> ## Documentation Index
> Fetch the complete documentation index at: https://docs.portalhq.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List audit events

> Retrieve a cursor-paginated list of the actions your Portal Dashboard members
took, newest first. This is the same feed shown in the Portal Dashboard's audit log.

Results cover every environment in your organization, regardless of which
environment the API key belongs to. Only actions taken in the Portal Dashboard
are recorded; requests made through the Custodian API are not.

Metadata values stored under common secret key names (for example `password`,
`token`, or `apiKey`) are replaced with `[REDACTED]` when the event is recorded.

This endpoint has its own rate limit of 30 requests per minute per environment.
Responses are sent with `Cache-Control: no-store`.




## OpenAPI

````yaml /openapi/custodian-api.yaml get /custodians/me/audit-events
openapi: 3.1.0
info:
  title: Portal Custodian API
  version: '3.0'
  description: >
    The Portal Custodian API provides endpoints for managing clients, building
    transactions,

    retrieving wallet data, managing delegations, alert webhooks and gas
    sponsorship, and

    reading the Portal Dashboard audit log.

    All endpoints require authentication via a Portal API Key (also known as a
    Custodian API Key)

    passed as a Bearer token.


    ## Base URL

    `https://api.portalhq.io/api/v3`


    ## Authentication

    Include your Portal API Key as a Bearer token in the `Authorization` header
    of every request.


    ## Chain ID Format

    Chain parameters use either friendly names (e.g. `ethereum`, `solana`) or
    CAIP-2 format

    (e.g. `eip155:1`, `solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`). When using
    CAIP-2 format

    in URLs, ensure the colon is URI-encoded (`%3A`).
servers:
  - url: https://api.portalhq.io/api/v3
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Clients
    description: Create and manage Portal clients
  - name: Transactions
    description: Build and evaluate blockchain transactions
  - name: Wallet Metadata
    description: Retrieve wallet balances and NFTs
  - name: Wallet Shares
    description: Manage backup shares and wallet ejection
  - name: Delegations
    description: Manage token delegations and delegated transfers
  - name: Session Keys
    description: Build and send EIP-7702 session key user operations
  - name: Alert Webhooks
    description: Manage alert webhooks, external addresses, and replay failed events
  - name: Gas Sponsorship
    description: View and manage gas sponsorship across chains
  - name: Due
    description: Manage Due webhook endpoints and deliveries
  - name: Audit Events
    description: Read the audit log of actions taken in the Portal Dashboard
paths:
  /custodians/me/audit-events:
    get:
      tags:
        - Audit Events
      summary: List audit events
      description: >
        Retrieve a cursor-paginated list of the actions your Portal Dashboard
        members

        took, newest first. This is the same feed shown in the Portal
        Dashboard's audit log.


        Results cover every environment in your organization, regardless of
        which

        environment the API key belongs to. Only actions taken in the Portal
        Dashboard

        are recorded; requests made through the Custodian API are not.


        Metadata values stored under common secret key names (for example
        `password`,

        `token`, or `apiKey`) are replaced with `[REDACTED]` when the event is
        recorded.


        This endpoint has its own rate limit of 30 requests per minute per
        environment.

        Responses are sent with `Cache-Control: no-store`.
      operationId: listAuditEvents
      parameters:
        - name: take
          in: query
          required: false
          description: >-
            The number of audit events to retrieve. Min `1`, max `100`. Default
            `50`.
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 50
        - name: cursor
          in: query
          required: false
          description: >
            The `metadata.cursor` value from the previous response. Pass it back
            unchanged

            to fetch the next page.
          schema:
            type: string
        - name: userIds
          in: query
          required: false
          description: Comma-delimited list of Portal Dashboard user IDs to filter by.
          schema:
            type: string
        - name: eventTypes
          in: query
          required: false
          description: >
            Comma-delimited list of audit event types to filter by, for example

            `member:invite,client:create`. Use

            `GET /custodians/me/audit-events/types` for the full list of valid
            values.
          schema:
            type: string
        - name: since
          in: query
          required: false
          description: >
            Returns only audit events created at or after this Unix timestamp
