Posit Audit Logs API

The Audit Logs API from Posit — 3 operation(s) for audit logs.

Operations 3

GET /v1/audit/actions Get audit actions #
GET /v1/audit_logs Get audit logs #
GET /v1/search/auditlogs Search audit logs #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/posit-audit-logs-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

posit-audit-logs-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: support@posit.co
    name: Posit Connect Support
    url: https://support.posit.co/hc/en-us
  description: '## Overview


    The Posit Connect Server API can be used to perform certain

    user actions remotely.'
  license:
    name: Commercial. Copyright 2015-2026 Posit Software, PBC. All Rights Reserved.
    url: https://posit.co/about/eula/
  termsOfService: https://posit.co/about/eula/
  title: Posit Connect API Reference Audit Logs API
  version: 1.0.1
servers:
- url: /__api__
security:
- apiKey: []
tags:
- name: Audit Logs
paths:
  /v1/audit/actions:
    get:
      description: 'Retrieve the list of audit actions available on your Posit Connect server.

        You can also see a list of these actions in the Admin Guide.

        Action names can be used to filter audit logs in the Audit Log Search API.'
      operationId: getAuditActions
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/AuditActionResult'
                type: array
          description: Successful response.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: Get audit actions
      tags:
      - Audit Logs
  /v1/audit_logs:
    get:
      description: 'This endpoint returns a portion of the audit logs, as well as

        paging information that can be used to navigate the audit log

        results.


        This endpoint requires administrator access.


        This endpoint uses keyset pagination. The URLs in the `paging` field''s

        subfields can be used to fetch the `next`, `previous`, `first`, and

        `last` pages of results.'
      operationId: getAuditLogs
      parameters:
      - description: 'Number of logs to return. The minimum supported value is 1 and

          maximum supported value is 500. Note that `limit` is a "best

          effort" request since there may not be enough logs to satisfy the limit.'
        in: query
        name: limit
        schema:
          default: 20
          format: int64
          type: integer
      - description: Gets the previous page of audit logs relative to the given id.
        in: query
        name: previous
        schema:
          type: string
      - description: Gets the next page of audit logs relative to the given id.
        in: query
        name: next
        schema:
          type: string
      - description: Whether the audit logs should be listed in ascending order.
        in: query
        name: ascOrder
        schema:
          default: true
          type: boolean
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditLogs'
          description: Successful response.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation is invalid.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested object does not exist.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: Get audit logs
      tags:
      - Audit Logs
  /v1/search/auditlogs:
    get:
      description: 'This endpoint searches for audit logs, using a search query format

        that allows for both search terms and filters. The search terms are used

        to find audit logs that have matching terms in the audit action, audit

        description, etc, while the filters are used to filter the search

        results by specific fields (such as `user_guid` or the audit `time`).


        Authenticated access with an Administrator role is required.


        #### Search query


        The search query is a string that includes both search terms and

        filters. Any text in the search query that is not a supported filter

        is treated as a search term, and those search terms are matched

        against any of: `user_description`, `action`, or `event_description`. Note that the search

        terms are case-insensitive, and all terms must be present in an audit log entry

        for it to be included in the search results.


        #### Filters


        Filters are specified as colon-delimited key-value pairs, containing one

        or more values separated by commas. If any of the values within a filter

        contain a space or comma, you should use quotes around the value. Example:


        ```

        myterm tag:tagwithoutspace,"tag with space"

        ```


        You can negate a filter or search term by prefixing it

        with a `-`. For example, `-user_id:0` will exclude audit logs produced by system actors which

        have a default user_id of `0`.


        The following filters are supported:


        `action:[,,...]` - Only return audit logs

        that have the specified action. If more than one action is provided,

        audit logs with ANY of the specified actions will be included. Note that

        actions are not case sensitive. Audit actions are enumerated in the

        Admin Guide, and are also exposed in the

        GET /v1/audit/actions.


        `user_guid:[,,...]` - Only return

        audit logs that have the specified user GUID. If more than one user

        GUID is provided, audit logs with ANY of the specified user GUIDs will

        be included.


        `user_id:[,,...]` - Only return audit logs

        that have the specified user ID. If more than one user ID is provided,

        audit logs with ANY of the specified user IDs will be included. The user ID `0`

        is reserved for system actors.


        `from:` - Only return audit logs that have a timestamp

        greater than or equal to the specified timestamp. The timestamp must

        be provided in RFC3339 format, such as `2023-01-01T12:34:56Z`. Up to nanosecond

        precision is supported (e.g. `2023-01-01T12:34:56.123456789Z`). The timestamp

        is inclusive, so audit logs with the specified timestamp will be

        included in the results.


        `to:` - Only return audit logs that have a timestamp

        less than or equal to the specified timestamp. The timestamp must

        be provided in RFC3339 format, such as `2023-01-01T12:34:56Z`. Up to nanosecond

        precision is supported (e.g. `2023-01-01T12:34:56.123456789Z`). The timestamp

        is inclusive, so audit logs with the specified timestamp will be

        included in the results.


