[{"data":1,"prerenderedAt":387},["ShallowReactive",2],{"content-\u002Fchangelog\u002F2026-04-24-audit-logs":3},{"id":4,"title":5,"author":6,"body":7,"categories":6,"category":370,"categoryType":371,"date":372,"description":373,"extension":374,"faq":6,"howto":6,"isBlog":375,"isChangelog":376,"meta":377,"navigation":376,"path":382,"rawbody":383,"seo":384,"stem":385,"thumbnail":6,"__hash__":386},"content\u002Fchangelog\u002F2026-04-24-audit-logs.md","Audit Logs",null,{"type":8,"value":9,"toc":361},"minimark",[10,14,19,45,49,52,154,158,161,306,310,316,319,323,326,336,347,351],[11,12,13],"p",{},"You can now see a history of actions that happen inside your instance, who did it, how, and from where.",[15,16,18],"h2",{"id":17},"tldr","TL;DR",[20,21,22,26,33,36,39,42],"ul",{},[23,24,25],"li",{},"Audit trail for actions on your instance",[23,27,28,29],{},"Dashboard UI under ",[30,31,32],"strong",{},"Settings → Audit logs",[23,34,35],{},"API endpoints for programmatic access",[23,37,38],{},"Tracks actor identity, passkey usage, IP address, country, user agent, and metadata",[23,40,41],{},"Distinguishes between dashboard (user) and API key actions",[23,43,44],{},"Filterable by feature, operation, actor type, user ID, API key ID, and entity ID",[15,46,48],{"id":47},"whats-logged","What's logged",[11,50,51],{},"Create, update, and delete operations across the platform are recorded:",[20,53,54,60,66,71,77,83,89,94,99,105,110,115,120,126,132,137,143,149],{},[23,55,56,59],{},[30,57,58],{},"Customers"," - create, update, delete",[23,61,62,65],{},[30,63,64],{},"Bank accounts"," - create, delete",[23,67,68,65],{},[30,69,70],{},"Blockchain wallets",[23,72,73,76],{},[30,74,75],{},"Blockchain operations"," - asset trustlines, USDB minting, Solana delegation",[23,78,79,82],{},[30,80,81],{},"Offramp wallets"," - create",[23,84,85,88],{},[30,86,87],{},"Virtual accounts"," - create, update",[23,90,91,65],{},[30,92,93],{},"Wallets",[23,95,96,82],{},[30,97,98],{},"Payins",[23,100,101,104],{},[30,102,103],{},"Payouts"," - create, update (document submission)",[23,106,107,82],{},[30,108,109],{},"Transfers",[23,111,112,82],{},[30,113,114],{},"Customer limit increases",[23,116,117,65],{},[30,118,119],{},"API keys",[23,121,122,125],{},[30,123,124],{},"Team members"," - update role, remove",[23,127,128,131],{},[30,129,130],{},"Invites"," - create, accept, delete",[23,133,134,65],{},[30,135,136],{},"Partner fees",[23,138,139,142],{},[30,140,141],{},"Billing"," - update details, pay invoice, collect fees, portal session",[23,144,145,148],{},[30,146,147],{},"Onboarding"," - every step from business details to completion",[23,150,151,65],{},[30,152,153],{},"Webhook endpoints",[15,155,157],{"id":156},"what-each-log-captures","What each log captures",[11,159,160],{},"Every audit log entry includes:",[162,163,164,177],"table",{},[165,166,167],"thead",{},[168,169,170,174],"tr",{},[171,172,173],"th",{},"Field",[171,175,176],{},"Description",[178,179,180,191,209,219,237,256,266,276,286,296],"tbody",{},[168,181,182,188],{},[183,184,185],"td",{},[30,186,187],{},"Actor",[183,189,190],{},"The user or API key that performed the action",[168,192,193,198],{},[183,194,195],{},[30,196,197],{},"Actor type",[183,199,200,204,205,208],{},[201,202,203],"code",{},"user"," (dashboard) or ",[201,206,207],{},"api_key"," (programmatic)",[168,210,211,216],{},[183,212,213],{},[30,214,215],{},"Passkey",[183,217,218],{},"Whether the action was verified with a passkey",[168,220,221,226],{},[183,222,223],{},[30,224,225],{},"Feature",[183,227,228,229,232,233,236],{},"The area of the platform (e.g. ",[201,230,231],{},"bank_account",", ",[201,234,235],{},"payout",")",[168,238,239,244],{},[183,240,241],{},[30,242,243],{},"Operation",[183,245,246,232,249,252,253],{},[201,247,248],{},"create",[201,250,251],{},"update",", or ",[201,254,255],{},"delete",[168,257,258,263],{},[183,259,260],{},[30,261,262],{},"Entity",[183,264,265],{},"The type and ID of the affected resource",[168,267,268,273],{},[183,269,270],{},[30,271,272],{},"IP address",[183,274,275],{},"Origin IP of the request",[168,277,278,283],{},[183,279,280],{},[30,281,282],{},"Country",[183,284,285],{},"Country derived from the request",[168,287,288,293],{},[183,289,290],{},[30,291,292],{},"User agent",[183,294,295],{},"Browser or SDK making the request",[168,297,298,303],{},[183,299,300],{},[30,301,302],{},"Metadata",[183,304,305],{},"Additional context specific to the action",[15,307,309],{"id":308},"dashboard","Dashboard",[11,311,312,313,315],{},"Navigate to ",[30,314,32],{}," to browse your instance's activity. Click any entry to open the detail pane with the full breakdown: actor info, request metadata, and action-specific context.",[11,317,318],{},"Use the filters to narrow down by feature, operation, actor type, user ID, API key ID, or entity