            (in seconds).

            Must be less than `until` when both are provided.
          schema:
            type: number
        - name: until
          in: query
          required: false
          description: >-
            Returns only audit events created at or before this Unix timestamp
            (in seconds).
          schema:
            type: number
      responses:
        '200':
          description: Audit events retrieved successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuditEventsResponse'
              example:
                results:
                  - id: cm8k2x9a1000108l4h3b2c7de
                    userId: cm1q7w3e5000208jx9k4l2mno
                    userEmail: jane@example.com
                    actorRole: OWNER
                    actorIsAdmin: false
                    event: alert-webhook:create
                    resourceId: cm8k2x8z0000008l4abcd1234
                    metadata:
                      environmentId: cm0z9y8x7000108abfedc4321
                      resourceName: https://example.com/alerts-webhooks/1/events
                    createdAt: '2026-03-11T14:02:31.000Z'
                  - id: cm8k1v4b2000308l4q9r8s7tu
                    userId: cm1q7w3e5000208jx9k4l2mno
                    userEmail: jane@example.com
                    actorRole: OWNER
                    actorIsAdmin: false
                    event: member:invite
                    resourceId: cm8k1v4a9000208l4zyxw9876
                    metadata: {}
                    createdAt: '2026-03-11T13:47:05.000Z'
                metadata:
                  cursor: >-
                    eyJjcmVhdGVkQXQiOiIyMDI2LTAzLTExVDEzOjQ3OjA1LjAwMFoiLCJpZCI6ImNtOGsxdjRiMjAwMDMwOGw0cTlyOHM3dHUifQ
                  take: 2
                  hasMore: true
        '400':
          description: >-
            Bad request - invalid `take`, `cursor`, `userIds`, `eventTypes`,
            `since`, or `until`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized - invalid or missing authentication token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '429':
          description: >-
            Rate limited - more than 30 requests to this endpoint within a
            one-minute window
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    AuditEventsResponse:
      type: object
      required:
        - results
        - metadata
      properties:
        results:
          type: array
          items:
            $ref: '#/components/schemas/AuditEvent'
        metadata:
          type: object
          required:
            - cursor
            - take
            - hasMore
          properties:
            cursor:
              type:
                - string
                - 'null'
              description: >-
                Opaque cursor for the next page, or `null` when there are no
                more results.
            take:
              type: integer
              description: Number of records requested
            hasMore:
              type: boolean
              description: Whether more results are available
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
    AuditEvent:
      type: object
      required:
        - id
        - userId
        - userEmail
        - actorRole
        - actorIsAdmin
        - event
        - resourceId
        - metadata
        - createdAt
      properties:
        id:
          type: string
          description: The unique identifier of the audit event.
        userId:
          type: string
          description: The ID of the Portal Dashboard user who took the action.
        userEmail:
          type: string
          description: The email of the Portal Dashboard user who took the action.
        actorRole:
          type: string
          enum:
            - OWNER
            - MEMBER
          description: The user's role in your organization when they took the action.
        actorIsAdmin:
          type: boolean
          description: Whether the user is a Portal staff member.
        event:
          type: string
          description: >
            The audit event type, in `resource:action` form (for example
            `member:invite`).

            See `GET /custodians/me/audit-events/types`.
        resourceId:
          type:
            - string
            - 'null'
          description: The ID of the resource the action was taken on, if any.
        metadata:
          type: object
          additionalProperties: true
          description: >
            Event-specific details, such as `environmentId` or `resourceName`.
            The keys

            vary by event type. Values under common secret key names are
            `[REDACTED]`.
        createdAt:
          type: string
          format: date-time
          description: When the action was taken.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: |
        Portal API Key (Custodian API Key). Pass as a Bearer token in the
        Authorization header.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.