> ## Documentation Index
> Fetch the complete documentation index at: https://cactal.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List audit log events

> Returns the organization’s immutable audit trail newest first as a paginated set, recording mutations performed by users and API keys across organizations, members, invitations, websites, and billing. Filter with the `eventType`, `resourceType`, `actorKind`, `actorPrincipalId`, and `websiteId` query parameters; `websiteId` narrows the trail to one website, including events recorded against its nested resources. Page size defaults to 20 (maximum 100). Requires a role with audit log access (owner or admin).



## OpenAPI

````yaml /api-reference/openapi.json get /organizations/{organizationId}/audit-log
openapi: 3.1.0
info:
  title: Cactal API
  version: 1.0.0
  description: >-
    The Cactal public API. Create, edit, publish, and operate websites
    programmatically. Authenticate every request with an API key sent as
    `Authorization: Bearer <key>`.
servers:
  - url: https://api.cactal.ai/v1
security:
  - apiKey: []
tags:
  - name: Documentation
    description: >-
      Search and read the Cactal product documentation for concepts, guides,
      agent workflows, platform behavior, and API operations.
  - name: Feedback
    description: >-
      Submit free-form product feedback from users and agents to the Cactal
      feedback inbox.
  - name: Websites
    description: >-
      Create and manage websites — the top-level resource that owns source code,
      content, assets, domains, and analytics.
  - name: Website editors
    description: >-
      Grant, list, and revoke website-scoped editor access, and invite
      collaborators to a single website by email.
  - name: API keys
    description: >-
      Create, scope, rotate, and revoke the API keys that authenticate
      programmatic and agent access.
  - name: Source code
    description: >-
      Read and edit the framework source files of a website draft. Mutations
      require an edit lease.
  - name: Publishing
    description: Validate, build, publish, and roll back website versions.
  - name: CMS collections
    description: >-
      Define the content model: collections of structured content owned by a
      website.
  - name: CMS fields
    description: Manage the typed fields that make up a collection schema.
  - name: CMS items
    description: >-
      Create, query, publish, and organize the content entries inside a
      collection.
  - name: Domains
    description: >-
      Manage platform subdomains and custom domains, including DNS verification
      and the primary domain.
  - name: Assets
    description: Upload and manage website files and images served from the Cactal CDN.
  - name: Media generation
    description: >-
      Generate reference-guided website images that are stored as ordinary
      Cactal CDN assets.
  - name: Project Context
    description: >-
      Upload private durable reference material that the website agent can
      search, read, and inspect.
  - name: Analytics
    description: >-
      Read first-party traffic analytics for a website and export datasets as
      CSV.
  - name: Organizations
    description: Manage organizations, members, and organization-wide invitations.
  - name: Audit log
    description: >-
      Read the immutable record of actions performed in an organization by users
      and API keys.
  - name: Billing
    description: >-
      Read billing state and manage plans, site capacity, and prepaid usage
      balance. Every billing operation requires the organization owner role,
      which API keys cannot hold — today these operations are performed from the
      dashboard, return 403 for API-key callers, and are hidden from MCP tool
      lists.
paths:
  /organizations/{organizationId}/audit-log:
    get:
      tags:
        - Audit log
      summary: List audit log events
      description: >-
        Returns the organization’s immutable audit trail newest first as a
        paginated set, recording mutations performed by users and API keys
        across organizations, members, invitations, websites, and billing.
        Filter with the `eventType`, `resourceType`, `actorKind`,
        `actorPrincipalId`, and `websiteId` query parameters; `websiteId`
        narrows the trail to one website, including events recorded against its
        nested resources. Page size defaults to 20 (maximum 100). Requires a
        role with audit log access (owner or admin).
      operationId: auditLog.list
      parameters:
        - name: organizationId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
        - name: eventType
          in: query
          required: false
          schema:
            type: string
            minLength: 1
        - name: resourceType
          in: query
          required: false
          schema:
            type: string
            minLength: 1
        - name: actorKind
          in: query
          required: false
          schema:
            type: string
            enum:
              - user
              - api_key
              - system
              - agent
        - name: actorPrincipalId
          in: query
          required: false
          schema:
            type: string
            minLength: 1
        - name: websiteId
          in: query
          required: false
          schema:
            description: >-
              Return only events about this website — either the website itself
              or a resource belonging to it.
            type: string
            minLength: 1
        - name: cursor
          in: query
          required: false
          schema:
            type: string
        - name: limit
          in: query
          required: false
          schema:
            default: 20
            type: integer
            minimum: 1
            maximum: 100
      responses:
        '200':
          description: One page of audit events, newest first.
          content:
            application/json:
              schema:
                type: object
                properties:
                  items:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          description: Unique event ID.
                        occurredAt:
                          description: When the action happened.
                          type: string
