# Audit Logs

<a id="get-api-v1-audit-logs"></a>
#### `GET /api/v1/audit-logs`

*List audit log entries*

Paginated audit log read. Filter by `event_type` (enum) and/or `username`. HMAC requests require the `audit:read` scope; browser admin sessions get implicit access.

**Query parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `limit` | integer | no | minimum=1; maximum=200 |
| `offset` | integer | no | minimum=0 |
| `event_type` | AuditEventType | no | — |
| `username` | string | no | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_PaginatedAuditLogsData_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "limit": 0,
    "logs": [
      "..."
    ],
    "offset": 0,
    "total": 0
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/audit-logs
```

---
