Audit
List audit logs
Return workspace activity for your organization: who did what, when, and on which resource.
GET
/
audit
/
logs
curl -X GET "https://api.cloud.blnkfinance.com/audit/logs?page=1&page_size=20&action=Deployment&instanceId=YOUR_INSTANCE_ID" \
-H "X-blnk-key: CLOUD_API_KEY"
{
"data": [
{
"audit_log_id": "audit_f482a1b3-6c2d-4e89-a17b-3d5e8f2a1c94",
"action": "Deployment destroy initiated",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"api_key_id": "apikey_6e6feddd-930b-4e38-8ba1-1a3eee659bb3",
"deployment_id": "deploy_c5d9e2a1-7b4f-4a3c-9e8d-1f6a2b4c8d30",
"created_at": "2026-09-11T09:28:16.864765Z"
},
{
"audit_log_id": "audit_845e6b1e-0463-4ce8-b858-2b3a398beff9",
"action": "App Launched",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"instance_id": "instance_073f7ffe-9dfd-42ce-aa50-d1dca1788adc",
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17",
"app_name": "Fee Engine",
"acting_app": {
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"name": "Fee Engine",
"logo_url": "https://cdn.example.com/fee-engine.png",
"slug": "fee-engine",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17"
},
"created_at": "2026-09-10T21:56:12.112739Z"
}
],
"pagination": {
"current_page": 1,
"page_size": 20,
"total": 128
}
}
An audit log is one workspace action: who did it, when, and which resource they touched. Cloud writes a row when someone uses the dashboard, a Cloud API key, the Proxy API, or a Custom App.
This endpoint lists those rows for the authenticated organization, newest first. To review the same activity in the dashboard, open Settings > Audit logs.
api_key_id is present when the actor used an API key. acting_app is present when a Custom App performed the action, or when the row is an app lifecycle event such as install or launch.
This endpoint requires the Cloud audit:read scope.
Authorization
Blnk Cloud APIs support any one of the following authentication methods. All of them work with yourCLOUD_API_KEY or OAUTH_ACCESS_TOKEN.
Pass X-blnk-key: CLOUD_API_KEY or X-blnk-key: OAUTH_ACCESS_TOKEN.
Query parameters
curl -X GET "https://api.cloud.blnkfinance.com/audit/logs?page=1&page_size=20&action=Deployment&instanceId=YOUR_INSTANCE_ID" \
-H "X-blnk-key: CLOUD_API_KEY"
integer
Page number. Defaults to
1. Values less than 1 are treated as 1.integer
Audit logs to return. Defaults to
10. Values less than 1 are treated as 10.string
Substring of the
action label on the log. Case-insensitive. For example: action=Ledger matches Ledger Created and Ledger Updated.| Supported values | Labels that match |
|---|---|
Ledger | Ledger Created, Ledger Updated |
Balance | Balance Created, Balance Updated |
Transaction | Transaction Created, Transaction Retrieved |
Identity | Identity Created, Identity Updated |
Reconciliation | Reconciliation Started, Instant Reconciliation Started |
Matching Rule | Matching Rule Created, Matching Rule Updated |
External Data | External Data Uploaded |
Alert | Alert assigned, Alert escalated |
App | App Installed, App Launched, App Deleted |
Domain | Domain verified, Domain removed |
Deployment | Deployment created, Deployment destroy initiated |
string
User id stored on the log as
performed_by_id (user_...). Exact match. Do not pass the display name in performed_by.string
Audit logs whose
instance_id is this Cloud instance (instance_...). This is a filter, not a routing param.string
Audit logs whose
ledger_id is this ledger (ldg_...).string
Audit logs whose
balance_id is this balance (bln_...).string
Audit logs whose
transaction_id is this transaction (txn_...).string
Audit logs whose
identity_id is this identity (idt_...).string
Audit logs whose
reconciliation_id is this reconciliation (recon_...).string
Audit logs whose
anomaly_id is this alert.string
Audit logs whose
doc_id is this document.string
Audit logs whose
app_id is this app (app_...).string
Audit logs whose
installed_app_id is this install (instapp_...).string
Case-insensitive substring of
app_name on the log.string
Audit logs whose
domain_name is this workspace domain. domain is an alias for the same filter.Response
Rows include every resource id field. Unrelated ids come back as empty strings. These fields are omitted when empty:api_key_id, deployment_id, domain_name, email, acting_app, and performed_by_id.
