> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the workspace audit log

> Workspace-level (tenant-wide), NOT project-scoped - there is no /projects/{pid}/audit form. JSON reads are open to any role; the CSV export is owner/admin.



## OpenAPI

````yaml /openapi.json get /admin/api/audit
openapi: 3.1.0
info:
  title: Hookie API
  version: 1.0.0
  summary: Capture, route and deliver webhooks.
  description: >-
    Hookie exposes three HTTP surfaces.


    **Ingest + streaming** is the public plane. A path-form endpoint URL
    authenticates by its own high-entropy slug — there is no key, token or
    cookie — and an `ik_live_…` ingest key authenticates the `/v1/*` routes.
    Whenever the URL names a dataset the payload is stored whole into it;
    project mapping rules are evaluated on exactly one shape, `POST
    /v1/ingest/{ingest_key}` with no dataset segment.


    **The customer portal API** is a separate, token-authed surface for your end
    customers, scoped to one portal and one customer.


    **The admin API** drives the console. It accepts either a browser session or
    an OAuth bearer token from a connected coding agent — the same routes, the
    same validation, the same audit trail. An agent's authority is its user's
    workspace role narrowed to the scopes granted in the console.


    This document is generated from the request handlers and adversarially
    verified against them.
  contact:
    name: Hookie
    url: https://hookie.ai
  license:
    name: Proprietary
    url: https://hookie.ai/legal/terms
servers:
  - url: https://app.hookie.ai
    description: Production
  - url: https://app.preview.hookie.ai
    description: Preview
security: []
tags:
  - name: Ingest
    description: Send events to Hookie.
  - name: Streaming
    description: Tail events in real time over SSE or WebSocket.
  - name: Portal
    description: Token-authed surface for your end customers.
  - name: Projects
    description: Projects and their settings.
  - name: Routing
    description: Rules, endpoints, datasets and records.
  - name: Delivery
    description: Destinations, deliveries and replay.
  - name: Workflows
    description: Multi-step workflows, triggers and AI agents.
  - name: Observability
    description: Search, correlation, stats and the audit log.
  - name: Workspace
    description: Members, connected agents, SSO and billing.
paths:
  /admin/api/audit:
    get:
      tags:
        - Audit
      summary: Read the workspace audit log
      description: >-
        Workspace-level (tenant-wide), NOT project-scoped - there is no
        /projects/{pid}/audit form. JSON reads are open to any role; the CSV
        export is owner/admin.
      operationId: listAudit
      parameters:
        - name: actor
          in: query
          required: false
          description: Substring matched against actor_email OR actor_sub.
          schema:
            type: string
        - name: action
          in: query
          required: false
          description: Exact action name, e.g. create_webhook or reveal_destination_secret.
          schema:
            type: string
        - name: target
          in: query
          required: false
          description: Exact target id.
          schema:
            type: string
        - name: since
          in: query
          required: false
          description: ISO timestamp; matches at >= since.
          schema:
            type: string
        - name: until
          in: query
          required: false
          description: ISO timestamp; matches at <= until.
          schema:
            type: string
        - name: limit
          in: query
          required: false
          description: >-
            Page size; non-numeric or non-positive falls back to 25, values
            above 100 are clamped. Ignored when format=csv (that path takes a
            single 5000-row page).
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 25
        - name: offset
          in: query
          required: false
          description: Row offset; forced to 0 when format=csv.
          schema:
            type: integer
            minimum: 0
            default: 0
        - name: format
          in: query
          required: false
          description: >-
            Set to csv for a CSV attachment instead of JSON. Requires the manage
            capability (owner/admin) and is itself audited as export_audit.
          schema:
            type: string
            enum:
              - csv
      responses:
        '200':
          description: >-
            Newest first. JSON by default; with format=csv the body is a
            text/csv attachment (hookie-audit.csv) with the header
            at,actor_email,actor_sub,actor_agent,action,target,details.
          content:
            application/json:
              schema:
                type: object
                required:
                  - audit
                  - total
                  - limit
                  - offset
                properties:
                  audit:
                    type: array
                    items:
                      type: object
                      required:
                        - id
                        - at
                        - actor_sub
                        - actor_email
                        - actor_agent
                        - action
                        - target
                        - details
                      properties:
                        id:
                          type: string
                        at:
                          type: string
                          format: date-time
                        actor_sub:
                          type: string
                        actor_email:
                          type:
                            - string
                            - 'null'
                        actor_agent:
                          type:
                            - string
                            - 'null'
                          description: >-
                            OAuth client id when the actor was a connected
                            agent.
                        action:
                          type: string
                        target:
                          type:
                            - string
                            - 'null'
                        details:
                          type:
                            - string
                            - 'null'
                          description: JSON-encoded string.
                  total:
                    type: integer
                    description: Rows matching the same filters, for the pager.
                  limit:
                    type: integer
                  offset:
                    type: integer
            text/csv:
              schema:
                type: string
        '401':
          description: >-
            Not signed in, or the agent bearer token is invalid, unknown or
            revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            Insufficient role - only returned for format=csv, which requires the
            manage capability (owner or admin).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable reason.
        retry_after:
          type: integer
          description: Seconds to wait. Present on 429.
        upgrade_url:
          type: string
          format: uri
          description: Present only on a monthly-quota 429.
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: hookie_session
      description: >-
        The console's sealed session cookie, set by WorkOS AuthKit. Mutating
        requests also require the `X-Requested-With` CSRF header.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        An OAuth 2.1 access token from a connected agent, audienced at the
        `/mcp` resource URI. The agent acts as its user, with that user's role
        narrowed to the granted `hookie:*` scopes. No CSRF header is required —
        a bearer token is not ambient credentials.

````