List audit events
/audit-eventsReturns entries from your organisation's audit trail, newest first: changes, exports and views of
personal data, by people, API keys, OAuth apps, kiosks and Agoo itself. The trail is append-only and
hash-chained: each entry's previous_hash is the hash of the entry before it. Returns entries from your
plan's audit-trail period (3 years on Pro, up to 7 years on Enterprise). Moving to a lower plan doesn't
delete older entries: they're kept, hidden, and come back when you move up.
Scope: audit:read · Plan: Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: audit:read
Query Parameters
How many items to return, from 1 to 100.
1 <= value <= 10025The next_cursor from the previous page. Leave it out for the first page.
length <= 512Only entries with this action.
length <= 100Only entries by this actor (a person, API key, OAuth app or device ID).
length <= 64Only entries about this object.
length <= 64Only entries at this site.
^site_[0-7][0-9a-hjkmnp-tv-z]{25}$"site_01kjpt3yw0fz0v414608h9x65s"Only entries at or after this time.
date-timeOnly entries before this time.
date-timeResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/audit-events?limit=25&action=visit.approved&actor_id=person_01kjsesxm0e4zbyvkr7bcfxbfg&target_id=visit_01m4k5z4j0fxbte6sn6e8tpgza&occurred_after=2026-10-14T00%3A00%3A00Z&occurred_before=2026-10-15T00%3A00%3A00Z"{ "data": [ { "id": "audit_01m4ww0fyreptvwxm0pnrd2g7y", "occurred_at": "2026-10-14T09:31:03Z", "action": "visitor.viewed", "actor": { "type": "person", "id": "person_01kjsevr70faybwar4k1wjj6x2", "name": "Abena Asante" }, "target": { "type": "visitor", "id": "visitor_01krdtb870fxj8t6ntdtcxwdk5" }, "site_id": "site_01kjpt3yw0fz0v414608h9x65s", "ip_address": "203.0.113.24", "metadata": {}, "hash": "f791fe1a375e72c16f76040c67bc77f83a4e623256782b3cfb3cb7af688b914a", "previous_hash": "b31cca067d1a4ed2302fc503d63175eeabbd824dc26e7a02cff396dedfdfa6ab" }, { "id": "audit_01m4ww0ezgek8v2detdf9c6yw0", "occurred_at": "2026-10-14T09:31:02Z", "action": "visit.approved", "actor": { "type": "person", "id": "person_01kjsesxm0e4zbyvkr7bcfxbfg", "name": "Kwame Mensah" }, "target": { "type": "visit", "id": "visit_01m4k5z4j0fxbte6sn6e8tpgza" }, "site_id": "site_01kjpt3yw0fz0v414608h9x65s", "ip_address": null, "metadata": { "channel": "push" }, "hash": "b31cca067d1a4ed2302fc503d63175eeabbd824dc26e7a02cff396dedfdfa6ab", "previous_hash": "dbb717b137008058d4b3d85acac51886bbece91b07982cfb9d326cb2384e00c2" } ], "next_cursor": "b3BhcXVlLWN1cnNvcg", "has_more": true}visitor.erased Webhook
A visitor's personal data is erased, through the API, the console or a data subject request. Delete any copy you hold of this visitor's personal data. Agoo sends this as a signed `POST` to every enabled endpoint subscribed to `visitor.erased` (or `*`). Verify the signature, return any `2xx` within 15 seconds, and de-duplicate on `webhook-id`.
List visit types GET
Returns your organisation's visit types: the six built-in types, renamed or not, and the types your admins have added, such as "Parent pickup" or "Vendor". Built-in types come first, then the others by name. Use a type's `key` as `type` when you create a visit, and its `form_id` to read the questions that type asks. Types that are turned off (`enabled: false`) are included so you can still read older visits; leave them out with `enabled=true`. Types open for pre-registration (`pre_registration: true`) carry a `public_form`: the questions a visitor answers when they pre-register, without the fields your staff fill in. **Scope:** `forms:read` · **Plan:** Pro and Enterprise in live mode; every plan in test mode. **Publishable keys:** allowed. They see only the types that are turned on and open for pre-registration, so a pre-registration form can offer exactly those.