> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# List Audit Entries

GET https://api.hiddenlayer.ai/audit/v3/entries

Returns audit log entries for the tenant, sorted by time with the most recent first. Results can be filtered by time range, actor, role, action, and resource type, or searched by free text.

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/audit/list-entries

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Query parameters

- `start_time` (datetime, optional) — Filter audit entries by time range
- `end_time` (datetime, optional) — Filter audit entries by time range
- `role` (string, optional) — Filter audit entries by role
- `action` (string, optional) — Filter audit entries by action
- `resource_type` (string, optional) — Filter audit entries by resource_type
- `actor_type` (enum, optional) — Filter audit entries by actor_type
  - Allowed values: `USER`, `API_KEY`
- `search` (string, optional) — Search for audit entries by text (searches user, role, action, resource type)
- `limit` (integer, optional, default: 25)
- `offset` (integer, optional, default: 0)

## Response

### 200

Successful response

- `items` (list of AuditEntry, required) — List of items. If no matching items are found, then `[]` will be returned.
- `limit` (integer, required, default: 25) — Maximum number of items to return
- `offset` (integer, required, default: 0) — Begin returning the results from this offset

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 422 Unprocessable Entity Error

Validation Error

- `loc` (list of ValidationErrorModelLocItems, required)
- `msg` (string, required)
- `type` (string, required)

## Types

### AuditEntry

Base properties needed for an audit entry

- `occurred_at` (datetime, required)
- `action` (string, required) — Action performed by the actor
- `resource_type` (string, required) — Type of HiddenLayer resource that was acted upon
- `resource_id` (string, required) — Unique identifier for the resource that was acted upon
- `api_permissions_required` (list of string, required) — Snapshot of API permissions required to perform the action
- `actor_type` (enum, required)
  - Allowed values: `USER`, `API_KEY`
- `actor_id` (string, required) — Unique identifier for the actor
- `assigned_roles` (list of string, required) — Snapshot of the roles assigned to the actor at the time of the action
- `metadata` (map from string to string, optional) — Contextual information specific to the audited event
- `description` (string, optional) — Description of the action performed
- `actor_name` (string, optional) — Name of the actor
- `actor_email` (string, optional) — Email address of the actor
- `correlation_id` (string, optional) — Correlation ID associated with the action
- `session_id` (string, optional) — Session ID

### ValidationErrorModelLocItems

## Examples

**Response**

```json
{
  "items": [
    {
      "occurred_at": "2025-05-27T00:00:00Z",
      "action": "delete",
      "resource_type": "model",
      "resource_id": "fb0eb4e3-6cd7-488b-981c-619b2c707ab9",
      "api_permissions_required": [
        "model:delete"
      ],
      "actor_type": "USER",
      "actor_id": "e4341229-9bb0-4336-84a6-4ca50c959369",
      "assigned_roles": [
        "org-admin"
      ],
      "metadata": {
        "model_name": "gpt-3.5-turbo"
      },
      "description": "deleted model",
      "actor_email": "john.doe@example.com"
    },
    {
      "occurred_at": "2025-05-24T00:00:00Z",
      "action": "create",
      "resource_type": "model",
      "resource_id": "fb0eb4e3-6cd7-488b-981c-619b2c707ab9",
      "api_permissions_required": [
        "model:create"
      ],
      "actor_type": "USER",
      "actor_id": "81ae1941-501e-48db-81db-49bf61c6fe8f",
      "assigned_roles": [
        "analyst"
      ],
      "metadata": {
        "model_name": "gpt-3.5-turbo",
        "model_version": "1.0",
        "model_source": "Local"
      },
      "description": "Created model",
      "actor_email": "john.doe@example.com"
    }
  ],
  "limit": 10,
  "offset": 0
}
```

**SDK Code**

```python Audit Entries
import requests

url = "https://api.hiddenlayer.ai/audit/v3/entries"

querystring = {"start_time":"2025-05-27T00:00:00Z","end_time":"2025-05-27T23:59:59Z","actor_type":"API_KEY"}

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers, params=querystring)

print(response.json())
```

```javascript Audit Entries
const url = 'https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Audit Entries
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Audit Entries
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java Audit Entries
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php Audit Entries
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp Audit Entries
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift Audit Entries
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/audit/v3/entries?start_time=2025-05-27T00%3A00%3A00Z&end_time=2025-05-27T23%3A59%3A59Z&actor_type=API_KEY")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```