> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# Management API — Audit Trail

Read the organization's trail of management actions. Requires a Management API Key and
is scoped to its organization — see the [Overview](/docs/red/management-api-overview)
for authentication and error conventions.

Each successful folder, member, and Red Team API Key mutation appends one audit entry. A
rejected action leaves no entry. Entries record identifiers and the action only — no
folder, key, or user content is ever stored.

## List audit entries

`GET /management/audit`

Returns entries newest first.

| Query parameter | Type   | Notes                                                                                    |
| --------------- | ------ | ---------------------------------------------------------------------------------------- |
| `limit`         | number | Maximum entries to return. Default 100, capped at 500.                                   |
| `before`        | number | Return entries older than this `at` timestamp — the `nextCursor` from the previous page. |

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  "https://$LAKERA_RED_HOST/management/audit?limit=50"
```

```json
{
  "entries": [
    {
      "id": "...",
      "at": 1786546819835,
      "actorUserId": "...",
      "keyId": "...",
      "action": "folder.key.created",
      "folderId": "...",
      "targetKeyId": "..."
    }
  ],
  "nextCursor": 1786546819835
}
```

`actorUserId` is the owner of the Management API Key that performed the action, and
`keyId` is that key. `folderId`, `memberUserId`, and `targetKeyId` appear only for
actions that touch those resources.

## Page through history

`nextCursor` is the `before` value to pass to fetch the next page, or `null` when the
last page has been reached. Keep requesting with it until it comes back `null`:

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  "https://$LAKERA_RED_HOST/management/audit?limit=100&before={nextCursor}"
```