{
"data": [
{
"audit_log_id": "audit_f482a1b3-6c2d-4e89-a17b-3d5e8f2a1c94",
"action": "Deployment destroy initiated",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"api_key_id": "apikey_6e6feddd-930b-4e38-8ba1-1a3eee659bb3",
"deployment_id": "deploy_c5d9e2a1-7b4f-4a3c-9e8d-1f6a2b4c8d30",
"created_at": "2026-09-11T09:28:16.864765Z"
},
{
"audit_log_id": "audit_845e6b1e-0463-4ce8-b858-2b3a398beff9",
"action": "App Launched",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"instance_id": "instance_073f7ffe-9dfd-42ce-aa50-d1dca1788adc",
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17",
"app_name": "Fee Engine",
"acting_app": {
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"name": "Fee Engine",
"logo_url": "https://cdn.example.com/fee-engine.png",
"slug": "fee-engine",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17"
},
"created_at": "2026-09-10T21:56:12.112739Z"
}
],
"pagination": {
"current_page": 1,
"page_size": 20,
"total": 128
}
}
array
Audit log rows for the current page, newest first.
Show Log properties
Show Log properties
string
Unique id of this row (
audit_...).string
Activity label, such as
Deployment destroy initiated, Transaction Created, or App Launched.string
Display name of the actor (
FirstName LastName). Falls back to the user id when Cloud cannot resolve the name.string
User id of the person who performed the action (
user_...). Pass this value as performed_by to filter. Omitted when the log has no user.string
Cloud API key that performed the action (
apikey_...). Omitted when the actor did not use a key.timestamp
When the action occurred, in UTC.
string
Related Cloud instance (
instance_...). Empty when the action is not tied to an instance.string
Related managed deployment (
deploy_...). Omitted when the action is not about a deployment.string
Related ledger (
ldg_...). Empty when unused.string
Related balance (
bln_...). Empty when unused.string
Related transaction (
txn_...). Empty when unused.string
Related identity (
idt_...). Empty when unused.string
Related reconciliation (
recon_...). Empty when unused.string
Related alert id. Empty when unused.
string
Related document id. Empty when unused.
string
Related app (
app_...). Empty when unused.string
Related install (
instapp_...). Empty when unused.string
App display name stored on the row. Empty when unused.
string
Workspace domain this action is about. Present on domain verification and join events.
string
Email stored on the row, such as a pending invite revoked during domain join. Omitted when unused.
object
Present when a Custom App performed the action, or when the row already stores app ids from an install or launch. Use
name and logo_url to show the app next to performed_by.Show Acting app properties
Show Acting app properties
string
App id (
app_...).string
App display name.
string
App slug, such as
fee-engine.string
App logo URL. Empty when none is set, or when Cloud fell back to the stored row.
string
Installed app id (
instapp_...). Omitted when Cloud cannot resolve the install.boolean
true when the app is no longer in the registry and Cloud filled name from this log row. Treat logo_url as a placeholder when it is empty.object
Need help?
We are very happy to help you make the most of Blnk, regardless of whether it is your first time or you are switching from another tool. To ask questions or discuss issues, please contact us or join our Discord community.Was this page helpful?
⌘I
curl -X GET "https://api.cloud.blnkfinance.com/audit/logs?page=1&page_size=20&action=Deployment&instanceId=YOUR_INSTANCE_ID" \
-H "X-blnk-key: CLOUD_API_KEY"
{
"data": [
{
"audit_log_id": "audit_f482a1b3-6c2d-4e89-a17b-3d5e8f2a1c94",
"action": "Deployment destroy initiated",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"api_key_id": "apikey_6e6feddd-930b-4e38-8ba1-1a3eee659bb3",
"deployment_id": "deploy_c5d9e2a1-7b4f-4a3c-9e8d-1f6a2b4c8d30",
"created_at": "2026-09-11T09:28:16.864765Z"
},
{
"audit_log_id": "audit_845e6b1e-0463-4ce8-b858-2b3a398beff9",
"action": "App Launched",
"performed_by_id": "user_01K4EX0BRXHNNGCRVT2TPNK07W",
"performed_by": "Alex Example",
"instance_id": "instance_073f7ffe-9dfd-42ce-aa50-d1dca1788adc",
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17",
"app_name": "Fee Engine",
"acting_app": {
"app_id": "app_9a1c4e70-2b8d-4f61-8c3a-7e5d2b1f0a94",
"name": "Fee Engine",
"logo_url": "https://cdn.example.com/fee-engine.png",
"slug": "fee-engine",
"installed_app_id": "instapp_3d5e8f2a-1c94-4b7e-9a2c-6f481d0e3b17"
},
"created_at": "2026-09-10T21:56:12.112739Z"
}
],
"pagination": {
"current_page": 1,
"page_size": 20,
"total": 128
}
}