GET
List user audit logs
Lists audit logs for the authenticated user within an enterprise. Returns audit logs based on the user's role (auditor, admin, or member) with appropriate filtering. Results are paginated and sorted by timestamp in descending order.
Requires access token scopes: auditlogs_view_all or user_manage
Query Params
-
filter[enterpriseId]string requiredEnterprise ID to scope the query -
filter[targetId]stringFilter by target ID. Common values include walletId, userId, enterpriseId and organizationId. -
filter[targetType]string enumFilter by target type. Common values include wallet, enterprise, user, and organization.userwalletenterpriseorganization -
filter[type]array of string enumsFilter by audit log type. Accepts a single value or a comma-separated list for multiple values.address.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress -
filter[actorId]stringFilter by actor ID -
filter[actorType]string enumFilter by actor type.adminuserbitgo -
filter[bucket]string enumFilter by audit log categoryenterpriseloginorganizationpolicysafetransactionunknownuserwallet -
filter[correlationId]stringFilter by correlation ID to correlate related audit events. -
filter[createdAt][gte]string date-timeFilter for audit logs on or after this date (ISO 8601 format) -
filter[createdAt][lt]string date-timeFilter for audit logs before this date (ISO 8601 format) -
page[after]stringOpaque pagination cursor returned in the previous page'slinks.next -
page[size]integerMaximum number of results to return per page
Responses
200
Successfully retrieved audit logs
Response Body
object
JSON:API response containing audit logs with pagination
-
dataarray of objects requiredList of audit log resource objectsdata object
-
typestring enum requiredaudit-logs -
idstring required -
attributesobject requiredAudit log entry for user-facing APIattributes object
-
actorobject requiredActor information for audit logsactor object
-
idstring required -
usernamestring requiredUsername of the actor -
typestring enum requiredType of actoradminuserbitgo
-
-
ipstringIP address of the actor -
userAgentstringUser agent of the actor -
sessionIdstringSession ID -
requestIdstring requiredRequest ID -
targetIdstring required -
targetTypestring enum requiredType of entity that was the target of the actionuserwalletenterpriseorganization -
timestampstring date-time requiredTimestamp of the action -
auditLogTypestring enum requiredAudit log event type identifier inresource.actionformataddress.createaddress.makeEmptyTransactionaddressBook.addaddressBook.removeaddressBook.updateadmin.actionApproveadmin.actionRejectadmin.actionRequestadmin.addVideoIdadmin.addVideoIdUseradmin.removeVideoIdadmin.rotateAccessTokenadmin.withdrawCollateralapproval.approveapproval.freezeapproval.rejectapproval.skipapproval.unfreezeapproval.verifyLivenessCheckenterprise.acceptServicesAgreemententerprise.acknowledgePolicyenterprise.activateNetworkCliententerprise.addBankAccountenterprise.addUserenterprise.addUserRequestenterprise.addVideoIdUserenterprise.addWebhookenterprise.addWebhookSecretenterprise.adminUpdateBankAccountenterprise.archiveenterprise.autoWhitelistenterprise.createenterprise.createCredentialenterprise.createPlaidBankAccountenterprise.deleteBankAccountenterprise.deleteCredentialenterprise.deletePricingTypeenterprise.freezeenterprise.internalUpdateBankAccountenterprise.kycExemptionenterprise.removeUserenterprise.removeUserRequestenterprise.removeVideoIdUserenterprise.renameenterprise.trustToSingaporeUpgradeenterprise.unfreezeenterprise.updateenterprise.updateAllowedCoinsenterprise.updateApprovalsRequiredenterprise.updateBankAccountenterprise.updateBitgoOrgenterprise.updateCredentialenterprise.updateKycStatusenterprise.updatePlaidBankAccountenterprise.updateUserenterprise.updateUserPermissionenterprise.updateUserRequestenterprise.updateVideoIdUserenterprise.updateWhitelistenterprise.updateWhitelistRequestfixSession.logonfixSession.logoutgoAccount.activationSkippedgoAccount.creategoAccount.rebalanceRequestgoAccount.requestPasswordResetgoAccount.settlegoAccount.settlementRequestgoAccount.updatePasswordResetkey.createCustodiallinkAccount.initiateTransferlinkAccount.retryTransfermarginCollateral.cancelWithdrawalmarginCollateral.depositmarginCollateral.requestWithdrawalmarginPosition.closeRequestmarginPosition.covermarginPosition.transfermarginWithdrawal.completemobilePairing.approvemobilePairing.approveReauthFailedmobilePairing.claimmobilePairing.consumemobilePairing.createmobilePairing.rejectmobilePairing.revokeViaEmailoauthaccesstoken.updateorder.cancelorder.placeorder.updateorder.updateNotesorganization.addRoleorganization.addRoleRequestorganization.addWebhookorganization.addWebhookSecretorganization.approveAddRoleorganization.approveUpdateRoleorganization.approveUpdateRoleUsersorganization.approveUserInvitationorganization.deleteorganization.inviteUserorganization.inviteUserRequestorganization.regenerateInvitationorganization.rejectAddRoleorganization.rejectRemoveRoleorganization.rejectUpdateRoleorganization.rejectUpdateRoleUsersorganization.rejectUpdateUserRolesorganization.rejectUserInvitationorganization.rejectUserRemovalorganization.removeRoleorganization.removeRoleRequestorganization.removeUserorganization.removeUserRequestorganization.updateorganization.updateAdminUsersorganization.updateRoleorganization.updateRoleRequestorganization.updateRoleUsersorganization.updateRoleUsersRequestorganization.updateUserRequestorganization.updateUserRolesorganization.updateUserRolesRequestpolicy.addpolicy.addRequestpolicy.duplicatepolicy.duplicateRequestpolicy.lockpolicy.optInpolicy.optInRequestpolicy.optOutpolicy.optOutRequestpolicy.removepolicy.removeRequestpolicy.unlockpolicy.unlockRequestpolicy.updatepolicy.updateMutabilitypolicy.updateRequestpolicy.updateTagpolicyConfig.dataValidationExemptionDisabledpolicyConfig.dataValidationExemptionEnabledsafe.addMembersafe.addWebhooksafe.archivesafe.childKeyCreatesafe.finalizesafe.freezesafe.initializesafe.keycardDownloadsafe.passkeyRegistersafe.passkeyRemovesafe.passwordChangesafe.removeMembersafe.removeWebhooksafe.renamesafe.rootKeyCreatedsafe.rootKeyCreationDeniedsafe.shareAcceptsafe.shareCreatesafe.unfreezesafe.walletMintsecurityControl.approvalBlockedsecurityControl.changeAppliedsecurityControl.changeRejectedsecurityControl.changeRequestedtransaction.bitgoSignedtransaction.changeGasPricetransaction.createtransaction.createRequesttransaction.failedCreationtransaction.updateCommenttransaction.updateSendQtransaction.updateSendQItemtransaction.updateSendQTxtransaction.updateWalletSendQtransactionRequest.addUserSignatureSharetransactionRequest.createtransactionRequest.removeUserSignatureSharetransactionRequest.updateuser.acknowledgeDappConsentuser.activateuser.add2FAuser.addTrustedDeviceuser.addTrustedMachineuser.addWebhookuser.allowCoinsuser.completeReset2FAuser.createuser.createAccessTokenuser.deactivateuser.defiCreateAcknowledgementuser.deleteAccessTokenuser.deleteTrustedDeviceuser.deleteTrustedMachineuser.deleteWebhookuser.detectRefreshTokenReuseuser.failedLoginuser.freezeuser.getInternalAccessTokenuser.loginuser.oauthAuthorizeuser.oauthClientRequestAuthorizeduser.oauthClientRequestDenieduser.refreshTokenFingerprintMismatchuser.remove2FAuser.removeFromBitgouser.removeSourceIpuser.reset2FAuser.resetPassworduser.setPassworduser.startReset2FAuser.unblockEmailuser.unfreezeuser.updateuser.updateAccessTokenuser.updateKycStatususer.updatePassworduser.upsertRecoveryCodesuser.verifyReset2FAuser.verifySourceuser.viewRecoveryCodesverifyPairing.approveverifyPairing.approveReauthFailedverifyPairing.claimverifyPairing.consumeverifyPairing.createverifyPairing.rejectverifyPairing.revokeViaEmailvideoCall.createvideoId.joinQueuevideoId.leaveQueuewallet.acceptInvitewallet.activateSafeModewallet.addAddressLabelwallet.addFlagwallet.addLockAssetwallet.addNodewallet.addUserwallet.addUserRequestwallet.addWebhookwallet.attachPasskeywallet.autoWhitelistwallet.batchUpdateTransferStatewallet.bulkLockAssetwallet.cancelInvitewallet.cosignRecoveryTransactionwallet.confirmTransferwallet.createwallet.declineInvitewallet.deletewallet.deleteLockAssetwallet.deletePasswordResetwallet.deleteWebhookwallet.externalWithdrawalwallet.forwardTokenwallet.freezewallet.initializewallet.invitewallet.redeployAddresswallet.rejectUserRequestwallet.removeAddressLabelwallet.removeFlagwallet.removeUnspentswallet.removeUserwallet.removeUserRequestwallet.renamewallet.resetPasswordwallet.resetWebhookNotificationwallet.restorewallet.setNoncewallet.shareKeyswallet.stakewallet.unfreezewallet.updatewallet.updateApprovalsRequiredwallet.updateApprovalsRequiredRequestwallet.updateCircuitBreakerwallet.updateCustomTagswallet.updateEnterprisewallet.updateFlagwallet.updateLockAssetwallet.updatePasswordwallet.updatePasswordResetwallet.updateToMPCv2wallet.updateTransferStatewallet.updateUserPermissionwallet.updateWhitelistwallet.updateWhitelistRequestwallet.whitelistAddress -
