curl --request GET \
--url https://api.openworklabs.com/v1/audit/operations \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/operations"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/operations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/operations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/operations"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/operations")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/operations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"operations": [
{
"id": "<string>",
"kind": "<string>",
"scope": "<string>",
"action": "<string>",
"initiatingActor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"origin": "api",
"originTrust": "authenticated",
"startedAt": "2023-11-07T05:31:56Z",
"outcome": "running",
"eventCount": 0,
"logicalBytes": 0,
"resources": [
{
"type": "<string>",
"id": "<string>",
"relationship": "target",
"label": "<string>"
}
]
}
],
"nextCursor": "<string>",
"snapshotSequence": 0
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}List retained audit operations
Organization administrator access to currently captured, retained audit history only; this is not coverage of every cloud action. Requires the latest literal metadata.capabilities.auditLogs=true and deployment visibility; feature disable returns 403 audit_feature_disabled without deleting history or changing capture preference. Legacy arbitrary payloads are preserved separately and are not backfilled or returned. One operation may contain multiple child events. Visibility is independent of capture entitlement. No duration, charge or continuous-drain guarantee is made. Default limit 50, maximum 100. Cursors are signed, organization/filter/mode scoped and expire 24 hours after the first page (not renewed). Repeat the same filters; limit may change. The snapshotSequence is the committed tenant publication watermark, not a timestamp or auto-increment allocation. Events above it are excluded, including later children of an existing operation. Missing retained anchors or changed removal counters return 410 audit_history_unavailable; start a new snapshot. These checks are not lossless-drain or retention protection guarantees. Time filters are inclusive operation-start bounds (ISO date or offset date-time; date-only means UTC midnight). actorId is the initiating user ID; outcome is the current OPERATION outcome, not an event outcome. action matches an exact stable action of any child event within the watermark. searchId is an exact case-sensitive ID match (1..255 characters, no controls), not free-text search: operation ID OR any canonical retained child event ID, child envelope requestId or child resource reference ID, scoped to this organization and operation within the watermark. Legacy payloads are not searched. All other filters are AND combined with searchId. Resource filters match stored references within the watermark, without live-resource joins; resourceType requires resourceId. Operation outcome/count/byte projections remain current rather than historical as-of-watermark values. Newest operations first, ordered by server first-recorded time then ID. Summary action and resources describe the FIRST event only (at most 256 stored references), not all affected resources. Expand events for complete evidence; X-Audit-Resource-Scope is first_event.
curl --request GET \
--url https://api.openworklabs.com/v1/audit/operations \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/audit/operations"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/audit/operations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/audit/operations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/audit/operations"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/audit/operations")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/audit/operations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"operations": [
{
"id": "<string>",
"kind": "<string>",
"scope": "<string>",
"action": "<string>",
"initiatingActor": {
"type": "user",
"id": "<string>",
"memberId": "<string>",
"credentialId": "<string>"
},
"origin": "api",
"originTrust": "authenticated",
"startedAt": "2023-11-07T05:31:56Z",
"outcome": "running",
"eventCount": 0,
"logicalBytes": 0,
"resources": [
{
"type": "<string>",
"id": "<string>",
"relationship": "target",
"label": "<string>"
}
]
}
],
"nextCursor": "<string>",
"snapshotSequence": 0
}{
"error": "audit_invalid_query"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"message": "<string>"
}{
"error": "organization_not_found"
}{
"error": "audit_cursor_expired"
}{
"error": "audit_unavailable"
}Authorizations
Session token passed as Authorization: Bearer <session-token> for user-authenticated Den routes.
Query Parameters
Maximum rows in this page.
1 <= x <= 100Opaque nextCursor from the prior page of the same query and mode.
4096Inclusive operation-start bound; date-only is UTC midnight. from must not exceed to.
Inclusive operation-start bound; date-only is UTC midnight. from must not exceed to.
Initiating user ID, not a delegated event actor or membership ID.
^usr_[0-7][0-9a-hjkmnp-tv-z]{25}$Exact stable action of any child event within the snapshot watermark.
1 - 128^[a-z][a-z0-9_.-]*$Current operation outcome; not an individual event outcome.
running, succeeded, failed, partial, unknown Stored operation origin.
api, cloud_ui, mcp, scheduler, webhook, platform_admin Exact case-sensitive operation, child event, child request or stored child resource reference ID within the snapshot watermark; OR across ID kinds, AND with other filters. Not free-text or legacy payload search.
1 - 255^[^\u0000-\u001f\u007f-\u009f]+$Exact case-sensitive stored reference ID from any child within the watermark.
1 - 255Optional stored reference type; requires resourceId.
1 - 64^[a-z][a-z0-9_.-]*$Was this page helpful?