REST APIEnterpriseAudit log

GET

Lists audit logs for the authenticated user within an enterprise. Returns audit logs based on the user's role (auditor, admin, or member) with appropriate filtering. Results are paginated and sorted by timestamp in descending order.

Requires access token scopes: auditlogs_view_all or user_manage

Query Params

  • filter[enterpriseId] string required
    Enterprise ID to scope the query

    matches ^[0-9a-f]{32}$

  • filter[targetId] string
    Filter by target ID. Common values include walletId, userId, enterpriseId and organizationId.

    matches ^[0-9a-f]{32}$

  • filter[targetType] string enum
    Filter by target type. Common values include wallet, enterprise, user, and organization.
    userwalletenterpriseorganization
  • filter[type] array of string enums
    Filter by audit log type. Accepts a single value or a comma-separated list for multiple values.
    address.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress
  • filter[actorId] string
    Filter by actor ID

    matches ^[0-9a-f]{32}$

  • filter[actorType] string enum
    Filter by actor type.
    adminuserbitgo
  • filter[bucket] string enum
    Filter by audit log category
    enterpriseloginorganizationpolicysafetransactionunknownuserwallet
  • filter[correlationId] string
    Filter by correlation ID to correlate related audit events.
  • filter[createdAt][gte] string date-time
    Filter for audit logs on or after this date (ISO 8601 format)
  • filter[createdAt][lt] string date-time
    Filter for audit logs before this date (ISO 8601 format)
  • page[after] string
    Opaque pagination cursor returned in the previous page's links.next
  • page[size] integer
    Maximum number of results to return per page

    >= 1 · <= 500

    Defaults to 25

Responses

200
Successfully retrieved audit logs

Response Body

object

JSON:API response containing audit logs with pagination
  • data array of objects required
    List of audit log resource objects
    data object
    • type string enum required
      audit-logs
    • id string required

      matches ^[0-9a-f]{32}$

    • attributes object required
      Audit log entry for user-facing API
      attributes object
      • actor object required
        Actor information for audit logs
        actor object
        • id string required

          matches ^[0-9a-f]{32}$

        • username string required
          Username of the actor

          at least 5 characters

        • type string enum required
          Type of actor
          adminuserbitgo
      • ip string
        IP address of the actor

        2 to 39 characters

      • userAgent string
        User agent of the actor
      • sessionId string
        Session ID
      • requestId string required
        Request ID

        5 to 100 characters

      • targetId string required

        matches ^[0-9a-f]{32}$

      • targetType string enum required
        Type of entity that was the target of the action
        userwalletenterpriseorganization
      • timestamp string date-time required
        Timestamp of the action
      • auditLogType string enum required
        Audit log event type identifier in resource.action format
        address.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress
      • correlationId string
        Correlation ID linking related audit events
      • detail map
        Additional data associated with the audit log event
      • category string enum
        Category of the audit log entry
        policytransactionuserwalletsafeenterpriseloginorganizationunknown
      • coin string
        Cryptocurrency coin identifier
      • title string
        Human-readable title for this audit log event
      • description string
        Human-readable description providing additional context for the event
  • links object required
    JSON:API pagination links
    links object
    • self string required
      Link to the current page
    • next string
      Link to the next page (absent when no more pages)
400
Invalid request parameters

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
401
Unauthorized

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
403
Forbidden

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
404
Not found

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
500
Internal server error

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier