Uptimeify Docs
Incident management

Audit Log

Read the Incident Management audit trail: who created, changed or deleted which team, schedule, source or setting, with the recorded diff. Cursor-paginated.

GET /api/im/audit-log

Returns the Incident Management audit trail of your organization, newest first: every create, update and delete on teams, members, schedules, overrides, escalation tiers, alert sources, routing rules, channels and IM settings, with who did it and the recorded change.

Authentication

Requires IM access and the organization role admin. Editors and responders are refused. An organization-wide API token works if it was created by an organization admin (a token carries the role of the user who created it). Incident Management must be enabled for the organization.

Query Parameters

ParameterTypeDescription
entityTypestringOnly this entity type, e.g. im_team, im_team_member, im_schedule, im_schedule_override, im_escalation_tier, im_alert_source, im_routing_rule, im_channel, im_incident, im_org_settings.
actorstringOnly entries by this user ID.
fromISO 8601Only entries at or after this instant. An invalid date is ignored.
toISO 8601Only entries at or before this instant. An invalid date is ignored.
limitnumberPage size. Default 50, maximum 200.
beforenumberCursor: pass nextCursor from the previous page to continue.

Example (cURL)

curl "$BASE_URL/api/im/audit-log?entityType=im_alert_source&limit=2" \
  -H "Authorization: Bearer $TOKEN"

Response

{
  "entries": [
    {
      "id": 5812,
      "entityType": "im_alert_source",
      "entityId": "7",
      "action": "update",
      "diff": { "ingestToken": { "from": "rotated", "to": "rotated" }, "secondaryExpiresAt": { "from": null, "to": "2026-10-16T09:30:00.000Z" } },
      "at": "2026-10-09T09:30:00.000Z",
      "actorUserId": "u_abc123",
      "actorName": "Jana Weber"
    },
    {
      "id": 5790,
      "entityType": "im_alert_source",
      "entityId": "7",
      "action": "create",
      "diff": { "name": "Zabbix production", "type": "zabbix", "teamId": 3, "autoResolve": true },
      "at": "2026-10-01T08:00:00.000Z",
      "actorUserId": "u_abc123",
      "actorName": "Jana Weber"
    }
  ],
  "hasMore": true,
  "nextCursor": 5790
}
FieldDescription
actioncreate, update or delete.
diffFree-form object recorded with the change, usually { field: { from, to } } for updates. Secrets are never recorded, rotations appear as "rotated" or "set".
actorUserId, actorNameWho made the change. Both null if that user account has been deleted since.
hasMore, nextCursorWhen hasMore is true, request the next page with before=<nextCursor>. nextCursor is null on the last page.

Common errors

  • 401 Unauthorized (unauthorized) when not authenticated
  • 403 Forbidden (customerScopedTokenForbidden) for a customer-scoped token
  • 403 Forbidden (imAccessDenied) when the session has no IM-eligible role
  • 403 Forbidden (imNotEnabled) when Incident Management is not enabled for the organization
  • 403 Forbidden (imAuditLogAccessDenied) when the caller's role is not admin

On this page