                          format: date-time
                        eventType:
                          type: string
                          description: >-
                            Stable event identifier, e.g.
                            `organizations.members.remove`. Also usable as the
                            `eventType` filter.
                        summary:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: Human-readable one-line summary of the action.
                        actorKind:
                          type: string
                          enum:
                            - user
                            - api_key
                            - system
                            - agent
                          description: What kind of principal performed the action.
                        actorPrincipalId:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: >-
                            Principal ID of the actor, when known. Usable as the
                            `actorPrincipalId` filter to follow one actor.
                        actorDisplay:
                          anyOf:
                            - type: object
                              properties:
                                label:
                                  type: string
                                  description: >-
                                    Display name of the actor: the user’s name
                                    or the API key’s name.
                                email:
                                  anyOf:
                                    - type: string
                                    - type: 'null'
                                  description: >-
                                    Email of user actors; `null` for API key
                                    actors.
                              required:
                                - label
                                - email
                              additionalProperties: false
                            - type: 'null'
                          description: >-
                            Resolved display info for the actor; `null` when the
                            actor cannot be resolved (for example a deleted
                            user, or `system` and `agent` actors).
                        resourceType:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: >-
                            Type of the affected resource, e.g.
                            `organization_member`.
                        resourceId:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: ID of the affected resource.
                        metadata:
                          anyOf:
                            - type: object
                              propertyNames:
                                type: string
                              additionalProperties: {}
                            - type: 'null'
                          description: Event-specific structured details.
                        durationMs:
                          type: integer
                          description: >-
                            How long the recorded operation took, in
                            milliseconds.
                      required:
                        - id
                        - occurredAt
                        - eventType
                        - summary
                        - actorKind
                        - actorPrincipalId
                        - actorDisplay
                        - resourceType
                        - resourceId
                        - metadata
                        - durationMs
                      additionalProperties: false
                  nextCursor:
                    anyOf:
                      - type: string
                      - type: 'null'
                    description: >-
                      Opaque cursor for the next page. Pass it as the `cursor`
                      parameter on the next request. `null` when this is the
                      last page.
                required:
                  - items
                  - nextCursor
                additionalProperties: false
        '400':
          description: >-
            Validation failed. The response `message` names the first invalid
            field.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceError'
        '401':
          description: Missing, invalid, expired, or revoked API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceError'
        '403':
          description: The authenticated principal lacks the required capability.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceError'
        '404':
          description: >-
            The resource does not exist or is outside the principal’s access
            scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceError'
        '429':
          description: >-
            Rate limit exceeded. Retry after the number of seconds in the
            `Retry-After` header.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceError'
components:
  schemas:
    ServiceError:
      type: object
      required:
        - kind
        - message
      description: >-
        Canonical error body returned by every non-2xx response. Extra fields
        carry error-specific details.
      properties:
        kind:
          type: string
          enum:
            - validation
            - unauthorized
            - forbidden
            - not_found
            - conflict
            - rate_limited
            - internal
          description: Stable, machine-readable error category.
        message:
          type: string
          description: Human-readable explanation of the failure.
        suggestion:
          type: string
          description: >-
            What to do next when the failure has a known fix; may name the exact
            operation to call.
        validValues:
          type: array
          items:
            type: string
          description: The acceptable values for the failing field, when the set is closed.
      additionalProperties: true
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        Cactal API key. Create one in the dashboard or via `POST /apiKeys`. The
        plaintext key is shown once at creation.

````