GET /api/v1/organizations/{id}/audit-events

Returns the organization activity feed (actions taken across the org's projects), newest first. Keyset/cursor paginated.

Path parameters

  • id string Required

    Organization whose audit feed to read

Query parameters

  • project_id string

    Filter by project

  • limit integer

    Max events per page (default 50, max 200)

  • cursor string

    Opaque keyset cursor for the next page

  • action string

    Filter by action (e.g. agent.deploy)

  • category string

    Filter by category: access or mutation

  • actor_email string

    Filter by actor email

  • outcome string

    Filter by outcome: success or failure

  • start_time string

    Start of time range (RFC3339)

  • end_time string

    End of time range (RFC3339)

  • show_admin_events boolean

    Include admin events (operator actions and GSA runtime events); default false hides them

Responses

  • Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence.

    Hide response attributes Show response attributes object
    • badRequestDetail object

      Optional validation details defined by the standard error schema; API negotiation errors do not emit this field.

      Hide badRequestDetail attribute Show badRequestDetail attribute object
      • fields array[object]

        Fields with validation failures.

        Hide fields attributes Show fields attributes object

        A field and its validation failure.

        • description string Required

          Human-readable validation failure.

        • field string Required

          Name or path of the invalid request field.

    • detail string Required

      Human-readable error details.

    • error integer Required

      HTTP status code.

    • errorCode string Required

      Machine-readable error code.

    • parameters array[string]

      Request parameter names associated with the error; omitted when none apply.

    • reason string Required

      HTTP status reason phrase.

    Hide response attributes Show response attributes object
    • badRequestDetail object

      Optional validation details defined by the standard error schema; API negotiation errors do not emit this field.

      Hide badRequestDetail attribute Show badRequestDetail attribute object
      • fields array[object]

        Fields with validation failures.

        Hide fields attributes Show fields attributes object

        A field and its validation failure.

        • description string Required

          Human-readable validation failure.

        • field string Required

          Name or path of the invalid request field.

    • detail string Required

      Human-readable error details.

    • error integer Required

      HTTP status code.

    • errorCode string Required

      Machine-readable error code.

    • parameters array[string]

      Request parameter names associated with the error; omitted when none apply.

    • reason string Required

      HTTP status reason phrase.

  • 200

    OK

    Hide response attributes Show response attributes object
    • audit_events array[object]
      Hide audit_events attributes Show audit_events attributes object
      • action string

        Values are agent.deploy, agent.rollback, agent.promote, secret.set, secret.delete, workspace_logs.view, data_viewer_access.grant, data_viewer_access.revoke, support_access.grant, support_access.revoke, service_account.create, service_account.rotate_secret, service_account.revoke, service_account.reactivate, service_account.replace_roles, service_account.token_mint, service_account.token_use, service_account.authz_denied, service_account.ip_access_list.update, oe_profile.capture, oe_profile.download, workspace.delete, project.delete, workspace.deletion_delivered, workspace.restoration_delivered, app_secrets.reclaim, project_secrets.reclaim, api_key_secrets.reclaim, ecr_repository.delete, namespace.delete, atlas_service_account.retire, workspace_records.purge, project_records.purge, project.reclaim, project_platform_target.select, project_staged_rollout.start, project_staged_rollout.resume, app_platform_update.accept, project_operation.force_cancel, project_operation.request_cancel, app_operation.request_cancel, project_operation.resume, runtime_config.set, runtime_config.clear, trace.view, application_secret.migrate, egress_allow_all.migrate, egress.save, guardrail.create, guardrail.update, guardrail.delete, policy.create, policy.update, policy.delete, credential_provider.create, credential_provider.update, or credential_provider.delete.

      • actor object
        Hide actor attributes Show actor attributes object
        • client_id string

          ClientID is the global service account client id when Type is ActorTypeServiceAccount.

        • email string
        • roles array[string]

          Roles are the actor's role(s) recorded at action time, if any. Optional.

        • type string

          Type discriminates the actor kind. Empty or ActorTypeUser means a human identified by UserID/Email. ActorTypeServiceAccount means a GSA identified by ClientID (UserID/Email may be empty).

        • user_id string
      • category string

        Values are access or mutation.

      • failure_reason string
      • id string
      • metadata object

        Additional properties are allowed.

      • outcome string

        Values are success or failure.

      • scope object
        Hide scope attributes Show scope attributes object
        • org_id string
        • project_id string
        • workspace_id string
      • source_ip string
      • target object
        Hide target attributes Show target attributes object
        • id string
        • name string
        • type string

          Type is the resource kind (e.g. "workspace_logs", "deployment", "secret").

