> ## Documentation Index
> Fetch the complete documentation index at: https://docs.devin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List Audit Logs

> List audit logs for the enterprise.

## Permissions

Requires a service user with the `ManageEnterpriseSettings` permission at the enterprise level.

## Time filters

This endpoint supports optional time filters using the `time_after` and `time_before` query parameters.

* Both `time_after` and `time_before` are **Unix timestamps in seconds**, interpreted as UTC.
* If you provide `time_before`, you must also provide `time_after`.
* The time range between `time_after` and `time_before` must be **100 days or less**.
* If no time filters are provided, the API returns audit logs for the full available history (subject to pagination).


## OpenAPI

````yaml /v3-openapi.yaml GET /v3/enterprise/audit-logs
openapi: 3.1.0
info:
  description: Devin v3 API with Service User authentication and RBAC
  title: Devin API v3
  version: 3.0.0
servers: []
security:
  - bearerAuth: []
paths:
  /v3/enterprise/audit-logs:
    get:
      tags:
        - audit_logs
      summary: List Audit Logs
      description: List audit logs for the enterprise.
      operationId: handle_get_enterprise_audit_logs_v3_enterprise_audit_logs_get
      parameters:
        - in: query
          name: order
          required: false
          schema:
            default: desc
            enum:
              - asc
              - desc
            title: Order
            type: string
        - in: query
          name: time_before
          required: false
          schema:
            anyOf:
              - type: integer
              - type: 'null'
            title: Time Before
        - in: query
          name: time_after
          required: false
          schema:
            anyOf:
              - type: integer
              - type: 'null'
            title: Time After
        - in: query
          name: after
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: After
        - in: query
          name: first
          required: false
          schema:
            default: 100
            maximum: 200
            minimum: 1
            title: First
            type: integer
        - in: query
          name: action
          required: false
          schema:
            anyOf:
              - $ref: '#/components/schemas/AuditLogAction'
              - type: 'null'
            title: Action
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedResponse_AuditLogResponse_'
          description: Successful Response
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
components:
  schemas:
    AuditLogAction:
      enum:
        - login
        - create_org
        - update_org
        - delete_org
        - revoke_all_enterprise_api_keys
        - add_enterprise_member
        - delete_member
        - add_member
        - assign_roles
        - update_role
        - create_role
        - delete_role
        - add_group_membership
        - update_group_membership
        - delete_group_membership
        - create_knowledge
        - edit_knowledge
        - delete_knowledge
        - create_folder
        - update_folder
        - delete_folder
        - create_session
        - sleep_session
        - terminate_session
        - send_message
        - create_service_api_key
        - revoke_enterprise_api_key
        - create_gitlab_integration
        - update_gitlab_integration
        - reconnect_gitlab_integration
        - delete_gitlab_integration
        - create_azure_devops_integration
        - reconnect_azure_devops_integration
        - delete_azure_devops_integration
        - remove_repo_from_devin
        - update_enterprise_hypervisor_settings
        - update_enterprise_settings
        - update_org_settings
        - ai_guardrail_violation
        - update_ai_guardrail
        - approve_deploy
        - approve_test_app
        - permission_response
        - search_query
        - create_org_api_key
        - create_user_api_key
        - view_org_api_key
        - view_user_api_key
        - create_secret
        - update_secret
        - delete_secret
        - create_playbook
        - update_playbook
        - delete_playbook
        - enable_persona
        - disable_persona
        - delete_persona
        - start_repo_setup
        - delete_repo_setup
        - finish_repo_setup
        - github_integration_deleted
        - create_github_integration
        - delete_github_integration
        - refresh_github_integration
        - create_bitbucket_integration
        - delete_bitbucket_integration
        - mcp_server_install
        - mcp_server_update
        - mcp_server_enable
        - mcp_server_disable
        - mcp_server_delete
        - mcp_server_secret_link
        - mcp_server_secret_unlink
        - mcp_server_oauth_initiate
        - mcp_server_oauth_tokens_granted
        - mcp_server_oauth_tokens_revoked
        - create_mcp_validation_session
        - create_service_user
        - delete_service_user
        - assign_service_user_role
        - remove_service_user_role
        - create_git_permission
        - delete_git_permission
        - update_git_permission
        - create_maintenance_task
        - update_maintenance_task
        - delete_maintenance_task
        - create_snapshot_script
        - schedule_snapshot_script
        - execute_snapshot_script
        - update_repo_setup_steering_knowledge
        - delete_repo_setup_steering_knowledge
        - set_org_group_limits
        - create_join_request
        - approve_join_request
        - automatic_join_event
        - reject_join_request
        - create_service_user_api_key
        - revoke_service_user_api_key
        - rotate_service_user_api_key
        - create_pat
        - revoke_pat
        - rotate_pat
        - create_blueprint
        - create_blueprint_version
        - rollback_blueprint_version
        - delete_blueprint
        - reorder_blueprints
        - create_enterprise_blueprint
        - create_enterprise_blueprint_version
        - rollback_enterprise_blueprint_version
        - delete_enterprise_blueprint
        - accept_skill_pr
        - trigger_blueprint_build
        - cancel_blueprint_build
        - upload_blueprint_file
        - delete_blueprint_file
        - pin_build
        - unpin_build
        - delete_build
        - trigger_automation
        - create_automation
        - update_automation
        - delete_automation
        - acknowledge_session_hard_cap
      title: AuditLogAction
      type: string
    PaginatedResponse_AuditLogResponse_:
      properties:
        end_cursor:
          anyOf:
            - type: string
            - type: 'null'
          description: Cursor to fetch the next page, or None if this is the last page.
          title: End Cursor
        has_next_page:
          default: false
          description: Whether there are more items available after this page.
          title: Has Next Page
          type: boolean
        items:
          items:
            $ref: '#/components/schemas/AuditLogResponse'
          title: Items
          type: array
        total:
          anyOf:
            - type: integer
            - type: 'null'
          description: Optional total count (can be omitted for performance).
          title: Total
      required:
        - items
      title: PaginatedResponse[AuditLogResponse]
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    AuditLogResponse:
      properties:
        action:
          $ref: '#/components/schemas/AuditLogAction'
        audit_log_id:
          title: Audit Log Id
          type: string
        created_at:
          title: Created At
          type: integer
        data:
          additionalProperties: true
          title: Data
          type: object
        org_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Org Id
        service_user_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Service User Id
        service_user_name:
          anyOf:
            - type: string
            - type: 'null'
          title: Service User Name
        user_email:
          anyOf:
            - type: string
            - type: 'null'
          title: User Email
        user_id:
          anyOf:
            - type: string
            - type: 'null'
          title: User Id
      required:
        - audit_log_id
        - action
        - created_at
        - org_id
        - user_id
        - user_email
        - service_user_id
        - service_user_name
        - data
      title: AuditLogResponse
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    bearerAuth:
      description: 'Service User credential (prefix: cog_)'
      scheme: bearer
      type: http

````