# Security audit logs

You can access security audit logs to review account activity, including login attempts, user management actions, and API key changes. This data helps you monitor account security and investigate potential unauthorized access or configuration changes.

To retrieve these logs, use the Get security audit logs API endpoint.

> **\[INFORMATIONAL]**
>
> The Security Audit Logs API is currently available to select accounts. Contact your Airwallex account manager to request access.

## API overview

**Endpoint**: `GET /api/v1/audit_log/security_audit_logs`

**Parameters**:

| Parameter         | Type    | Description                                                                                                 |
| ----------------- | ------- | ----------------------------------------------------------------------------------------------------------- |
| `from_event_time` | string  | The start date of `event_time`, inclusive. Defaults to 180 days prior to the current time. ISO 8601 format. |
| `end_event_time`  | string  | The end date of `event_time`, inclusive. Defaults to now. ISO 8601 format.                                  |
| `page`            | string  | Page bookmark for pagination.                                                                               |
| `page_size`       | integer | Page size. Default: 100. Valid values: 1–2000.                                                              |

**Response**:

The response contains a list of audit log items and pagination markers.

```json
{
    "items": [
        {
            "id": "45a6d9c3-bdcd-3bbf-b592-10f287a87ccd",
            "account_id": "acct_IDSCMmzqMCeKRFcgwbtAdQ",
            "event_time": "2022-06-08T06:41:37+0000",
            "operator_info": {
                "type": "WEBAPP_ACCOUNT_USER",
                "mobile": "12345679",
                "email": "test@airwallex.com"
            },
            "session_info": {
                "application": "Chrome",
                "ip_address": "101.228.247.142",
                "location": "Shanghai, China",
                "os": "Mac OS X",
                "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
            },
            "event_type": "account.user_invitation.accepted",
            "event_details": {
                "roles": ["Developer"],
                "target": {
                    "type": "USER",
                    "email": "testing+cyisscardholder002720653@airwallex.com",
                    "mobile": "56-39815749"
                }
            }
        }
    ],
    "page_after": "YWZ0ZXI9MTdiYTVhYzktM2FiMC00NmIzLWE4ODctMTNjNmU5NTg2N2Qy",
    "page_before": "YmVmb3JlPTg0NDg0ODIwLTU0N2UtNDc5YS1iMTY3LTgzYjQwMzcwODQ2ZQ=="
}
```

## Log item structure

| Field           | Description                                                                                        | Sample                                         |
| --------------- | -------------------------------------------------------------------------------------------------- | ---------------------------------------------- |
| `id`            | Unique UUID of the event.                                                                          | `"id": "45a6d9c3-bdcd-3bbf-b592-10f287a87ccd"` |
| `event_time`    | Timestamp of the event in UTC. ISO 8601 format.                                                    | `"event_time": "2022-06-08T06:41:37+0000"`     |
| `account_id`    | Unique identifier of the account.                                                                  | `"account_id": "acct_TOslkS7-MnyXlQuV8Lb4og"`  |
| `operator_info` | Information about the user who performed the action. Currently only exposes `WEBAPP_ACCOUNT_USER`. | See response sample above.                     |
| `session_info`  | Information about where and how the operator triggered the event (IP, location, device).           | See response sample above.                     |
| `event_type`    | Name of the audit log event type.                                                                  | `"event_type": "user.email.added"`             |
| `event_details` | Detailed information specific to the event type.                                                   | See sections below.                            |

## Event types and details

The structure of `event_details` varies depending on the `event_type`. The following sections describe the metadata available for each event category.

### Login credential changes

| Event Type                          | Description                                      | Event Details Metadata                                 |
| ----------------------------------- | ------------------------------------------------ | ------------------------------------------------------ |
| `user.email.updated`                | User email verified (updated).                   | `new_value`, `old_value`, `target`                     |
| `user.email.added`                  | New user email verified (added).                 | `new_value`, `target`                                  |
| `user.email.update_initiated`       | User requested email change.                     | `new_value`, `old_value`, `target`                     |
| `user.mobile.updated`               | User phone number verified (updated).            | `new_value`, `old_value`, `target`                     |
| `user.mobile.added`                 | User phone number verified (added).              | `new_value`, `target`                                  |
| `user.mobile.update_initiated`      | User requested phone number change.              | `new_value`, `old_value`, `target`                     |
| `user.password.updated`             | User changed password.                           | `target`                                               |
| `user.password.reset_initiated`     | User initiated password reset (forgot password). | `target`                                               |
| `user.mobile_login_allowed.updated` | Mobile login setting changed.                    | `new_value` (boolean), `old_value` (boolean), `target` |

