REST APIEnterpriseAudit log

GET

Lists audit logs for the authenticated user within an enterprise or organization. Enterprise results are based on the user's role, while organization-scoped results require organization admin access. Results are paginated and sorted by timestamp in descending order. Provide exactly one of filter[enterpriseId] or filter[organizationId]; the parameters are mutually exclusive.

Requires access token scopes: auditlogs_view_all or user_manage

Query Params

  • filter[enterpriseId] string
    Enterprise ID to scope the query. Mutually exclusive with filter[organizationId].

    matches ^[0-9a-f]{32}$

  • filter[organizationId] string
    Organization ID to scope organization audit logs. Mutually exclusive with filter[enterpriseId]. Exactly one scope filter is required.

    matches ^[0-9a-f]{32}$

  • filter[targetId] string
    Filter by target ID. Common values include walletId, userId, enterpriseId and organizationId.

    matches ^[0-9a-f]{32}$

  • filter[targetType] string enum
    Filter by target type. Common values include wallet, enterprise, user, and organization.
    userwalletenterpriseorganization
  • filter[type] array of string enums
    Filter by audit log type. Accepts a single value or a comma-separated list for multiple values.
    address.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress
  • filter[actorId] string
    Filter by actor ID

    matches ^[0-9a-f]{32}$

  • filter[actorType] string enum
    Filter by actor type.
    adminuserbitgo
  • filter[bucket] string enum
    Filter by audit log category
    enterpriseloginorganizationpolicysafetransactionunknownuserwallet
  • filter[correlationId] string
    Filter by correlation ID to correlate related audit events.
  • filter[createdAt][gte] string date-time
    Filter for audit logs on or after this date (ISO 8601 format)
  • filter[createdAt][lt] string date-time
    Filter for audit logs before this date (ISO 8601 format)
  • page[after] string
    Opaque pagination cursor returned in the previous page's links.next
  • page[size] integer
    Maximum number of results to return per page

    >= 1 · <= 500

    Defaults to 25

Responses

200
Successfully retrieved audit logs

Response Body

object

JSON:API response containing audit logs with pagination
  • data array of objects required
    List of audit log resource objects
    data object
    • type string enum required
      audit-logs
    • id string required

      matches ^[0-9a-f]{32}$

    • attributes object required
      Audit log entry for user-facing API
      attributes object
      • actor object required
        Actor information for audit logs
        actor object
        • id string required

          matches ^[0-9a-f]{32}$

        • username string required
          Username of the actor

          at least 5 characters

        • type string enum required
          Type of actor
          adminuserbitgo
      • ip string
        IP address of the actor

        2 to 39 characters

      • userAgent string
        User agent of the actor
      • sessionId string
        Session ID
      • requestId string required
        Request ID

        5 to 100 characters

      • targetId string required

        matches ^[0-9a-f]{32}$

      • targetType string enum required
        Type of entity that was the target of the action
        userwalletenterpriseorganization
      • timestamp string date-time required
        Timestamp of the action
      • auditLogType string enum required
        Audit log event type identifier in resource.action format
        address.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress
      • correlationId string
        Correlation ID linking related audit events
      • detail map
        Additional data associated with the audit log event
      • category string enum
        Category of the audit log entry
        policytransactionuserwalletsafeenterpriseloginorganizationunknown
      • coin string
        Cryptocurrency coin identifier
      • title string
        Human-readable title for this audit log event
      • description string
        Human-readable description providing additional context for the event
  • links object required
    JSON:API pagination links
    links object
    • self string required
      Link to the current page
    • next string
      Link to the next page (absent when no more pages)
400
Invalid request parameters

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
401
Unauthorized

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
403
Forbidden

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
404
Not found

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier
500
Internal server error

Response Body

object

JSON:API error Response
  • errors array of objects required

    at least 1 items

    errors object
    • code string enum required
      Machine-readable error code from the BitGo error catalog
      BAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE
    • status string required
      HTTP status code as a string
    • title string required
      Stable human-readable summary for this error code
    • detail string
      Occurrence-specific explanation of the error
    • source object
      Location of the problem in the request
      source object
      • parameter string
        Query parameter name
      • pointer string
        JSON Pointer into the request body
      • header string
        Request header name
    • meta object
      meta object
      • requestId string required
        Request Identifier