Skip to main content
GET
Export audit events

Authorizations

klef.session
string
cookie
required

Cookie-based session. Obtain by completing the /auth/login/{provider} OAuth flow; the /auth/callback response sets the klef.session cookie that subsequent requests send automatically.

Query Parameters

action
enum<string>

The catalog of every audit verb: entity-change CRUD plus explicitly-recorded activities.

Available options:
entity_insert,
entity_update,
entity_delete,
workspace_onboarded,
member_invited,
member_role_changed,
member_removed,
invitation_revoked,
invitation_resent,
invitation_accepted,
workspace_accessed,
audit_retention_changed,
workspace_deletion_scheduled,
workspace_restored,
workspace_exported,
workspace_purged,
connection_created,
connection_updated,
connection_deleted,
connection_secret_revealed,
workspace_secret_created,
workspace_secret_updated,
workspace_secret_deleted,
workspace_secret_revealed,
inbox_item_resolved,
inbox_items_resolved_all,
api_key_created,
api_key_rotated,
api_key_revoked,
policy_created,
policy_updated,
policy_enabled,
policy_disabled,
policy_deleted,
subscription_checkout_started,
subscription_plan_changed,
subscription_cancellation_scheduled,
subscription_cancellation_cleared,
subscription_status_changed,
agent_credit_checkout_started,
agent_credits_purchased,
agent_credits_adjusted,
signed_in,
signed_out,
workers_exported,
audit_events_exported,
target_account_provisioned,
target_account_updated,
target_account_adopted,
target_account_detached,
target_account_grants_changed,
target_account_link_changed,
target_account_forgotten,
target_account_claims_changed,
target_account_elements_changed,
target_account_element_ended,
agent_turn_requested,
agent_turn_answered,
agent_turn_failed,
agent_tool_called,
agent_change_proposed,
agent_change_applied,
worker_record_viewed,
sync_plan_approved,
sync_plan_auto_approved,
scheduled_approval_changed,
password_set,
temporary_access_pass_issued,
first_sign_in_link_sent,
first_sign_in_link_opened,
recipient_code_requested,
recipient_proven,
recipient_refused,
first_sign_in_revealed,
password_reset_requested
q
string
Required string length: 3 - 100
from
string
to
string
actor
string<uuid>[]
eventType
enum<string>[]

What an audited activity acted upon. Entity-change records carry the CLR type name of the row that moved instead, and are never read back out of the audit log.

Available options:
workspace,
workspace_connection,
workspace_secret,
membership,
invitation,
api_key,
inbox_item,
policy,
billing,
session,
data_export,
target_account,
agent_turn,
worker,
sync_plan
timeZone
string

Response

OK