### 2FA actions

| Event Type                          | Description                                               | Event Details Metadata                                                                                                             |
| ----------------------------------- | --------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| `user.2fa.enabled`                  | First two-factor authentication (2FA) method set up.      | `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile` (if SMS), `target`                                       |
| `user.2fa.disabled`                 | Last 2FA method removed or 2FA disabled.                  | `target`                                                                                                                           |
| `user.2fa.removed`                  | A 2FA method was removed.                                 | `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `target`                                                              |
| `user.2fa.added`                    | A 2FA method was added.                                   | `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile` (if SMS), `target`                                       |
| `user.2fa.updated`                  | A specific 2FA method was changed (such as phone number). | `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile`, `target`                                                |
| `user.2fa.default_method.updated`   | Primary 2FA method updated.                               | `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile` (if SMS), `target`                                       |
| `user.2fa.recovery_codes.generated` | New recovery codes generated.                             | `target`                                                                                                                           |
| `user.2fa.recovery_codes.used`      | Recovery code used for verification.                      | `target`                                                                                                                           |
| `user.2fa.post_login.success`       | Post-login 2FA authentication succeeded.                  | `2fa_context` (such as `LOGIN`, `EDIT_EMAIL`), `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile`, `target` |
| `user.2fa.post_login.failed`        | Post-login 2FA authentication failed.                     | `2fa_context` (such as `LOGIN`, `EDIT_EMAIL`), `2fa_method` (one of `AUTHENTICATOR_APP`, `SMS`, `AWX_APP`), `2fa_mobile`, `target` |
| `account.2fa_settings.updated`      | Account 2FA settings updated.                             | `setting_type` (such as `accountLogin`), `new_value`                                                                               |

### API key actions

| Event Type                               | Description                               | Event Details Metadata                                                                       |
| ---------------------------------------- | ----------------------------------------- | -------------------------------------------------------------------------------------------- |
| `account.api_key.admin.generated`        | Admin API key created.                    | No specific metadata.                                                                        |
| `account.api_key.admin.regenerated`      | Admin API key regenerated.                | No specific metadata.                                                                        |
| `account.api_key.restricted.regenerated` | Restricted API key regenerated.           | `new_api_key_name`                                                                           |
| `account.api_key.restricted.generated`   | Restricted API key created or duplicated. | `new_api_key_name`, `new_api_key_permissions`                                                |
| `account.api_key.restricted.updated`     | Restricted API key edited.                | `old_api_key_name`, `new_api_key_name`, `old_api_key_permissions`, `new_api_key_permissions` |
| `account.api_key.restricted.deleted`     | Restricted API key deleted.               | `old_api_key_name`                                                                           |

### User login actions

| Event Type           | Description                           | Event Details Metadata                                                                                                                 |
| -------------------- | ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| `user.login.success` | User login succeeded.                 | `platform` (such as `APP`, `WEB`), `2fa_required`, `2fa_skipped_remember_device`, `2fa_method`, `2fa_mobile`, `target`                 |
| `user.login.failed`  | User login failed.                    | `platform`, `reason` (such as `INVALID_PASSWORD`), `2fa_required`, `2fa_skipped_remember_device`, `2fa_method`, `2fa_mobile`, `target` |
| `user.locked`        | User locked due to repeated failures. | `reason` (such as `MULTIPLE_INVALID_PASSWORD`), `target`                                                                               |

### User management actions

| Event Type                         | Description             | Event Details Metadata                                                                                                           |
| ---------------------------------- | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `account.user_invitation.created`  | User invited.           | `roles`, `target` (invitee info)                                                                                                 |
| `account.user_invitation.accepted` | User joined account.    | `target`                                                                                                                         |
| `account.user.suspended`           | User suspended.         | `target`                                                                                                                         |
| `account.user.unsuspended`         | User unsuspended.       | `target`                                                                                                                         |
| `account.user.removed`             | User removed.           | `target`                                                                                                                         |
| `account.user.role_updated`        | User role changed.      | `old_value` (roles), `new_value` (roles), `target`                                                                               |
| `account.role.created`             | Custom role created.    | `new_role_name`, `new_role_description`, `new_role_permissions`                                                                  |
| `account.role.updated`             | Custom role edited.     | `old_role_name`, `new_role_name`, `old_role_description`, `new_role_description`, `old_role_permissions`, `new_role_permissions` |
| `account.role.deleted`             | Custom role deleted.    | `old_role_name`                                                                                                                  |
| `account.team.created`             | Team created.           | `new_team_name`, `new_team_description`                                                                                          |
| `account.team.updated`             | Team edited.            | `old_team_name`, `new_team_name`, `old_team_description`, `new_team_description`                                                 |
| `account.team.deleted`             | Team deleted.           | `old_team_name`                                                                                                                  |
| `account.team.role_updated`        | Team role updated.      | `team_name`, `old_value`, `new_value`                                                                                            |
| `account.team.user_added`          | User added to team.     | `team_name`, `target`                                                                                                            |
| `account.team.user_removed`        | User removed from team. | `team_name`, `target`                                                                                                            |