over time, so consumers should accept
            unknown values.
          type: string
        actor:
          allOf:
            - $ref: '#/components/schemas/AuditLogActor'
          description: >-
            The person, API key, data source, or system process that initiated
            this action.
        provider:
          description: >-
            Integration provider associated with the event, using the `Provider`
            name (for example, `GitHub`), when applicable.
          type: string
        dataSource:
          allOf:
            - $ref: '#/components/schemas/AuditLogDataSource'
          description: The associated data source, if this action concerns one.
        action:
          description: >-
            Human-readable action lines in display order. This wording may
            change; use `eventType` for programmatic classification.
          items:
            description: >-
              One human-readable line describing the action; lines appear in
              display order.
            example: Added GitHub as a data source
            type: string
          type: array
        userAgent:
          description: >-
            HTTP User-Agent header of the request that triggered the event, when
            available.
          type: string
        client:
          description: >-
            Unblocked client that triggered the event (for example,
            `Dashboard`), when available.
          type: string
      required:
        - action
        - actor
        - eventId
        - eventType
        - timestamp
      type: object
    PublicApiError:
      properties:
        status:
          description: The HTTP status code
          example: 400
          type: integer
      required:
        - status
      type: object
    AuditLogActor:
      description: Actor details captured when the audit event was recorded.
      properties:
        type:
          description: >
            Kind of actor that initiated the action. `Person` is a user,
            `ApiKey` is an API

            credential, `DataSource` is an integration, and `System` is an
            Unblocked process.
          enum:
            - Person
            - System
            - ApiKey
            - DataSource
          type: string
        name:
          description: >-
            Display name of the actor as captured when the event was recorded;
            it can differ from the actor's current name.
          type: string
        email:
          description: >-
            Email address recorded for the actor, when available; system and
            integration actors may not have one.
          format: email
          type: string
        provider:
          description: >-
            Integration provider associated with the actor, using the `Provider`
            name, when applicable.
          type: string
      required:
        - name
        - type
      type: object
    AuditLogDataSource:
      description: Data source associated with the event, when applicable.
      properties:
        name:
          description: >-
            Display name of the data source as captured when the event was
            recorded; it can differ from its current name.
          type: string
      required:
        - name
      type: object
  headers:
    Link:
      description: |
        A link header providing navigation links related to the response.
      example: <https://api.example.com/some/resource>; rel="next"
      schema:
        type: string
  securitySchemes:
    ApiKeyBearerAuth:
      bearerFormat: Unblocked API Key
      description: The API key to authenticate requests. Obtainable from the web dashboard.
      scheme: bearer
      type: http

````