Query identity audit-log events
/portal/v1/accounts/{accountSlug}/audit-log/identitiesIdentity surface — returns rows where an end-user identity is the actor OR the resource. Admin-on-identity rows appear here so customers can answer 'everything that ever happened to identity X' from a single endpoint. Same database row may also be returned by the admin surface.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
audit.viewSecurityView the account-wide audit log. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
Query Parameters
fromstring · date-time Optional Lower bound (inclusive). Defaults to `to - 30 days` when omitted.
tostring · date-time Optional Upper bound (inclusive). Defaults to `now()` when omitted.
actionstring[] Optional Filter by one or more action keys. Repeat the query param (`?action=a&action=b`) or pass a comma-separated string.
categoryenum Optional severityenum Optional outcomeenum Optional actor_idstring · uuid Optional actor_typestring Optional Free-form actor-type filter (e.g. `user`, `identity`).
resource_typestring Optional Free-form resource-type filter (e.g. `identity`, `role`, `node`).
resource_idstring · uuid Optional correlation_idstring · uuid Optional application_idstring · uuid Optional Narrow to rows for one Application within the Account. Omit to include all Applications.
environment_idstring · uuid Optional Narrow to rows for one Environment. Implies the Environment's parent Application. Omit to include all Environments.
qstring Optional Full-text query against actor_label, resource_label (trigram), and metadata (GIN).
cursorstring Optional Opaque base64url cursor returned by the previous response. Omit for the first page.
limitnumber Optional Page size. Defaults to 50; max 200.
Responses
application/json
items *AuditLogRowDto[]pagination *object
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
Pagination
This endpoint returns a paginated collection. Use the query parameters below to page through results.
pagenumberPage number (1-indexed). Defaults to 1.
takenumberItems per page (1–100). Defaults to 20.
Each response includes an items array alongside a pagination object with item_count, page_count, has_previous_page, and has_next_page fields.
Returned object
curl -X GET "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/audit-log/identities?from=value&to=value&action=value&category=auth&severity=info&outcome=success&actor_id=value&actor_type=value&resource_type=value&resource_id=value&correlation_id=value&application_id=value&environment_id=value&q=value&cursor=value&limit=0" \ -H "Authorization: Bearer $CANOPY_TOKEN"
{ "items": [ { "id": "string", "account_id": "string", "application_id": "string", "environment_id": "string", "actor_id": "string", "actor_type": "string", "action": "string", "resource_type": "string", "resource_id": "string", "metadata": {}, "created_at": "2026-04-20T12:00:00.000Z", "actor_label": "string", "resource_label": "string", "correlation_id": "00000000-0000-0000-0000-000000000000", "outcome": "success", "category": "auth", "severity": "info", "customer_visible": false, "identity_visible": false } ], "pagination": { "next_cursor": "string" } }
Tell us how we can improve this guide.