---
updatedAt: 2026-09-30T17:50:34.235Z
---

Fetch the complete documentation index at: https://docs.avvio.xyz/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# List audit events

`GET https://api.avvio.xyz/business/api/v1/payments/organizations/{orgId}/audit-events`

Records who did what, from where, with which credential. It has one
row per audited mutation on your organization (payouts created or canceled, batches, approvals decided, recipients changed, keys and webhook endpoints managed), recorded whether it succeeded or was
refused. A refused attempt is as much of an audit record as a
successful one.

Rows name the key by its **prefix** (`apiKeyPrefix`), which is how you
named it in the dashboard; a dashboard action carries `actorUserId`
instead. Exactly one of the two is set. `requestId` is the same value
as the `x-request-id` header on that request and the `requestId` in any
error body it returned.

A read-only key may read this; that is the point of a read-only key.
Newest first, cursor on `id`. Retained for five years.

## Parameters

- `orgId` (path, required) — The opaque organization id issued to you, normally CUID-shaped (for example `cmsx…`). It is not an `org_`-prefixed alias. Pass it unchanged in every organization-scoped path.
- `cursor` (query) — A `nextCursor` from a previous page; rows strictly older than it.
- `limit` (query) — From 1 to 100. Defaults to 50.
- `action` (query) — One action, e.g. `payout.create`.
- `resourceId` (query) — Everything done to one payout, batch, approval, recipient, key or endpoint.
- `apiKey` (query) — A key prefix. An unknown prefix is an empty page, not a 404.
- `actorUserId` (query)
- `createdAfter` (query) — Inclusive, ISO-8601 with a timezone.
- `createdBefore` (query) — Inclusive, ISO-8601 with a timezone.

## Example

```bash
curl -s "$AVVIO_BASE_URL/payments/organizations/$AVVIO_ORG_ID/audit-events?action=payout.create" \
  -H "x-api-key: $AVVIO_API_KEY"
```

## Responses

- `200` — Audit events, newest first.
- `400` — `VALIDATION_ERROR`: a cursor that is not one we issued, or a malformed instant.
- `401` — The key was refused. Nothing ran. - `UNAUTHORIZED`: missing, invalid or revoked, or a key on a route that does not accept one. - `KEY_EXPIRED`: the key passed the expiry it was issued with. Issue a new one; an expired key cannot be rotated. - `KEY_IP_NOT_ALLOWED`: the key is pinned to source addresses and this request came from another.
- `403` — A valid key that may not make this call. Nothing ran. - `FORBIDDEN`: the key belongs to a different organization. - `ACCOUNT_BLOCKED`: API access for your organization is suspended, and every key is refused until we lift it. Contact support.
- `429` — Too many requests. The default ceiling is **100 requests per minute per API credential** on a 60-second window. High-volume payout and reconciliation routes declare a 600/minute override, and batch submission a 30/minute ceiling. A separate 2,000/minute per-source-IP abuse ceiling always applies. Obey `Retry-After`; it is in seconds and is authoritative. A 429 means the request was refused before the handler ran. Retry reads normally; retry an idempotent mutation with its same `Idempotency-Key`.

Machine contract: [partner-payouts.openapi.yaml](/partner-payouts.openapi.yaml), operation `listAuditEvents`.
