> ## Documentation Index
> Fetch the complete documentation index at: https://simplecloud.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List audit events

> Lists the network's audit events, newest first. Requires the audit_log:read permission, which covers every event in the network regardless of the caller's other permissions. API keys (network passwords) cannot read the audit log. To get the next page, pass next_cursor as cursor with the same filters.



## OpenAPI

````yaml https://controller.simplecloud.app/swagger/doc.json get /v0/audit-events
openapi: 3.1.0
info:
  contact:
    name: SimpleCloud support
    url: https://discord.simplecloud.app
  description: >-
    JWT sent in Authorization: Bearer <token>. Access depends on the token's
    network membership and permissions. The admin endpoint requires admin
    claims.
  title: SimpleCloud Controller API
  version: '1.0'
servers:
  - url: https://controller.simplecloud.app/
security: []
externalDocs:
  description: ''
  url: ''
paths:
  /v0/audit-events:
    get:
      tags:
        - audit
      summary: List audit events
      description: >-
        Lists the network's audit events, newest first. Requires the
        audit_log:read permission, which covers every event in the network
        regardless of the caller's other permissions. API keys (network
        passwords) cannot read the audit log. To get the next page, pass
        next_cursor as cursor with the same filters.
      operationId: list_audit_events
      parameters:
        - description: Network ID
          in: header
          name: X-Network-ID
          required: true
          schema:
            type: string
        - description: Earliest occurrence, inclusive (RFC 3339)
          in: query
          name: from
          schema:
            format: date-time
            type: string
        - description: Latest occurrence, exclusive (RFC 3339)
          in: query
          name: to
          schema:
            format: date-time
            type: string
        - description: Action, for example server_groups.update
          in: query
          name: action
          schema:
            type: string
        - description: Resource type, for example server_groups
          in: query
          name: resource_type
          schema:
            type: string
        - description: Resource ID
          in: query
          name: resource_id
          schema:
            type: string
        - description: User ID or API key ID
          in: query
          name: actor_id
          schema:
            type: string
        - description: Page size
          in: query
          name: limit
          schema:
            default: 50
            maximum: 200
            minimum: 1
            type: integer
        - description: next_cursor from the previous page
          in: query
          name: cursor
          schema:
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/models.ListAuditEventsResponse'
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/models.ErrorResponse'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/models.ErrorResponse'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/models.ErrorResponse'
          description: Forbidden
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/models.ErrorResponse'
          description: Internal Server Error
      security:
        - BearerAuth: []
        - NetworkCredential: []
components:
  schemas:
    models.ListAuditEventsResponse:
      description: A page of audit events, newest first
      properties:
        events:
          items:
            $ref: '#/components/schemas/models.AuditEvent'
          type: array
          uniqueItems: false
        next_cursor:
          description: |-
            NextCursor fetches the next page when passed as cursor with the same
            filters. It is null on the last page.
          example: >-
            MjAyNi0xMC0wOVQxMjozMDowMC4xMjM0NTZafDAxOTJhMWIyLWMzZDQtN2U1Zi04YTliLTBjMWQyZTNmNGE1Yg
          type: string
      type: object
    models.ErrorResponse:
      description: Generic error response
      properties:
        error:
          type: string
      type: object
    models.AuditEvent:
      description: One recorded action in a network's audit log
      properties:
        action:
          example: server_groups.update
          type: string
        actor:
          $ref: '#/components/schemas/models.AuditEventActor'
        changes:
          description: >-
            Changes maps each changed field to {"from": old, "to": new}, or to

            {"changed": true} for redacted fields. Over the size cap it is

            {"_truncated": true, "fields": [names]}, without fields when the
            names

            alone are too long. It is null when the action records no changes.
          type: object
        id:
          example: 0192a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b
          type: string
        occurred_at:
          example: '2026-10-09T12:30:00.123456Z'
          type: string
        request_id:
          description: >-
            RequestID correlates the event with request logs. Clients may set
            it.
          example: req_01J9Z3
          type: string
        resource:
          $ref: '#/components/schemas/models.AuditEventResource'
      type: object
    models.AuditEventActor:
      description: Who performed an audited action
      properties:
        id:
          description: ID is the user's ID or the API key's (network password's) ID.
          example: user_2abc
          type: string
        name:
          description: >-
            Name is a snapshot taken when the event was recorded: the user's
            email

            or the API key's name. It is null when unknown, such as for unnamed
            keys.
          example: alice@example.com
          type: string
        type:
          enum:
            - user
            - api_key
          example: user
          type: string
      type: object
    models.AuditEventResource:
      description: What an audited action affected
      properties:
        id:
          example: 123e4567-e89b-12d3-a456-426614174000
          type: string
        name:
          description: Name is a snapshot taken when the event was recorded, or null.
          example: lobby
          type: string
        type:
          example: server_groups
          type: string
      type: object
  securitySchemes:
    NetworkCredential:
      description: >-
        Network password or signed JWT. Password authentication also requires
        X-Network-ID and grants full access to that network, except the audit
        log. JWT permissions still apply.
      in: header
      name: X-Network-Credential
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.