Logto Audit logs API
Audit logs are used to track end-user activities in Logto sign-in experience and other flows. It does not include activities in Logto Console.
Audit logs are used to track end-user activities in Logto sign-in experience and other flows. It does not include activities in Logto Console.
openapi: 3.0.1
info:
title: Logto API references Account center Audit logs API
description: 'API references for Logto services.
Note: The documentation is for Logto Cloud. If you are using Logto OSS, please refer to the response of `/api/swagger.json` endpoint on your Logto instance.'
version: Cloud
servers:
- url: https://[tenant_id].logto.app/
description: Logto endpoint address.
security:
- OAuth2:
- all
tags:
- name: Audit logs
description: Audit logs are used to track end-user activities in Logto sign-in experience and other flows. It does not include activities in Logto Console.
paths:
/api/logs:
get:
operationId: ListLogs
tags:
- Audit logs
parameters:
- name: userId
in: query
required: false
schema:
type: string
description: Filter logs by user ID.
- name: applicationId
in: query
required: false
schema:
type: string
description: Filter logs by application ID.
- name: logKey
in: query
required: false
schema:
type: string
description: Filter logs by log key.
- name: page
in: query
description: Page number (starts from 1).
required: false
schema:
type: integer
minimum: 1
default: 1
- name: page_size
in: query
description: Entries per page.
required: false
schema:
type: integer
minimum: 1
default: 20
responses:
'200':
description: An array of logs that match the given query.
content:
application/json:
schema:
type: array
items:
type: object
required:
- tenantId
- id
- key
- payload
- createdAt
properties:
tenantId:
type: string
maxLength: 21
id:
type: string
minLength: 1
maxLength: 21
key:
type: string
minLength: 1
maxLength: 128
payload:
type: object
required:
- key
- result
properties:
key:
type: string
result:
type: string
enum:
- Success
- Error
error:
oneOf:
- type: object
additionalProperties:
example: {}
- type: string
ip:
type: string
userAgent:
type: string
userAgentParsed:
type: object
properties:
ua:
type: string
browser:
type: object
properties:
name:
type: string
version:
type: string
major:
type: string
type:
type: string
device:
type: object
properties:
model:
type: string
type:
type: string
vendor:
type: string
engine:
type: object
properties:
name:
type: string
version:
type: string
os:
type: object
properties:
name:
type: string
version:
type: string
cpu:
type: object
properties:
architecture:
type: string
userId:
type: string
applicationId:
type: string
sessionId:
type: string
params:
type: object
additionalProperties:
example: {}
createdAt:
type: number
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
summary: Get logs
description: Get logs that match the given query with pagination.
/api/logs/{id}:
get:
operationId: GetLog
tags:
- Audit logs
parameters:
- $ref: '#/components/parameters/logId-root'
responses:
'200':
description: Log details.
content:
application/json:
schema:
type: object
required:
- tenantId
- id
- key
- payload
- createdAt
properties:
tenantId:
type: string
maxLength: 21
id:
type: string
minLength: 1
maxLength: 21
key:
type: string
minLength: 1
maxLength: 128
payload:
type: object
required:
- key
- result
properties:
key:
type: string
result:
type: string
enum:
- Success
- Error
error:
oneOf:
- type: object
additionalProperties:
example: {}
- type: string
ip:
type: string
userAgent:
type: string
userAgentParsed:
type: object
properties:
ua:
type: string
browser:
type: object
properties:
name:
type: string
version:
type: string
major:
type: string
type:
type: string
device:
type: object
properties:
model:
type: string
type:
type: string
vendor:
type: string
engine:
type: object
properties:
name:
type: string
version:
type: string
os:
type: object
properties:
name:
type: string
version:
type: string
cpu:
type: object
properties:
architecture:
type: string
userId:
type: string
applicationId:
type: string
sessionId:
type: string
params:
type: object
additionalProperties:
example: {}
createdAt:
type: number
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
'404':
description: Log not found.
summary: Get log
description: Get log details by ID.
components:
parameters:
logId-root:
in: path
description: The unique identifier of the log.
required: true
schema:
type: string
name: id
securitySchemes:
OAuth2:
type: oauth2
description: "Logto Management API is a comprehensive set of REST APIs that gives you the full control over Logto to suit your product needs and tech stack. To see the full guide on Management API interactions, visit [Interact with Management API](https://docs.logto.io/docs/recipes/interact-with-management-api/).\n\n### Get started\n\nThe API follows the same authentication principles as other API resources in Logto, with some slight differences. To use Logto Management API:\n\n1. A machine-to-machine (M2M) application needs to be created.\n2. A machine-to-machine (M2M) role with Management API permission `all` needs to be assigned to the application.\n\nOnce you have them set up, you can use the `client_credentials` grant type to fetch an access token and use it to authenticate your requests to the Logto Management API.\n\n### Fetch an access token\n\nTo fetch an access token, you need to make a `POST` request to the `/oidc/token` endpoint of your Logto tenant.\n\nFor Logto Cloud users, the base URL is your Logto endpoint, i.e. `https://[tenant-id].logto.app`. The tenant ID can be found in the following places:\n\n- The first path segment of the URL when you are signed in to Logto Cloud. For example, if the URL is `https://cloud.logto.io/foo/get-started`, the tenant ID is `foo`.\n- In the \"Settings\" tab of Logto Cloud.\n\nThe request should follow the OAuth 2.0 [client credentials](https://datatracker.ietf.org/doc/html/rfc6749#section-4.4) grant type. Here is a non-normative example of how to fetch an access token:\n\n```bash\ncurl --location \\\n --request POST 'https://[tenant-id].logto.app/oidc/token' \\\n --header 'Content-Type: application/x-www-form-urlencoded' \\\n --data-urlencode 'grant_type=client_credentials' \\\n --data-urlencode 'client_id=[app-id]' \\\n --data-urlencode 'client_secret=[app-secret]' \\\n --data-urlencode 'resource=https://[tenant-id].logto.app/api' \\\n --data-urlencode 'scope=all'\n```\n\nReplace `[tenant-id]`, `[app-id]`, and `[app-secret]` with your Logto tenant ID, application ID, and application secret, respectively.\n\nThe response will be like:\n\n```json\n{\n \"access_token\": \"eyJhbG...2g\", // Use this value for accessing the Logto Management API\n \"expires_in\": 3600, // Token expiration in seconds\n \"token_type\": \"Bearer\", // Token type for your request when using the access token\n \"scope\": \"all\" // Scope `all` for Logto Management API\n}\n```\n\n### Use the access token\n\nOnce you have the access token, you can use it to authenticate your requests to the Logto Management API. The access token should be included in the `Authorization` header of your requests with the `Bearer` authentication scheme.\n\nHere is an example of how to list the first page of users in your Logto tenant:\n\n```bash\ncurl --location \\\n --request GET 'https://[tenant-id].logto.app/api/users' \\\n --header 'Authorization: Bearer eyJhbG...2g'\n```\n\nReplace `[tenant-id]` with your Logto tenant ID and `eyJhbG...2g` with the access token you fetched earlier."
flows:
clientCredentials:
tokenUrl: /oidc/token
scopes:
all: All scopes