Events

The Events API gives you read access to the audit trail of your OneLogin account: logins, provisioning runs, changes to users, apps, roles and policies, and more. Use it to feed a SIEM, build reports, or investigate a specific user, app, or IP address.

API v2 events are served by a dedicated events service that uses cursor-based pagination, so paging through large result sets is fast at any depth. See Event Resource for the response format and the differences from API v1.