ID.",[15,320,322],{"id":321},"api","API",[11,324,325],{},"Two new endpoints are available:",[327,328,333],"pre",{"className":329,"code":331,"language":332},[330],"language-text","GET \u002Fv1\u002Finstances\u002F{instance_id}\u002Faudit-logs\nGET \u002Fv1\u002Finstances\u002F{instance_id}\u002Faudit-logs\u002F{id}\n","text",[201,334,331],{"__ignoreMap":335},"",[11,337,338,339,342,343,346],{},"The list endpoint returns a paginated list of audit logs for your instance. It supports cursor-based pagination and the same filters available in the dashboard, plus date range filtering with ",[201,340,341],{},"start_date"," and ",[201,344,345],{},"end_date",". The detail endpoint returns a single audit log entry by ID.",[15,348,350],{"id":349},"permissions","Permissions",[11,352,353,354,342,357,360],{},"Only ",[30,355,356],{},"owner",[30,358,359],{},"admin"," roles can view audit logs.",{"title":335,"searchDepth":362,"depth":362,"links":363},2,[364,365,366,367,368,369],{"id":17,"depth":362,"text":18},{"id":47,"depth":362,"text":48},{"id":156,"depth":362,"text":157},{"id":308,"depth":362,"text":309},{"id":321,"depth":362,"text":322},{"id":349,"depth":362,"text":350},"New Feature","feature","2026-04-24","Track actions across your instance with audit logs. See who did what, when, from where, and whether a passkey was used, from the dashboard or the API.","md",false,true,{"excerpt":378},{"type":8,"value":379},[380],[11,381,13],{},"\u002Fchangelog\u002F2026-04-24-audit-logs","---\ntitle: Audit Logs\ndescription: Track actions across your instance with audit logs. See who did what, when, from where, and whether a passkey was used, from the dashboard or the API.\ndate: 2026-04-24\ncategory: New Feature\ncategoryType: feature\nisChangelog: true\n---\n\nYou can now see a history of actions that happen inside your instance, who did it, how, and from where.\n\n\u003C!--more-->\n\n## TL;DR\n\n- Audit trail for actions on your instance\n- Dashboard UI under **Settings → Audit logs**\n- API endpoints for programmatic access\n- Tracks actor identity, passkey usage, IP address, country, user agent, and metadata\n- Distinguishes between dashboard (user) and API key actions\n- Filterable by feature, operation, actor type, user ID, API key ID, and entity ID\n\n## What's logged\n\nCreate, update, and delete operations across the platform are recorded:\n\n- **Customers** - create, update, delete\n- **Bank accounts** - create, delete\n- **Blockchain wallets** - create, delete\n- **Blockchain operations** - asset trustlines, USDB minting, Solana delegation\n- **Offramp wallets** - create\n- **Virtual accounts** - create, update\n- **Wallets** - create, delete\n- **Payins** - create\n- **Payouts** - create, update (document submission)\n- **Transfers** - create\n- **Customer limit increases** - create\n- **API keys** - create, delete\n- **Team members** - update role, remove\n- **Invites** - create, accept, delete\n- **Partner fees** - create, delete\n- **Billing** - update details, pay invoice, collect fees, portal session\n- **Onboarding** - every step from business details to completion\n- **Webhook endpoints** - create, delete\n\n## What each log captures\n\nEvery audit log entry includes:\n\n| Field | Description |\n|-------|-------------|\n| **Actor** | The user or API key that performed the action |\n| **Actor type** | `user` (dashboard) or `api_key` (programmatic) |\n| **Passkey** | Whether the action was verified with a passkey |\n| **Feature** | The area of the platform (e.g. `bank_account`, `payout`) |\n| **Operation** | `create`, `update`, or `delete` |\n| **Entity** | The type and ID of the affected resource |\n| **IP address** | Origin IP of the request |\n| **Country** | Country derived from the request |\n| **User agent** | Browser or SDK making the request |\n| **Metadata** | Additional context specific to the action |\n\n## Dashboard\n\nNavigate to **Settings → Audit logs** to browse your instance's activity. Click any entry to open the detail pane with the full breakdown: actor info, request metadata, and action-specific context.\n\nUse the filters to narrow down by feature, operation, actor type, user ID, API key ID, or entity ID.\n\n## API\n\nTwo new endpoints are available:\n\n```\nGET \u002Fv1\u002Finstances\u002F{instance_id}\u002Faudit-logs\nGET \u002Fv1\u002Finstances\u002F{instance_id}\u002Faudit-logs\u002F{id}\n```\n\nThe list endpoint returns a paginated list of audit logs for your instance. It supports cursor-based pagination and the same filters available in the dashboard, plus date range filtering with `start_date` and `end_date`. The detail endpoint returns a single audit log entry by ID.\n\n## Permissions\n\nOnly **owner** and **admin** roles can view audit logs.\n",{"title":5,"description":373},"changelog\u002F2026-04-24-audit-logs","qnsRup-Bw5sjaHF3yac0ggpk-kx0NFPs82CDViZVH8E",1785718016610]