Kernel Audit Logs API
Read audit log records for the authenticated organization.
Read audit log records for the authenticated organization.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/kernel-audit-logs-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
openapi: 3.1.0
info:
title: Kernel API Keys Audit Logs API
description: Developer tools and cloud infrastructure for AI agents to use web browsers
version: 0.1.0
servers:
- url: https://api.onkernel.com
description: API Server
security:
- bearerAuth: []
tags:
- name: Audit Logs
description: Read audit log records for the authenticated organization.
paths:
/audit-logs:
get:
operationId: getAuditLogs
tags:
- Audit Logs
summary: List audit logs
description: API for searching audit logs. Limited to at most 30 day search, returns up to 100 records per page. Not recommended for bulk export.
security:
- bearerAuth: []
parameters:
- name: start
in: query
required: true
description: Lower bound (inclusive) for the audit record timestamp.
schema:
type: string
format: date-time
example: '2026-01-01T00:00:00Z'
- name: end
in: query
required: true
description: Upper bound (exclusive) for the audit record timestamp.
schema:
type: string
format: date-time
example: '2026-01-02T00:00:00Z'
- name: auth_strategy
in: query
required: false
description: Filter by authentication strategy.
schema:
type: string
- name: service
in: query
required: false
description: Filter by service name.
schema:
type: string
- name: method
in: query
required: false
description: Filter by HTTP method.
schema:
type: string
- name: exclude_method
in: query
required: false
description: Filter out results by HTTP method.
style: form
explode: false
schema:
type: array
maxItems: 10
items:
type: string
- name: search
in: query
required: false
description: Free-text search over path, user ID, email, client IP, and status.
schema:
type: string
- name: search_user_id
in: query
required: false
description: Additional user IDs to OR into free-text search.
style: form
explode: false
schema:
type: array
maxItems: 100
items:
type: string
- name: limit
in: query
required: false
description: Maximum number of results to return.
schema:
type: integer
minimum: 1
maximum: 100
default: 100
- name: page_token
in: query
required: false
description: Opaque page token from X-Next-Page-Token for the next page of older records.
schema:
type: string
responses:
'200':
description: A list of audit log records.
headers:
X-Limit:
description: The limit applied to the returned records.
schema:
type: integer
minimum: 1
maximum: 100
X-Next-Page-Token:
description: Page token for the next page of older records, omitted when no more results.
schema:
type: string
X-Has-More:
description: Whether there are more records available beyond this page.
schema:
type: boolean
default: false
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/AuditLogEntry'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'500':
$ref: '#/components/responses/InternalError'
x-codeSamples:
- lang: JavaScript
source: "import Kernel from '@onkernel/sdk';\n\nconst client = new Kernel({\n apiKey: process.env['KERNEL_API_KEY'], // This is the default and can be omitted\n});\n\n// Automatically fetches more pages as needed.\nfor await (const auditLogEntry of client.auditLogs.list({\n end: '2026-01-02T00:00:00Z',\n start: '2026-01-01T00:00:00Z',\n})) {\n console.log(auditLogEntry.user_id);\n}"
- lang: Python
source: "import os\nfrom datetime import datetime\nfrom kernel import Kernel\n\nclient = Kernel(\n api_key=os.environ.get(\"KERNEL_API_KEY\"), # This is the default and can be omitted\n)\npage = client.audit_logs.list(\n end=datetime.fromisoformat(\"2026-01-02T00:00:00\"),\n start=datetime.fromisoformat(\"2026-01-01T00:00:00\"),\n)\npage = page.items[0]\nprint(page.user_id)"
- lang: Go
source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"time\"\n\n\t\"github.com/kernel/kernel-go-sdk\"\n\t\"github.com/kernel/kernel-go-sdk/option\"\n)\n\nfunc main() {\n\tclient := kernel.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tpage, err := client.AuditLogs.List(context.TODO(), kernel.AuditLogListParams{\n\t\tEnd: time.Now(),\n\t\tStart: time.Now(),\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", page)\n}\n"
/audit-logs/export/chunk:
get:
operationId: getAuditLogsExportChunk
tags:
- Audit Logs
summary: Download an audit-log export chunk
description: Download an organization's audit log records for a time range as a file, for archival, compliance, or offline analysis. For interactive browsing, use GET /audit-logs.
security:
- bearerAuth: []
parameters:
- name: start
in: query
required: true
description: Lower bound (inclusive) for the audit record timestamp.
schema:
type: string
format: date-time
example: '2026-01-01T00:00:00Z'
- name: end
in: query
required: true
description: Upper bound (exclusive) for the audit record timestamp.
schema:
type: string
format: date-time
example: '2026-01-02T00:00:00Z'
- name: auth_strategy
in: query
required: false
description: Filter by authentication strategy.
schema:
type: string
- name: service
in: query
required: false
description: Filter by service name.
