Read the activity log
Owners and admins only. AI runs with their tokens and credits, tool calls, knowledge syncs and imports, team and settings changes, and whatever failed, newest first. Background work and API calls are only logged when they go wrong. Keep the same snapshot and filters while paging. Reading the log writes nothing to it.
GET
/logsAuthorization
AuthorizationBearer token · headerrequired`MEDIAN_KEY` from Settings under API, or an MCP OAuth access token. A key acts as the organization; a token acts as the person who approved it.
Query parameters
fromnumberInclusive Unix timestamp in milliseconds; defaults to 30 days before the end.
tonumberInclusive Unix timestamp in milliseconds; defaults to now.
snapshotnumberFixed recording cutoff in Unix milliseconds; defaults to now.
limitintegerRecords per page.
min 1 · max 200 · default: 100
cursorstringContinuation cursor. An empty filtered page may still have a continuation.
searchstringMatches the entry's line, its error and tool names.
categorystringOne area, like ai, tools, knowledge or team.
actorIdstringOne member's user id.
conversationIdstringOnly entries about one conversation.
usagebooleanOnly entries that used something billed: tokens, emails or pages.
actorKindstringWho did it: a member, the support agent, the assistant, a customer, the API or the system.
Allowed:
memberagentassistantcustomerapisystemoutcomestringEvent outcome.
Allowed:
successfaileddeniedpendingcanceledResponses
200A page of entries.
pageobject[]requiredisDonebooleanrequiredcontinueCursorstringrequired401Invalid or missing credentials.
403The authenticated role cannot read these records.
429Shared organization API allowance or temporary fair-use protection reached. Retry-After states the delay.
Request
curl -X GET "https://api.median.sh/v1/logs" \
-H "Authorization: Bearer YOUR_TOKEN"const response = await fetch("https://api.median.sh/v1/logs", {
method: "GET",
headers: {
"Authorization": "Bearer YOUR_TOKEN"
}
});Response
{
"page": [
{}
],
"isDone": true,
"continueCursor": "string"
}Invalid or missing credentials.
The authenticated role cannot read these records.
Shared organization API allowance or temporary fair-use protection reached. Retry-After states the delay.