correlationIdstringCorrelation ID linking related audit events -
detailmapAdditional data associated with the audit log event -
categorystring enumCategory of the audit log entrypolicytransactionuserwalletsafeenterpriseloginorganizationunknown -
coinstringCryptocurrency coin identifier -
titlestringHuman-readable title for this audit log event -
descriptionstringHuman-readable description providing additional context for the event
-
-
-
linksobject requiredJSON:API pagination linkslinks object
-
selfstring requiredLink to the current page -
nextstringLink to the next page (absent when no more pages)
-
400
Invalid request parameters
Response Body
object
JSON:API error Response
-
errorsarray of objects requirederrors object
-
codestring enum requiredMachine-readable error code from the BitGo error catalogBAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE -
statusstring requiredHTTP status code as a string -
titlestring requiredStable human-readable summary for this error code -
detailstringOccurrence-specific explanation of the error -
sourceobjectLocation of the problem in the requestsource object
-
parameterstringQuery parameter name -
pointerstringJSON Pointer into the request body -
headerstringRequest header name
-
-
metaobjectmeta object
-
requestIdstring requiredRequest Identifier
-
-
401
Unauthorized
Response Body
object
JSON:API error Response
-
errorsarray of objects requirederrors object
-
codestring enum requiredMachine-readable error code from the BitGo error catalogBAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE -
statusstring requiredHTTP status code as a string -
titlestring requiredStable human-readable summary for this error code -
detailstringOccurrence-specific explanation of the error -
sourceobjectLocation of the problem in the requestsource object
-
parameterstringQuery parameter name -
pointerstringJSON Pointer into the request body -
headerstringRequest header name
-
-
metaobjectmeta object
-
requestIdstring requiredRequest Identifier
-
-
403
Forbidden
Response Body
object
JSON:API error Response
-
errorsarray of objects requirederrors object
-
codestring enum requiredMachine-readable error code from the BitGo error catalogBAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE -
statusstring requiredHTTP status code as a string -
titlestring requiredStable human-readable summary for this error code -
detailstringOccurrence-specific explanation of the error -
sourceobjectLocation of the problem in the requestsource object
-
parameterstringQuery parameter name -
pointerstringJSON Pointer into the request body -
headerstringRequest header name
-
-
metaobjectmeta object
-
requestIdstring requiredRequest Identifier
-
-
404
Not found
Response Body
object
JSON:API error Response
-
errorsarray of objects requirederrors object
-
codestring enum requiredMachine-readable error code from the BitGo error catalogBAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE -
statusstring requiredHTTP status code as a string -
titlestring requiredStable human-readable summary for this error code -
detailstringOccurrence-specific explanation of the error -
sourceobjectLocation of the problem in the requestsource object
-
parameterstringQuery parameter name -
pointerstringJSON Pointer into the request body -
headerstringRequest header name
-
-
metaobjectmeta object
-
requestIdstring requiredRequest Identifier
-
-
500
Internal server error
Response Body
object
JSON:API error Response
-
errorsarray of objects requirederrors object
-
codestring enum requiredMachine-readable error code from the BitGo error catalogBAD_REQUESTVALIDATION_ERRORUNAUTHORIZEDFORBIDDENNOT_FOUNDCONFLICTRATE_LIMIT_EXCEEDEDINTERNAL_ERRORUPSTREAM_ERRORSERVICE_UNAVAILABLE -
statusstring requiredHTTP status code as a string -
titlestring requiredStable human-readable summary for this error code -
detailstringOccurrence-specific explanation of the error -
sourceobjectLocation of the problem in the requestsource object
-
parameterstringQuery parameter name -
pointerstringJSON Pointer into the request body -
headerstringRequest header name
-
-
metaobjectmeta object
-
requestIdstring requiredRequest Identifier
-
-