Layerbeat

Read the audit log

GET
/v1/audit-log

Lists workspace security and management events, newest first.

Access: User session: workspace admin or owner. API keys aren't supported.

Authorization

headerAuthorizationBearer <token>

Send Authorization: Bearer <token>. A token is an API key (lb_live_…, scoped, for programs) or a session (lb_sess_…, from signup or login, for people). See Authentication above.

Query Parameters

limit?integer

Page size.

Range1 <= value <= 100
Default50
cursor?string

next_cursor from the previous page.

Header Parameters

X-Org-ID?string

Sessions only: act on this organization (you must be a member). Default: your first organization.

Response Body

Events

application/json
  1. response
data*array<>
next_cursor*|

Pass as cursor to get the next page; null when there are no more results.

curl -X GET 'https://layerbeat.com/v1/audit-log'
{  "data": [    {      "id": "1042",      "actor": "api_key:key_rs6goiwfde7kq3mzt5xv2nuhpa",      "action": "vm.create",      "target": "vm_gnkrp6zuxvsqki7sqxeluvsw2y",      "ip": "203.0.113.7",      "metadata": {        "plan": "small",        "region": "sgp"      },      "created_at": "2026-10-01T10:00:00Z"    }  ],  "next_cursor": null}