schema:
type: string
- name: method
in: query
required: false
description: Filter by HTTP method.
schema:
type: string
- name: exclude_method
in: query
required: false
description: Filter out results by HTTP method.
style: form
explode: false
schema:
type: array
maxItems: 10
items:
type: string
- name: search
in: query
required: false
description: Free-text search over path, user ID, email, client IP, and status.
schema:
type: string
- name: search_user_id
in: query
required: false
description: Additional user IDs to OR into free-text search.
style: form
explode: false
schema:
type: array
maxItems: 100
items:
type: string
- name: cursor
in: query
required: false
description: Opaque cursor from X-Next-Cursor for the next chunk of older records.
schema:
type: string
- name: limit
in: query
required: false
description: Maximum number of records to return in this chunk.
schema:
type: integer
minimum: 1
maximum: 50000
default: 50000
- name: format
in: query
required: false
description: Encoding for the returned chunk.
schema:
type: string
enum:
- jsonl
- jsonl.gz
default: jsonl.gz
responses:
'200':
description: One chunk of audit log records.
headers:
X-Has-More:
description: Whether more records remain beyond this chunk.
schema:
type: boolean
default: false
X-Next-Cursor:
description: Cursor for the next chunk of older records, empty when no more results.
schema:
type: string
X-Row-Count:
description: Number of records in this chunk.
schema:
type: integer
minimum: 0
maximum: 50000
X-Content-Sha256:
description: Hex SHA-256 of the response body.
schema:
type: string
pattern: ^[a-f0-9]{64}$
content:
application/octet-stream:
schema:
type: string
format: binary
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'500':
$ref: '#/components/responses/InternalError'
x-codeSamples:
- lang: JavaScript
source: "import Kernel from '@onkernel/sdk';\n\nconst client = new Kernel({\n apiKey: process.env['KERNEL_API_KEY'], // This is the default and can be omitted\n});\n\nconst response = await client.auditLogs.exportChunk({\n end: '2026-01-02T00:00:00Z',\n start: '2026-01-01T00:00:00Z',\n});\n\nconsole.log(response);\n\nconst content = await response.blob();\nconsole.log(content);"
- lang: Python
source: "import os\nfrom datetime import datetime\nfrom kernel import Kernel\n\nclient = Kernel(\n api_key=os.environ.get(\"KERNEL_API_KEY\"), # This is the default and can be omitted\n)\nresponse = client.audit_logs.export_chunk(\n end=datetime.fromisoformat(\"2026-01-02T00:00:00\"),\n start=datetime.fromisoformat(\"2026-01-01T00:00:00\"),\n)\nprint(response)\ncontent = response.read()\nprint(content)"
- lang: Go
source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"time\"\n\n\t\"github.com/kernel/kernel-go-sdk\"\n\t\"github.com/kernel/kernel-go-sdk/option\"\n)\n\nfunc main() {\n\tclient := kernel.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tresponse, err := client.AuditLogs.ExportChunk(context.TODO(), kernel.AuditLogExportChunkParams{\n\t\tEnd: time.Now(),\n\t\tStart: time.Now(),\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", response)\n}\n"
components:
responses:
InternalError:
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Unauthorized – missing or invalid authorization token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
BadRequest:
description: Bad Request – invalid input
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
schemas:
Error:
type: object
required:
- code
- message
properties:
code:
type: string
description: Application-specific error code (machine-readable)
example: bad_request
message:
type: string
description: Human-readable error description for debugging
example: 'Missing required field: app_name'
details:
type: array
description: Additional error details (for multiple errors)
items:
$ref: '#/components/schemas/ErrorDetail'
inner_error:
$ref: '#/components/schemas/ErrorDetail'
AuditLogEntry:
type: object
required:
- timestamp
- auth_strategy
- user_id
- email
- status
- method
- path
- route
- domain
- duration_ms
- client_ip
- user_agent
properties:
timestamp:
type: string
format: date-time
description: UTC time when the request was received.
auth_strategy:
type: string
description: Authentication strategy used for the request.
user_id:
type: string
description: ID of the authenticated user, if any.
email:
type: string
description: Email of the authenticated user at request time, if any.
status:
type: integer
description: HTTP response status code.
method:
type: string
description: HTTP method.
path:
type: string
description: Request path.
route:
type: string
description: Matched API route pattern, if available.
domain:
type: string
description: Request host.
duration_ms:
type: integer
description: Request duration in milliseconds.
client_ip:
type: string
description: Client IP address.
user_agent:
type: string
description: User agent header.
ErrorDetail:
type: object
properties:
code:
type: string
description: Lower-level error code providing more specific detail
example: invalid_input
message:
type: string
description: Further detail about the error
example: Provided version string is not semver compliant
securitySchemes:
bearerAuth:
type: http
scheme: bearer