curl --request GET \
--url https://api.portalhq.io/api/v3/custodians/me/audit-events \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.portalhq.io/api/v3/custodians/me/audit-events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.portalhq.io/api/v3/custodians/me/audit-events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.portalhq.io/api/v3/custodians/me/audit-events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.portalhq.io/api/v3/custodians/me/audit-events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.portalhq.io/api/v3/custodians/me/audit-events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.portalhq.io/api/v3/custodians/me/audit-events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"results": [
{
"id": "cm8k2x9a1000108l4h3b2c7de",
"userId": "cm1q7w3e5000208jx9k4l2mno",
"userEmail": "jane@example.com",
"actorRole": "OWNER",
"actorIsAdmin": false,
"event": "alert-webhook:create",
"resourceId": "cm8k2x8z0000008l4abcd1234",
"metadata": {
"environmentId": "cm0z9y8x7000108abfedc4321",
"resourceName": "https://example.com/alerts-webhooks/1/events"
},
"createdAt": "2026-03-11T14:02:31.000Z"
},
{
"id": "cm8k1v4b2000308l4q9r8s7tu",
"userId": "cm1q7w3e5000208jx9k4l2mno",
"userEmail": "jane@example.com",
"actorRole": "OWNER",
"actorIsAdmin": false,
"event": "member:invite",
"resourceId": "cm8k1v4a9000208l4zyxw9876",
"metadata": {},
"createdAt": "2026-03-11T13:47:05.000Z"
}
],
"metadata": {
"cursor": "eyJjcmVhdGVkQXQiOiIyMDI2LTAzLTExVDEzOjQ3OjA1LjAwMFoiLCJpZCI6ImNtOGsxdjRiMjAwMDMwOGw0cTlyOHM3dHUifQ",
"take": 2,
"hasMore": true
}
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}List audit events
Retrieve a cursor-paginated list of the actions your Portal Dashboard members took, newest first. This is the same feed shown in the Portal Dashboard’s audit log.
Results cover every environment in your organization, regardless of which environment the API key belongs to. Only actions taken in the Portal Dashboard are recorded; requests made through the Custodian API are not.
Metadata values stored under common secret key names (for example password,
token, or apiKey) are replaced with [REDACTED] when the event is recorded.
This endpoint has its own rate limit of 30 requests per minute per environment.
Responses are sent with Cache-Control: no-store.
curl --request GET \
--url https://api.portalhq.io/api/v3/custodians/me/audit-events \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.portalhq.io/api/v3/custodians/me/audit-events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.portalhq.io/api/v3/custodians/me/audit-events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.portalhq.io/api/v3/custodians/me/audit-events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.portalhq.io/api/v3/custodians/me/audit-events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.portalhq.io/api/v3/custodians/me/audit-events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.portalhq.io/api/v3/custodians/me/audit-events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"results": [
{
"id": "cm8k2x9a1000108l4h3b2c7de",
"userId": "cm1q7w3e5000208jx9k4l2mno",
"userEmail": "jane@example.com",
"actorRole": "OWNER",
"actorIsAdmin": false,
"event": "alert-webhook:create",
"resourceId": "cm8k2x8z0000008l4abcd1234",
"metadata": {
"environmentId": "cm0z9y8x7000108abfedc4321",
"resourceName": "https://example.com/alerts-webhooks/1/events"
},
"createdAt": "2026-03-11T14:02:31.000Z"
},
{
"id": "cm8k1v4b2000308l4q9r8s7tu",
"userId": "cm1q7w3e5000208jx9k4l2mno",
"userEmail": "jane@example.com",
"actorRole": "OWNER",
"actorIsAdmin": false,
"event": "member:invite",
"resourceId": "cm8k1v4a9000208l4zyxw9876",
"metadata": {},
"createdAt": "2026-03-11T13:47:05.000Z"
}
],
"metadata": {
"cursor": "eyJjcmVhdGVkQXQiOiIyMDI2LTAzLTExVDEzOjQ3OjA1LjAwMFoiLCJpZCI6ImNtOGsxdjRiMjAwMDMwOGw0cTlyOHM3dHUifQ",
"take": 2,
"hasMore": true
}
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Portal API Key (Custodian API Key). Pass as a Bearer token in the Authorization header.
Query Parameters
The number of audit events to retrieve. Min 1, max 100. Default 50.
1 <= x <= 100The metadata.cursor value from the previous response. Pass it back unchanged
to fetch the next page.
Comma-delimited list of Portal Dashboard user IDs to filter by.
Comma-delimited list of audit event types to filter by, for example
member:invite,client:create. Use
GET /custodians/me/audit-events/types for the full list of valid values.
Returns only audit events created at or after this Unix timestamp (in seconds).
Must be less than until when both are provided.
Returns only audit events created at or before this Unix timestamp (in seconds).
Was this page helpful?