
List audit events via the xAI Management API
Pull xAI team audit events over HTTP when you need automation, paging, or filters beyond the Console table. Official Using Management API documents GET https://management-api.x.ai/audit/teams/{teamId}/events with a management key in the Authorization: Bearer header. Events cover changes to team settings, API keys, team membership, and other administrative actions. The Management API host is https://management-api.x.ai, not https://api.x.ai. Create the management key in the Console under Settings → Management Keys before you call the route.
What you need
A management key with permission to read audit events, the team id for the path, and a shell or client that can send HTTPS GET requests. Management keys are separate from inference API keys — obtain them at console.x.ai → Settings → Management Keys, and confirm your account has Management Keys Read permission on the users page when the Settings entry is missing. For a click-through view of the same Console-side feed, use View xAI Console audit logs. For Cursor Admin API audit pulls (a different product surface), see Fetch team audit logs with the Cursor Admin API. Key lifecycle jobs sit beside Manage API keys with the xAI Management API and Rotate or disable an xAI API key in the Console. More API jobs live on the API hub.
Call the audit events endpoint
- Export the management key and keep it out of chat logs and public repos:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_TEAM_ID="your_team_id"
- List the first page of events:
curl "https://management-api.x.ai/audit/teams/${XAI_TEAM_ID}/events?pageSize=10" \
-H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
- Narrow the query when you know the window or actor. Supported query parameters include
pageSize,pageToken,eventFilter.userId,eventFilter.queryfor full-text description search,eventTimeFromandeventTimeToas ISO 8601 timestamps, andorderByset toTIME_ASCENDINGorTIME_DESCENDING.
curl "https://management-api.x.ai/audit/teams/${XAI_TEAM_ID}/events?pageSize=50&eventTimeFrom=2026-01-01T00:00:00Z" \
-H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
- When the response includes
nextPageToken, request the next page withpageTokenset to that value until the token is absent.
Each event object can include eventTime, eventId, a free-form English description, and a user object with ids and email when populated. Example descriptions look like API key 'Production Key' was created. Validate the management key first with GET https://management-api.x.ai/auth/management-keys/validation if you get unexpected auth failures — that route needs no inference ACLs.
When to use API versus Console
Use the Management API when a SIEM, cron, or incident script should page events without a browser. Use the Console Audit Log when a human needs a quick filter by Description or User during triage. Keep the team id aligned with the Console team picker so the two views describe the same membership and key changes. Zero Data Retention still allows administrative audit events while stripping API request and response content from retention.
Pitfalls
Sending an inference API key to management-api.x.ai fails auth because management keys are a different credential. Omitting pageToken loops on the first page and looks like a short log. Filtering with Cursor Admin API mental models on this host returns nothing useful — that API is a different product. Copying a team id from the wrong Console team mixes two audit histories in one script.