      • timestamp string
    • has_more boolean
    • next_cursor string
    Hide response attributes Show response attributes object
    • audit_events array[object]
      Hide audit_events attributes Show audit_events attributes object
      • action string

        Values are agent.deploy, agent.rollback, agent.promote, secret.set, secret.delete, workspace_logs.view, data_viewer_access.grant, data_viewer_access.revoke, support_access.grant, support_access.revoke, service_account.create, service_account.rotate_secret, service_account.revoke, service_account.reactivate, service_account.replace_roles, service_account.token_mint, service_account.token_use, service_account.authz_denied, service_account.ip_access_list.update, oe_profile.capture, oe_profile.download, workspace.delete, project.delete, workspace.deletion_delivered, workspace.restoration_delivered, app_secrets.reclaim, project_secrets.reclaim, api_key_secrets.reclaim, ecr_repository.delete, namespace.delete, atlas_service_account.retire, workspace_records.purge, project_records.purge, project.reclaim, project_platform_target.select, project_staged_rollout.start, project_staged_rollout.resume, app_platform_update.accept, project_operation.force_cancel, project_operation.request_cancel, app_operation.request_cancel, project_operation.resume, runtime_config.set, runtime_config.clear, trace.view, application_secret.migrate, egress_allow_all.migrate, egress.save, guardrail.create, guardrail.update, guardrail.delete, policy.create, policy.update, policy.delete, credential_provider.create, credential_provider.update, or credential_provider.delete.

      • actor object
        Hide actor attributes Show actor attributes object
        • client_id string

          ClientID is the global service account client id when Type is ActorTypeServiceAccount.

        • email string
        • roles array[string]

          Roles are the actor's role(s) recorded at action time, if any. Optional.

        • type string

          Type discriminates the actor kind. Empty or ActorTypeUser means a human identified by UserID/Email. ActorTypeServiceAccount means a GSA identified by ClientID (UserID/Email may be empty).

        • user_id string
      • category string

        Values are access or mutation.

      • failure_reason string
      • id string
      • metadata object

        Additional properties are allowed.

      • outcome string

        Values are success or failure.

      • scope object
        Hide scope attributes Show scope attributes object
        • org_id string
        • project_id string
        • workspace_id string
      • source_ip string
      • target object
        Hide target attributes Show target attributes object
        • id string
        • name string
        • type string

          Type is the resource kind (e.g. "workspace_logs", "deployment", "secret").

      • timestamp string
    • has_more boolean
    • next_cursor string
  • Bad Request

    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
  • Unauthorized

    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
  • Forbidden

    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
  • Internal Server Error

    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
    Hide response attributes Show response attributes object
    • code string
    • error string
    • success boolean
GET /api/v1/organizations/{id}/audit-events
curl \
 --request GET 'https://agentengine.mongodb.com/api/v1/organizations/{id}/audit-events' \
 --header "Authorization: $API_KEY"
Response examples (406)
{
  "detail": "This operation is not available in API version 2026-09-20-preview.",
  "error": 406,
  "errorCode": "OPERATION_NOT_IN_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
{
  "detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
  "error": 406,
  "errorCode": "UNACCEPTABLE_MEDIA_TYPE",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
{
  "detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
  "error": 406,
  "errorCode": "UNSUPPORTED_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
Response examples (406)
{
  "detail": "This operation is not available in API version 2026-09-20-preview.",
  "error": 406,
  "errorCode": "OPERATION_NOT_IN_API_VERSION",
  "parameters": [
    "Accept"
  ],
  "reason": "Not Acceptable"
}
Response examples (200)
{
  "audit_events": [
    {
      "action": "agent.deploy",
      "actor": {
        "client_id": "string",
        "email": "string",
        "roles": [
          "string"
        ],
        "type": "string",
        "user_id": "string"
      },
      "category": "access",
      "failure_reason": "string",
      "id": "string",
      "metadata": {},
      "outcome": "success",
      "scope": {
        "org_id": "string",
        "project_id": "string",
        "workspace_id": "string"
      },
      "source_ip": "string",
      "target": {
        "id": "string",
        "name": "string",
        "type": "string"
      },
      "timestamp": "string"
    }
  ],
  "has_more": true,
  "next_cursor": "string"
}
Response examples (200)
{
  "audit_events": [
    {
      "action": "agent.deploy",
      "actor": {
        "client_id": "string",
        "email": "string",
        "roles": [
          "string"
        ],
        "type": "string",
        "user_id": "string"
      },
      "category": "access",
      "failure_reason": "string",
      "id": "string",
      "metadata": {},
      "outcome": "success",
      "scope": {
        "org_id": "string",
        "project_id": "string",
        "workspace_id": "string"
      },
      "source_ip": "string",
      "target": {
        "id": "string",
        "name": "string",
        "type": "string"
      },
      "timestamp": "string"
    }
  ],
  "has_more": true,
  "next_cursor": "string"
}
Response examples (400)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (400)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (401)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (401)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (403)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (403)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (500)
{
  "code": "string",
  "error": "string",
  "success": true
}
Response examples (500)
{
  "code": "string",
  "error": "string",
  "success": true
}