> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List audit events

> Use this endpoint to list audit events with filters and cursor-based pagination. Designed for SOX/GLBA compliance reporting.



## OpenAPI

````yaml /en/openapi/v3-current/tracer.yaml get /v1/audit-events
openapi: 3.1.0
info:
  title: Midaz Tracer API
  description: >-
    Reference for Midaz Tracer transaction validation, fraud rules, spending
    limits, reservations, and audit events.
  version: 4.0.0
servers:
  - url: https://tracer.sandbox.lerian.net
security: []
tags:
  - name: Validations API
  - name: Rules API
  - name: Limits API
  - name: Reservations API
  - name: Audit Events API
paths:
  /v1/audit-events:
    get:
      tags:
        - Audit Events API
      summary: List audit events
      description: >-
        Use this endpoint to list audit events with filters and cursor-based
        pagination. Designed for SOX/GLBA compliance reporting.
      operationId: listAuditEvents
      parameters:
        - description: Start date (RFC3339 format)
          explode: false
          in: query
          name: start_date
          schema:
            description: Start date (RFC3339 format)
            type: string
        - description: End date (RFC3339 format)
          explode: false
          in: query
          name: end_date
          schema:
            description: End date (RFC3339 format)
            type: string
        - description: Filter by event type (TRANSACTION_VALIDATED, RULE_*, LIMIT_*)
          explode: false
          in: query
          name: event_type
          schema:
            description: Filter by event type (TRANSACTION_VALIDATED, RULE_*, LIMIT_*)
            type: string
        - description: >-
            Filter by action (VALIDATE, CREATE, UPDATE, DELETE, ACTIVATE,
            DEACTIVATE, DRAFT)
          explode: false
          in: query
          name: action
          schema:
            description: >-
              Filter by action (VALIDATE, CREATE, UPDATE, DELETE, ACTIVATE,
              DEACTIVATE, DRAFT)
            type: string
        - description: Filter by result (SUCCESS, FAILED, ALLOW, DENY, REVIEW)
          explode: false
          in: query
          name: result
          schema:
            description: Filter by result (SUCCESS, FAILED, ALLOW, DENY, REVIEW)
            type: string
        - description: Filter by resource type (transaction, rule, limit)
          explode: false
          in: query
          name: resource_type
          schema:
            description: Filter by resource type (transaction, rule, limit)
            type: string
        - description: Filter by resource ID (UUID)
          explode: false
          in: query
          name: resource_id
          schema:
            description: Filter by resource ID (UUID)
            type: string
        - description: Filter by actor type (user, system)
          explode: false
          in: query
          name: actor_type
          schema:
            description: Filter by actor type (user, system)
            type: string
        - description: Filter by actor ID
          explode: false
          in: query
          name: actor_id
          schema:
            description: Filter by actor ID
            type: string
        - description: Filter by account ID (UUID)
          explode: false
          in: query
          name: account_id
          schema:
            description: Filter by account ID (UUID)
            type: string
        - description: Filter by segment ID (UUID)
          explode: false
          in: query
          name: segment_id
          schema:
            description: Filter by segment ID (UUID)
            type: string
        - description: Filter by portfolio ID (UUID)
          explode: false
          in: query
          name: portfolio_id
          schema:
            description: Filter by portfolio ID (UUID)
            type: string
        - description: Filter by transaction type (CARD, WIRE, PIX, CRYPTO)
          explode: false
          in: query
          name: transaction_type
          schema:
            description: Filter by transaction type (CARD, WIRE, PIX, CRYPTO)
            type: string
        - description: Filter by matched rule ID (UUID)
          explode: false
          in: query
          name: matched_rule_id
          schema:
            description: Filter by matched rule ID (UUID)
            type: string
        - description: 'Max items per page (1-1000, default: 100)'
          explode: false
          in: query
          name: limit
          schema:
            description: 'Max items per page (1-1000, default: 100)'
            type: string
        - description: Pagination token (empty for first page)
          explode: false
          in: query
          name: cursor
          schema:
            description: Pagination token (empty for first page)
            type: string
        - description: Sort field (created_at, event_type)
          explode: false
          in: query
          name: sort_by
          schema:
            description: Sort field (created_at, event_type)
            type: string
        - description: Sort direction (ASC, DESC)
          explode: false
          in: query
          name: sort_order
          schema:
            description: Sort direction (ASC, DESC)
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListAuditEventsResponse'
          description: OK
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    ListAuditEventsResponse:
      additionalProperties: false
      properties:
        auditEvents:
          items:
            $ref: '#/components/schemas/AuditEvent'
          maxItems: 1000
          type:
            - array
            - 'null'
        hasMore:
          examples:
            - true
          type: boolean
        nextCursor:
          examples:
            - eyJpZCI6IjAxOTI4In0=
          type: string
      required:
        - auditEvents
        - hasMore
      type: object
    Error:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    AuditEvent:
      additionalProperties: false
      properties:
        action:
          examples:
            - VALIDATE
          type: string
        actor:
          $ref: '#/components/schemas/Actor'
        context:
          additionalProperties: {}
          type: object
        createdAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
        eventId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        eventType:
          examples:
            - TRANSACTION_VALIDATED
          type: string
        hash:
          examples:
            - a3f1e2b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2
          type: string
        metadata:
          additionalProperties: {}
          type: object
        previousHash:
          examples:
            - b4e2f3a5c6d7e8f9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3
          type: string
        resourceId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          type: string
        resourceType:
          examples:
            - transaction
          type: string
        result:
          examples:
            - ALLOW
          type: string
      required:
        - eventId
        - eventType
        - createdAt
        - action
        - result
        - resourceId
        - resourceType
        - actor
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
    Actor:
      additionalProperties: false
      properties:
        actorType:
          examples:
            - user
          type: string
        id:
          examples:
            - 00000000-0000-0000-0000-000000000000
          type: string
        ipAddress:
          examples:
            - 203.0.113.42
          type: string
        name:
          examples:
            - Jane Doe
          type: string
        role:
          examples:
            - admin
          type: string
      required:
        - actorType
        - id
        - name
        - ipAddress
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Static API key presented in the X-API-Key header.
      in: header
      name: X-API-Key
      type: apiKey

````