openapi: 3.0.1 info: title: HubSpot Account Audit Logs description: Basepom for all HubSpot Projects version: 2026-09 x-hubspot-product-tier-requirements: marketing: FREE sales: FREE service: FREE cms: FREE commerce: FREE crmHub: FREE dataHub: FREE x-hubspot-api-use-case: You want to build an internal tool for your compliance team to regularly monitor the activity of employees in your company accessing data in your HubSpot account. x-hubspot-introduction: The account activity API allows you to retrieve login history and security activity for your HubSpot account. servers: - url: https://api.hubapi.com tags: - name: Basic paths: /account-info/2026-09/activity/audit-logs: get: tags: - Basic summary: Retrieve audit logs description: Retrieve activity history for user actions related to approvals, content updates, CRM object updates, security activity, and more (Enterprise only). Learn more about [activities included in audit log exports](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history-in-a-centralized-audit-log?hubs_content=knowledge.hubspot.com/account-management/view-and-export-account-activity-history&hubs_content-cta=centralized%20audit%20log#data-included-in-the-centralized-audit-log). operationId: get-/account-info/2026-09/activity/audit-logs parameters: - name: actingUserId in: query description: '' required: false style: form explode: true schema: type: array items: type: integer format: int32 - name: after in: query description: The paging cursor token of the last successfully read resource will be returned as the `paging.next.after` JSON property of a paged response containing more results. required: false style: form explode: true schema: type: string - name: fillFinalTimestamp in: query description: '' required: false style: form explode: true schema: type: boolean - name: limit in: query description: The maximum number of results to display per page. required: false style: form explode: true schema: type: integer format: int32 - name: occurredAfter in: query description: '' required: false style: form explode: true schema: type: string format: date-time - name: occurredBefore in: query description: '' required: false style: form explode: true schema: type: string format: date-time - name: sort in: query description: '' required: false style: form explode: true schema: type: array items: type: string responses: '200': description: successful operation content: application/json: schema: $ref: '#/components/schemas/CollectionResponsePublicApiUserActionEventForwardPaging' default: description: '' $ref: '#/components/responses/Error' security: - oauth2: - account-info.security.read /account-info/2026-09/activity/login: get: tags: - Basic summary: Retrieve login activity description: Retrieve logs of user actions related to [login activity](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history#account-login-history). operationId: get-/account-info/2026-09/activity/login parameters: - name: after in: query description: The paging cursor token of the last successfully read resource will be returned as the `paging.next.after` JSON property of a paged response containing more results. required: false style: form explode: true schema: type: string - name: limit in: query description: The maximum number of results to display per page. required: false style: form explode: true schema: type: integer format: int32 - name: userId in: query description: '' required: false style: form explode: true schema: type: integer format: int32 responses: '200': description: successful operation content: application/json: schema: $ref: '#/components/schemas/CollectionResponsePublicLoginAuditForwardPaging' default: description: '' $ref: '#/components/responses/Error' security: - oauth2: - account-info.security.read /account-info/2026-09/activity/security: get: tags: - Basic summary: Retrieve security history description: Retrieve logs of user actions related to [security activity](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history#security-activity-history). operationId: get-/account-info/2026-09/activity/security