App API
List audit events
The entries of the organisation's audit log, newest first, with filters and cursor pages — for a SIEM or an audit. The log never contains chat content and no successful sign-ins.
GEThttps://api.futureway.ai/v1/audit-events
Authentication
- Header
Authorization: Bearer $FUTUREWAY_API_KEY- Scope
- audit:readRead the organisation's audit log (GET /v1/audit-events) — for a SIEM or an audit. Service keys only.
- Key kinds
- service
- Format
- Futureway envelope
Details on keys and scopes under Authentication.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| from | string | no | Only entries from this time on (ISO 8601, inclusive). |
| to | string | no | Only entries up to this time (ISO 8601, inclusive). |
| actor_id | string | no | Only entries triggered by this person. |
| category | stringauth | security | sso | domain | scim | member | group | share | api_key | billing | automation | governance | learning | org | studio | connection | export | audit | no | Only entries of this area. |
| action | string | no | Only entries of this action, e.g. member.role_changed. |
| q | string | no | Free text over action names and the names of the people and groups involved. |
| cursor | string | no | The next_cursor value of the previous response — returns the next page. |
| limit | integer | no | Entries per page, 1 to 200 (default 50). |
Example request
curl https://api.futureway.ai/v1/audit-events \
-H "Authorization: Bearer $FUTUREWAY_API_KEY"Response
200
{
"data": [
{
"id": "5b1f7a62-3c52-4d5e-9a0f-0d3c7ac5d2f1",
"created_at": "2026-10-01T10:00:00.000Z",
"action": "member.role_changed",
"category": "member",
"actor": {
"type": "user",
"id": "db72417d-eaa4-4bef-95df-127c54d98753",
"name": "Erika Beispiel",
"email": "erika@example.org",
"key_id": null
},
"targets": [
{
"key": "target_user_id",
"kind": "user",
"id": "37a2e31e-da2e-4b45-ad2c-907b42ec7668",
"name": "Max Beispiel",
"email": "max@example.org"
}
],
"details": {
"target_user_id": "37a2e31e-da2e-4b45-ad2c-907b42ec7668",
"from": "member",
"to": "manager"
},
"origin": {
"ip_prefix": "203.0.113.0/24",
"user_agent_summary": "Chrome · Windows"
}
}
],
"next_cursor": "2026-10-01T10:00:00.000000Z|5b1f7a62-3c52-4d5e-9a0f-0d3c7ac5d2f1"
}Errors
| Status | Code | Description |
|---|---|---|
| 401 | unauthorized | No, invalid or revoked API key. |
| 401 | key_expired | The key has expired — create a new one. |
| 400 | invalid_body | The request body does not match the endpoint's schema. |
| 403 | scope_missing | The key does not carry the scope this endpoint requires. |
| 403 | browser_request_rejected | The request looks like a browser (Origin, fetch metadata or session cookie). |
| 429 | rate_limit_error | Too many requests in the window; retry-after names the wait. |
Formats and handling under Errors.