        #### Pagination


        This endpoint uses offset pagination. Requests can include

        query-string parameters for `page_number` and `page_size` to

        fetch different pages of results.'
      operationId: searchAuditLogs
      parameters:
      - description: Search audit log entries.
        in: query
        name: q
        schema:
          type: string
      - description: The page number to return.
        in: query
        name: page_number
        schema:
          default: 1
          format: int64
          type: integer
      - description: The number of items per page.
        in: query
        name: page_size
        schema:
          default: 20
          format: int64
          type: integer
      - description: 'The sort order: asc or desc.'
        in: query
        name: order
        schema:
          enum:
          - asc
          - desc
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditLogSearchResults'
          description: Successful response.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation is invalid.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: Search audit logs
      tags:
      - Audit Logs
components:
  schemas:
    AuditActionResult:
      additionalProperties: false
      description: An audit action available on your Posit Connect server.
      properties:
        action:
          description: The name of the action.
          example: create_user
          type: string
        description:
          description: A human-readable description of the action.
          example: Create a new user.
          type: string
      type: object
    AuditLog:
      additionalProperties: false
      description: An audit log entry.
      properties:
        id:
          description: The identifier of the audit action.
          type: string
        time:
          description: Timestamp in RFC3339 format when the action was taken.
          example: '2006-01-02T15:04:05-07:00'
          format: date-time
          type: string
        user_id:
          description: The user identifier of the actor who performed the audit action.
          type: string
        user_guid:
          description: The user GUID of the actor who performed the audit action.
          format: uuid
          type:
          - string
          - 'null'
        user_description:
          description: A description of the actor.
          example: Full name (username)
          type: string
        action:
          description: The audit action taken.
          example: add_user
          type: string
        event_description:
          description: A human-readable description of the action.
          example: Added user Full Name (username)
          type: string
      type: object
    AuditLogSearchResults:
      additionalProperties: false
      description: Audit log search results with total count.
      properties:
        total:
          description: The total number of matching audit log entries.
          example: 100
          type: integer
        results:
          description: The matching audit log entries for this page.
          items:
            $ref: '#/components/schemas/AuditLogEntry'
          type: array
      type: object
    AuditLogEntry:
      additionalProperties: false
      description: An audit log entry.
      properties:
        id:
          description: The unique identifier of the audit log entry.
          example: '123'
          type: string
        time:
          description: The timestamp (RFC3339) of the audit action.
          example: '2006-01-02T15:04:05-07:00'
          format: date-time
          type: string
        user_id:
          description: The unique identifier of the user who performed the action.
          example: '456'
          type: string
        user_guid:
          description: The GUID of the user who performed the action.
          example: d4aaf24e-b7d5-404f-843e-a78e4c1eab38
          format: uuid
          type:
          - string
          - 'null'
        user_description:
          description: A description of the user who performed the action.
          example: John Doe
          type: string
        action:
          description: The name of the audit action.
          example: create_user
          type: string
        event_description:
          description: A human-readable description of the event.
          example: Created a new user account.
          type: string
      type: object
    PagingCursors:
      additionalProperties: false
      description: Cursor values for keyset pagination.
      properties:
        previous:
          description: A cursor ID that can be used with the previous query parameter to get the previous page of results.
          example: '23948901087'
          type:
          - string
          - 'null'
        next:
          description: A cursor ID that can be used with the next query parameter to get the next page of results.
          example: '23948901087'
          type:
          - string
          - 'null'
      type: object
    AuditLogs:
      additionalProperties: false
      description: Audit log results with keyset pagination.
      properties:
        results:
          description: The audit logs
          items:
            $ref: '#/components/schemas/AuditLog'
          type: array
        paging:
          allOf:
          - $ref: '#/components/schemas/KeysetPaging'
          description: Paging object that can be used for navigation.
      type: object
    APIError:
      additionalProperties: false
      description: The error object returned by the API on failure.
      properties:
        code:
          description: The specific code for the type of error returned. See the [API error codes reference](#api-error-codes) for the full set of values.
          type: integer
        error:
          description: A description of the problem that was encountered.
          type: string
        payload:
          description: Additional error details, if any. The structure varies by error type.
          type:
          - object
          - 'null'
      required:
      - code
      - error
      type: object
    KeysetPaging:
      allOf:
      - $ref: '#/components/schemas/PagingLinks'
      - properties:
          cursors:
            allOf:
            - $ref: '#/components/schemas/PagingCursors'
            description: Cursor values for navigating between pages.
        type: object
      description: Keyset-based pagination metadata with cursors and navigation links.
    PagingLinks:
      description: Navigation links for keyset pagination.
      properties:
        first:
          description: A full URL of the first page of results. Null if the current response is the first page.
          type:
          - string
          - 'null'
        previous:
          description: A full URL of the previous page of results. Null if the current response is the first page.
          type:
          - string
          - 'null'
        next:
          description: A full URL of the next page of results. Null if the current response is the last page.
          type:
          - string
          - 'null'
        last:
          description: A full URL of the last page of results. Null if the current response is the last page.
          type:
          - string
          - 'null'
      type: object
  securitySchemes:
    apiKey:
      description: 'Prefix your API key with `Key `, e.g. `Key ABC123`.

        '
      in: header
      name: Authorization
      type: apiKey