parameters: - name: after in: query description: The paging cursor token of the last successfully read resource will be returned as the `paging.next.after` JSON property of a paged response containing more results. required: false style: form explode: true schema: type: string - name: fromTimestamp in: query description: '' required: false style: form explode: true schema: type: integer format: int64 - name: limit in: query description: The maximum number of results to display per page. required: false style: form explode: true schema: type: integer format: int32 - name: toTimestamp in: query description: '' required: false style: form explode: true schema: type: integer format: int64 - name: userId in: query description: '' required: false style: form explode: true schema: type: integer format: int32 responses: '200': description: successful operation content: application/json: schema: $ref: '#/components/schemas/CollectionResponseHydratedCriticalActionForwardPaging' default: description: '' $ref: '#/components/responses/Error' security: - oauth2: - account-info.security.read components: schemas: ActingUser: required: - userId type: object properties: userEmail: type: string description: The email address of the user who performed the action. userId: type: integer description: The user's unique ID. format: int32 CollectionResponseHydratedCriticalActionForwardPaging: required: - results type: object properties: paging: $ref: '#/components/schemas/ForwardPaging' results: type: array items: $ref: '#/components/schemas/HydratedCriticalAction' CollectionResponsePublicApiUserActionEventForwardPaging: required: - results type: object properties: paging: $ref: '#/components/schemas/ForwardPaging' results: type: array items: $ref: '#/components/schemas/PublicApiUserActionEvent' CollectionResponsePublicLoginAuditForwardPaging: required: - results type: object properties: paging: $ref: '#/components/schemas/ForwardPaging' results: type: array items: $ref: '#/components/schemas/PublicLoginAudit' Error: required: - category - correlationId - message type: object properties: category: type: string description: The error category context: type: object additionalProperties: type: array items: type: string description: Context about the error condition example: '{invalidPropertyName=[propertyValue], missingScopes=[scope1, scope2]}' correlationId: type: string description: A unique identifier for the request. Include this value with any error reports or support tickets format: uuid example: aeb5f871-7f07-4993-9211-075dc63e7cbf errors: type: array description: further information about the error items: $ref: '#/components/schemas/ErrorDetail' links: type: object additionalProperties: type: string description: A map of link names to associated URIs containing documentation about the error or recommended remediation steps message: type: string description: A human readable message describing the error along with remediation steps where appropriate example: An error occurred subCategory: type: string description: A specific category that contains more specific detail about the error description: Represents an error response returned by the API when an operation fails. This component is used in various endpoints to provide detailed information about the error encountered. example: message: Invalid input (details will vary based on the error) correlationId: aeb5f871-7f07-4993-9211-075dc63e7cbf category: VALIDATION_ERROR links: knowledge-base: https://www.hubspot.com/products/service/knowledge-base ErrorDetail: required: - message type: object properties: code: type: string description: The status code associated with the error detail context: type: object additionalProperties: type: array items: type: string description: Context about the error condition example: '{missingScopes=[scope1, scope2]}' in: type: string description: The name of the field or parameter in which the error was found. message: type: string description: A human readable message describing the error along with remediation steps where appropriate subCategory: