API / view-xai-console-audit-logs

API

View xAI Console audit logs

Open the xAI Console audit log when you need a team-admin view of who created keys, changed team settings, or otherwise interacted with the API server from the Console side. Official Security states that team admins can view the audit log at xAI Console → Audit Log, search by Event ID, Description, or User, and narrow results with a date-range time filter. A common Description filter is ListApiKeys when you are tracing key inventory calls. This Console feed is separate from Cursor Admin API audit pulls and from the Grok Bot enterprise dashboard export — stay on console.x.ai for xAI team administration events.

What you need

A team-admin login on the Console for the team you want to inspect, and a clear question such as who created a key yesterday or which admin changed team settings in a window. If Zero Data Retention is enabled on the team, administrative events such as key creation and team changes still appear here, but the content of API requests and responses does not. For a programmatic pull of the same xAI team events, use List audit events via the xAI Management API. For Cursor/Grok Bot control-plane logs instead, see Fetch team audit logs with the Cursor Admin API or View and export Grok Bot audit logs in the dashboard. Browse other API jobs on the API hub.

Open, filter, and read the feed

  1. Sign in to console.x.ai as a team admin and select the team in the team picker.
  2. Open Audit Log from the Console navigation.
  3. Set the time filter to the date range you care about so the table is not flooded with older rows.
  4. Search by Event ID when you already have an id, by Description for free-text matches such as ListApiKeys, or by User when you are tracing one admin.
  5. Open individual rows to read the description and actor details, then export or note Event IDs you need for a ticket or incident write-up.

Use Description search when you know the action family but not the Event ID. Use the time filter first when the window is narrow and you want every event in that span. Combine User plus time when you are reviewing one person's work after a suspected compromise.

How this pairs with key rotation

After you disable or replace a key with Rotate or disable an xAI API key in the Console, reopen Audit Log and confirm the disable, delete, or create events landed for the expected user and team. If you automate inventory later, keep Management API audit pulls and Console UI checks aligned on the same team id so you do not compare two different teams by accident.

Pitfalls

Opening Audit Log on the wrong team in the picker shows a clean feed while the incident team stays untouched. Expecting prompt or completion text under Zero Data Retention fails by design — only administrative events remain. Mixing this Console page with the Cursor enterprise audit dashboard sends you to the wrong product for Bot control-plane events. Skipping the time filter on a busy team buries the row you need under unrelated inventory noise.