> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ada.cx/reference/audit-log/getting-started/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ada.cx/_mcp/server. # Getting started The Audit log API lets you pull configuration-change events for your instance and ingest them into a SIEM or other tooling. This page walks through a first pull and then ongoing, incremental polling. For the full reference: event schema, rate limits, pagination, and webhook events, see the [Audit log API overview](/reference/audit-log/overview). ## Before you begin You'll need to generate a [Platform API key](/reference/introduction/authentication) to call the API. ## Pull a window of events Request events for a time window of up to 30 days. Results come back newest first. ```bash curl -X GET "https://EXAMPLE.ada.support/api/v2/analytics/audit-log/events/?start_date=2026-06-01T00:00:00%2B00:00&end_date=2026-06-09T00:00:00%2B00:00&limit=100" \ -H "Authorization: Bearer YOUR_API_KEY" ``` `start_date` is required, and the window between `start_date` and `end_date` cannot exceed 30 days. When `end_date` is omitted it defaults to the request time. ## Page through the results Each response includes a `meta.next_page_url`. Replay it verbatim to fetch the next page, and keep going until `next_page_url` is `null`, which marks the last page. ```bash curl -X GET "PASTE_THE_NEXT_PAGE_URL_HERE" \ -H "Authorization: Bearer YOUR_API_KEY" ``` Do not modify the URL between pages. The time window and cursor are encoded in it, and changing them returns a `400`. ## Poll incrementally For ongoing ingestion, store the newest `timestamp` already retrieved. On the next run, set `start_date` to just after that value and follow `next_page_url` until it is `null`. ```bash curl -X GET "https://EXAMPLE.ada.support/api/v2/analytics/audit-log/events/?start_date=2026-06-09T12:34:56.790%2B00:00" \ -H "Authorization: Bearer YOUR_API_KEY" ``` Poll on a steady cadence, for example every few minutes. The endpoint allows 10 requests per second, 120 per minute, and 40,000 per day. A `429` response means a limit was exceeded, so back off and retry. ## Backfill older history A single request covers at most 30 days. To load more history, issue successive requests over adjacent 30-day windows, walking backward in time until you reach the earliest data you need. ## Receive events in real time (optional) To react to changes as they happen, subscribe to the `v1.audit_log.emitted` webhook in the Ada dashboard. Delivery is best-effort, so continue to use the pull API as the durable record for reconciliation. See [webhook support](/reference/audit-log/overview#webhook-support).