> For the complete documentation index, see [llms.txt](https://docs.uptiq.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.uptiq.ai/cookbooks/platform-admin/agents-and-evidence/show-who-changed-what.md).

# Review the audit trail

The audit trail is reachable over MCP, not REST — and \`/audit-logs\` is not it.

Control Center's Audit Trails record — the configuration-and-access change log with an Actor, a Module (Users, Accounts, Agents…) and an Action (Created, Updated, User Invited…) — **is reachable programmatically, but not over REST.** It is served by the audit-logs MCP endpoint, described below.

The REST route whose name suggests it, `GET /audit-logs`, is a different thing entirely.

## At a glance

| Item              | Value                                           |
| ----------------- | ----------------------------------------------- |
| ⚙️ Microservice   | `Identity Hub`                                  |
| 🌍 Environment    | `QA`                                            |
| 🔗 Base URL       | `https://api-builder-qa.uptiq.dev/identity-hub` |
| ⌘ MCP endpoint    | `POST /audit-logs/mcp`                          |
| 🔐 Authentication | Account API key                                 |

{% columns %}
{% column %}

#### What it does

Returns configuration and access events through an MCP tool.
{% endcolumn %}

{% column %}

#### What it doesn't do

It doesn't expose the user action trail through REST.
{% endcolumn %}
{% endcolumns %}

{% hint style="danger" %}
**`GET /audit-logs` looks like a match and isn't.** It exists, it's on Identity Hub, and its name is exactly what you'd search for. But its `direction` parameter is `incoming | outgoing` — it logs **HTTP request/response traffic** (URL, method, status code, service, request ID) between this platform and other systems, not configuration or access events with an actor's email. Read its description before building on it: presenting this as "who changed what" would tell your reader the wrong thing.
{% endhint %}

## The audit trail is available — over MCP, not REST

`POST /identity-hub/audit-logs/mcp` is a Model Context Protocol (Streamable HTTP) endpoint exposing ten read-only tools over the same data the REST routes serve. One of them, **`get_audit_trail_logs`**, is described by the server as *"the user action audit trail — who did what, when, across all modules"* — the record this recipe wants.

It is a JSON-RPC endpoint, so every call is a `POST`, including `initialize`. The server is stateless and issues no `mcp-session-id`.

{% hint style="info" %}
**`GET` on this path returns `405`, by design** — the spec titles the GET and DELETE operations "(not offered)" because a stateless server has no event stream and no session to terminate. A `POST` without `accept: application/json, text/event-stream` returns `406`. Neither is a fault.
{% endhint %}

## Code snippets

```bash
curl -X POST https://api-builder-qa.uptiq.dev/identity-hub/audit-logs/mcp \
  -H "x-platform-key: YOUR_API_KEY" \
  -H "account-id: YOUR_ACCOUNT_ID" \
  -H "app-id: YOUR_APP_ID" \
  -H "content-type: application/json" \
  -H "accept: application/json, text/event-stream" \
  -d '{
    "jsonrpc": "2.0", "id": 1, "method": "tools/call",
    "params": { "name": "get_audit_trail_logs", "arguments": { "query": { "pageSize": 20 } } }
  }'
```

`arguments.query` is required — omitting it returns a JSON-RPC `-32602` validation error rather than defaulting.

Note the header spellings: this route takes **`account-id`** and **`app-id`** (hyphenated), not the `accountid` the REST routes on this service use. See [Authentication](https://gitlab.com/uptiq-inc-enterprise/development/documentation/platform-docs-repo/-/tree/main/api-references/qa/getting-started/authentication.md).

### The other nine tools

`get_traffic_audit_logs` / `export_traffic_audit_logs` (HTTP traffic), `get_database_audit_logs` / `export_database_audit_logs` (row-level changes, with old values), `get_ai_gateway_logs`, `get_ai_gateway_log_detail`, `get_ai_gateway_log_models`, `get_embedding_logs`, `get_embedding_log_models`.

## What `/audit-logs` is actually for

If you need HTTP-level traffic logging — which service handled a request, what method, what status code came back — it's genuinely useful for that:

```bash
curl "https://api-builder-qa.uptiq.dev/identity-hub/audit-logs?direction=incoming&methods=POST&methods=DELETE" \
  -H "x-platform-key: YOUR_API_KEY" \
  -H "accountid: YOUR_ACCOUNT_ID"
```

`module` filters by product area (`agent`, `app`, `skill`, `integrations`, `marketplace`, `platform` — the microservices behind each), not by the Control Center entities (Users, Roles, Teams) the Audit Trails screen uses. Don't map one onto the other.

## What to use instead

| Need                         | What to use                                                                                                                             |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Review the audit trail       | Use [Review the audit trail](https://docs.uptiq.ai/platform-guides/admin/agents-and-evidence/review-the-audit-trail) in Control Center. |
| Query user action events     | Call `get_audit_trail_logs` through the MCP endpoint.                                                                                   |
| Review AI Gateway operations | Use `GET /audit-logs/ai-gateway` for the model, latency, and cost. It isn't a replacement for the configuration-change trail.           |

## Developer notes

| Situation                    | What to do                                                                                                           |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| Call MCP from an HTTP client | Send JSON-RPC in a `POST` request. There isn't a REST equivalent for the user action trail.                          |
| Verify account-key support   | Use the MCP flow. `initialize`, `tools/list`, and `get_audit_trail_logs` return `200` with an account API key in QA. |

## Related

* [Review the audit trail](https://docs.uptiq.ai/platform-guides/admin/agents-and-evidence/review-the-audit-trail) — as a screen
* [Export activity data](/cookbooks/platform-admin/agents-and-evidence/export-activity-for-review.md)
* [Remove a user's access](/cookbooks/platform-admin/give-people-access/remove-someones-access.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.uptiq.ai/cookbooks/platform-admin/agents-and-evidence/show-who-changed-what.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
