Skip to content
Holst
English
Esc
navigateopen⌘Jpreview
On this page

Exporting audit events

The GET /v1/organizations/{organizationId}/audit_events method returns audit events for the selected organization.

Before you begin

You need:

  1. A personal access token with the organization:audit_events_read scope.
  2. The organization ID. In Holst, it appears in the organization page URL after /org/: /org/{organizationId}/....
  3. The user who created the token must be an administrator of the selected organization.

Send a request

Send the request with the token in the Authorization header:

curl \
  "https://api.holst.so/v1/organizations/{organizationId}/audit_events" \
  -H "Authorization: Bearer holst_pat_..."

This request returns up to 100 of the most recent events, newest first.

Request parameters

  • actionTypes — action types used to filter events. Separate multiple values with commas. See Action types for possible values.
  • startTime and endTime — the start and end of the time range, formatted as RFC 3339 timestamps.
  • order — event order. asc starts with the oldest events; desc starts with the newest and is the default.
  • pageSize — number of events per page, from 1 to 1000. The default is 100.

For example, this request retrieves workspace creation events from August 2026:

curl --get \
  "https://api.holst.so/v1/organizations/{organizationId}/audit_events" \
  -H "Authorization: Bearer holst_pat_..." \
  --data-urlencode "actionTypes=workspace_create" \
  --data-urlencode "startTime=2026-08-01T00:00:00Z" \
  --data-urlencode "endTime=2026-09-01T00:00:00Z" \
  --data-urlencode "order=asc" \
  --data-urlencode "pageSize=1000"

API response

The response contains:

  • auditEvents — an array of audit events in the order specified by order.
  • nextCursor — cursor for the next page. This field is omitted when there are no more events.

See Event structure for the fields in each event.

Retrieve the next page

If the response includes nextCursor, pass its value in the cursor parameter:

curl --get \
  "https://api.holst.so/v1/organizations/{organizationId}/audit_events" \
  -H "Authorization: Bearer holst_pat_..." \
  --data-urlencode "actionTypes=workspace_create" \
  --data-urlencode "startTime=2026-08-01T00:00:00Z" \
  --data-urlencode "endTime=2026-09-01T00:00:00Z" \
  --data-urlencode "order=asc" \
  --data-urlencode "pageSize=1000" \
  --data-urlencode "cursor=NEXT_CURSOR"

If the first request used filters or sorting, include them unchanged on every page. Repeat the request until nextCursor is omitted from the response.

API reference

See Get audit events for parameters, response fields, and possible errors.