type: string description: A specific category that contains more specific detail about the error description: Represents detailed information about an error that occurred in the API. This component is used to provide additional context and specifics about errors, typically as part of an error response. ForwardPaging: type: object properties: next: $ref: '#/components/schemas/NextPage' description: Paging information for forward-only pagination. Contains the next page reference when more results are available; omitted or empty on the last page. HydratedCriticalAction: required: - createdAt - id - type - userId type: object properties: actingUser: type: string description: Email address of the user associated with the activity. countryCode: type: string description: The approximate country code createdAt: type: string description: The time the activity took place. format: date-time id: type: string description: The activity's unique ID. infoUrl: type: string description: A link to the URL where the action was taken in the account. ipAddress: type: string description: IP address where the activity originated. location: type: string description: The approximate location where the activity took place. objectId: type: string description: The ID of the affected object. regionCode: type: string description: The approximate region code type: type: string description: The type of activity. enum: - ACCEPTANCE_TEST - ACCOUNT_ADDED_TO_MULTI_ACCOUNT_ORGANIZATION - ACCOUNT_REMOVED_FROM_MULTI_ACCOUNT_ORGANIZATION - ADD_ADMIN_PERMISSIONS - ADD_ADMIN_USER - ADD_SINGLE_SIGN_ON - ADD_TWO_FACTOR_AUTHENTICATION - ADD_USER - ADD_WEBHOOK_IN_WORKFLOW - ALLOWED_GEOLOCATIONS_DISABLED - ALLOWED_GEOLOCATIONS_ENABLED - ALLOWED_LOGIN_METHODS_DELETE - ALLOWED_LOGIN_METHODS_UPDATE - ATTACHMENT_LOGGING_DISABLED - ATTACHMENT_LOGGING_ENABLED - AUTOMATED_INACTIVE_USER_DEACTIVATION_DISABLED - AUTOMATED_INACTIVE_USER_DEACTIVATION_ENABLED - BOTS_WEBHOOK_POST - BOTS_WEBHOOK_UPDATE - BOTS_WEBHOOK_VIEWED - BULK_EMAIL_DOMAIN_CHANGE - CHANGE_AD_EVENT_CONSENT_SETTING - CHANGE_AD_EVENT_DATA_SHARING_SETTING - CHANGE_PASSWORD - CONTACT_DATA_EXPORT - CONTACT_OWNER_AUTO_ASSIGN_DISABLED - CONTACT_OWNER_AUTO_ASSIGN_ENABLED - DATA_ACCESS_REQUEST_SUBMITTED - DATA_BACKUP_CREATED - DATA_BACKUP_DOWNLOADED - DATA_BACKUP_SCHEDULE_CREATED - DATA_BACKUP_SCHEDULE_DELETED - DATA_BACKUP_SCHEDULE_UPDATED - DATA_RESTORE_COMPLETED - DATA_SHARING_CONNECTION_ADDED - DATA_SHARING_CONNECTION_REMOVED - DATASET_SYNC - DEACTIVATE_USER - DOMAIN_BASED_INVITE_CREATED - DOMAIN_BASED_INVITE_REMOVED - DOMAIN_BASED_INVITES_DISABLED - DOMAIN_BASED_INVITES_ENABLED - EMAIL_LOGGING_SYNC_SET_ALL - EMAIL_LOGGING_SYNC_SET_CONTACTS - EMAIL_LOGGING_SYNC_SET_REPLIES - EMAIL_TRACKING_DISABLED - EMAIL_TRACKING_ENABLED - EXPORT - EXPORT_APPROVAL - EXPORT_DOWNLOAD - EXPORT_USERS - FORM_SUBMISSIONS_EXPORT - GDPR_DELETE - GDPR_TOGGLE_DISABLED - GDPR_TOGGLE_ENABLED - HAPIKEY_CREATE - HAPIKEY_DEACTIVATE - HAPIKEY_VIEW - HUBSPOT_EMPLOYEE_ACCESS_DISABLED - HUBSPOT_EMPLOYEE_ACCESS_ENABLED - IMPERSONATE_USER - IMPORT - INSTALL_INTEGRATION - IP_RESTRICTIONS_DISABLED - IP_RESTRICTIONS_ENABLED - JOINED_PORTAL_VIA_DOMAIN_BASED_INVITE - LEGAL_BASIS_REQUIREMENT_DISABLED - LEGAL_BASIS_REQUIREMENT_ENABLED - MANUAL_PASSWORD_RESET_EMAIL_SEND - MANUAL_REGISTRATION_EMAIL_SEND - MARKETING_CONTACTS_APP_SETTINGS_DISABLED - MARKETING_CONTACTS_APP_SETTINGS_ENABLED - MERGE_REVERT - MODIFY_WEBHOOK_IN_WORKFLOW - MULTI_ACCOUNT_REPORTING_CONNECTION_ADDED - MULTI_ACCOUNT_REPORTING_CONNECTION_REMOVED - MULTI_ACCOUNT_WORKFLOWS_CONNECTION_ADDED - MULTI_ACCOUNT_WORKFLOWS_CONNECTION_REMOVED - NEVER_LOG_FOR_PORTAL_ADDITION - NEVER_LOG_FOR_PORTAL_DELETION - NEVER_LOG_FOR_USER_ADDITION - NEVER_LOG_FOR_USER_DELETION - PASSKEY_ADDED - PASSKEY_DELETED - PAYMENT_ACCOUNT_CREATION - PAYMENT_ACCOUNT_INFO_UPDATE - PAYMENT_BANK_ACCOUNT_CHANGE - PAYMENT_ONBOARDING_LINK_SEND - PERSONAL_ACCESS_KEY_CREATE - PERSONAL_ACCESS_KEY_DEACTIVATE - PERSONAL_ACCESS_KEY_ROTATE - PERSONAL_ACCESS_KEY_VIEW - PRIVATE_APP_ACCESS_TOKEN_CREATE - PRIVATE_APP_ACCESS_TOKEN_DEACTIVATE - PRIVATE_APP_ACCESS_TOKEN_ROTATE - PRIVATE_APP_ACCESS_TOKEN_VIEW - PRIVATE_APP_CLIENT_SECRET_VIEW - PRIVATE_APP_CLIENT_SECRET_WRITE - PRIVATE_APP_SCOPE_GROUPS_UPDATE - PRODUCTION_DEPLOYMENT - PROPERTY_HISTORY_REVISION - PUBLIC_APP_CLIENT_SECRET_VIEW - PUBLIC_APP_CLIENT_SECRET_WRITE - REACTIVATE_USER - REMOVE_ADMIN_PERMISSIONS - REMOVE_ADMIN_USER - REMOVE_SINGLE_SIGN_ON - REMOVE_TWO_FACTOR_AUTHENTICATION - REMOVE_USER - REQUIRE_SINGLE_SIGN_ON - RESTRICTED_LIST_ADDED_TO_CONTENT - SANDBOX_CREATION - SANDBOX_DELETION - SANDBOX_SYNC - SANDBOX_SYNC_TO_PRODUCTION - SECRET_ADDED_TO_SERVERLESS_FUNCTION - SENSITIVE_DATA_DISABLED - SENSITIVE_DATA_ENABLED - SEQUENCE_CLONED - SEQUENCE_CREATED - SEQUENCE_ENROLLMENT_INITIATED - SEQUENCE_ENROLLMENT_STATE_CHANGED - SEQUENCE_MODIFIED - SERVICE_KEY_AUTO_ROTATE - SERVICE_KEY_CREATE - SERVICE_KEY_DEACTIVATE - SERVICE_KEY_PERMISSIONS_UPDATE - SERVICE_KEY_REVEAL - SERVICE_KEY_ROTATE - SERVICE_KEY_ROTATION_SCHEDULE_REMOVED - SERVICE_KEY_ROTATION_SCHEDULE_SET - SERVICE_KEY_ROTATION_SCHEDULE_UPDATED - SMTP_TOKEN_CREATED - SMTP_TOKEN_DELETED - SMTP_TOKEN_PASSWORD_RESET - SMTP_TOKEN_RETRIEVED - TEAM_ADDED - TEAM_DELETED - TEAM_USER_ADDED - TEAM_USER_DELETED - TEMPLATE_DELETED - TEMPLATE_MODIFIED - TOUCHLESS_PURCHASE - TWO_FACTOR_PROTECTED_ENDPOINT_BLOCKED - TWO_FACTOR_PROTECTED_ENDPOINT_SUCCEEDED - UNIFIED_RESTORE_UNDO_EXECUTION - UNINSTALL_INTEGRATION - UNREQUIRE_SINGLE_SIGN_ON - WEBHOOK_SETTINGS_UPDATE - WEBHOOK_SUBSCRIPTION_CREATE - WEBHOOK_SUBSCRIPTION_UPDATE userId: type: integer description: The user's unique ID. format: int32 NextPage: required: - after type: object properties: after: type: string description: A paging cursor token for retrieving subsequent pages. link: type: string description: A URL that can be used to retrieve the next page results. description: Specifies the paging information needed to retrieve the next set of results in a paginated API response PublicApiUserActionEvent: required: - actingUser - action - category - id - occurredAt type: object properties: actingUser: $ref: '#/components/schemas/ActingUser' action: type: string description: The type of action taken. category: type: string description: The category of the activity. id: type: string description: The login activity's unique ID. occurredAt: type: string description: The time that the action occurred at. format: date-time subCategory: type: string description: The subcategory of the activity. targetObjectId: type: string description: The ID of the impacted object. PublicLoginAudit: required: - id - loginAt - loginSucceeded type: object properties: countryCode: type: string description: The approximate country code of the login email: type: string description: Email address of the user associated with the login. id: type: string description: The login activity's unique ID. ipAddress: type: string description: IP address where the activity originated. location: type: string description: The approximate location where the login activity originated. loginAt: type: string description: The time the login took place. format: date-time loginSucceeded: type: boolean description: Whether the login was successful or not. regionCode: type: string description: The approximate region code of the login userAgent: type: string description: Information about the device used for logging in. userId: type: integer description: The user's unique ID. format: int32 responses: Error: description: An error occurred. content: '*/*': schema: $ref: '#/components/schemas/Error' securitySchemes: developer_hapikey: type: apiKey name: hapikey in: query oauth2: type: oauth2 flows: authorizationCode: authorizationUrl: https://app.hubspot.com/oauth/authorize tokenUrl: https://api.hubapi.com/oauth/v1/token scopes: account-info.security.read: '' external-settings-access: '' private_apps: type: apiKey name: private-app in: header private_apps_legacy: type: apiKey name: private-app-legacy in: header x-hubspot-product-tier-requirements: marketing: FREE sales: FREE service: FREE cms: FREE commerce: FREE crmHub: FREE dataHub: FREE