Skip to content
Create account or Sign in
/
Ask AI
Create accountSign in
Get started Payments Revenue Data Platforms and marketplaces Money management Stablecoins Developer resources
More
APIs & SDKsHelp
Overview
Versioning
Changelog
Upgrade your integrationHow API versioning works
Essentials
SDKs
API
Testing
Stripe CLI
Tools
Stripe Dashboard
Stripe Projects
Provisioning
Workbench
Developers Dashboard
Stripe for Visual Studio Code
Terraform
Stripe Discord server
Features
Workflows
Batch jobs
Event destinations
Stripe health alertsFile uploads
AI tools
Agent pluginsModel Context ProtocolAgent skillsStripe Directory
Extend Stripe
Overview
Build Stripe apps
Use apps from Stripe
Build extensions
Custom objects
Security and privacy
Security
Activity logsStripebot web crawler
Privacy
Partners
Partner ecosystem
Partner certification
United States
English (United States)
  1. Home/
  2. Developer resources
Public preview

Activity logsPublic preview

Programmatically access your account's security history.

The Activity Logs API provides programmatic access to your account’s security history. Use it to retrieve detailed logs of security-related activities across your Stripe account, including API key management, user invitations, role changes, authentication, and money movement configuration.

With the Activity Logs API, you can:

  • Monitor API key lifecycle events for security auditing.
  • Track user access changes and role modifications.
  • Create custom alerting systems for suspicious activities.
  • Integrate activity data with your security information and event management (SIEM) system.

Get started

Authenticate requests to the Activity Logs API using a secret API key with the Activity logs permission set to Read. Include the Stripe-Version: 2026-09-30.preview header in all requests.

Tracked action types

The following sections describe the types of security events the Activity Logs API tracks.

API key actions

  • api_key_created: When a new API key is created
  • api_key_deleted: When an API key is deleted
  • api_key_updated: When an API key is modified
  • api_key_viewed: When an API key’s secret is viewed

Activity Logs might not include API key rotation events for every account. When included, a rotation produces an api_key_deleted action for the old key and an api_key_created action for the replacement key.

Available since April 1, 2026.

User invitation actions

  • user_invite_created: When a user invitation is sent
  • user_invite_deleted: When a user invitation is revoked
  • user_invite_accepted: When a user accepts an invitation

Available since April 1, 2026.

User role actions

  • user_roles_updated: When user roles are modified
  • user_roles_deleted: When user roles are removed

Note

User role actions capture changes made through the Stripe Dashboard, SCIM, and SSO. The details.user_roles.source property identifies how a role change was made.

Available since April 1, 2026. Coverage of role changes made through SCIM or SSO is available since August 12, 2026.

SSO actions

  • sso_settings_created: SSO (SAML) was configured for the account.
  • sso_settings_updated: SSO (SAML) settings were updated.
  • sso_settings_deleted: SSO (SAML) configuration was removed.
  • sso_domain_verified: A domain was verified for SSO.

Available since October 5, 2026.

SCIM group actions

  • scim_group_updated: A SCIM group’s details were updated.
  • scim_group_deleted: A SCIM group was deleted.
  • scim_group_member_added: A member was added to a SCIM group.
  • scim_group_member_removed: A member was removed from a SCIM group.
  • scim_group_roles_updated: Roles for a SCIM group were changed.

Available since October 5, 2026.

User profile actions

  • user_email_changed: A user changed their email address.
  • user_email_verified: A user verified their email address.
  • user_express_phone_number_changed: A user changed the phone number on their Express account.

Available since October 5, 2026.

Account security actions

  • anomaly_detection_settings_updated: Anomaly detection settings were updated.
  • two_step_authentication_mandate_enabled: A two-step authentication requirement was enabled.
  • two_step_authentication_mandate_disabled: A two-step authentication requirement was disabled.

Available since October 5, 2026.

Authentication actions

  • user_password_changed: The user changed their account password.
  • user_password_initialized: The user set a password on their account.
  • user_password_reset_requested: A password reset was requested for the user.
  • user_password_reset_succeeded: The user successfully reset their password.
  • user_password_reset_failed: A password reset attempt failed due to an invalid one-time code.
  • user_google_account_connected: A user connected a Google account for sign-in.
  • user_google_account_disconnected: A user disconnected their Google account.
  • user_two_step_authentication_method_added: The user added a two-step authentication method.
  • user_two_step_authentication_method_updated: The user updated an existing two-step authentication method.
  • user_two_step_authentication_method_removed: A two-step authentication method was removed from the account.
  • user_two_step_authentication_method_reset: A two-step authentication method was reset.
  • user_two_step_authentication_backup_code_used: The user used an emergency backup code to disable two-step authentication.
  • user_two_step_authentication_reset_requested: An account admin requested a two-step authentication reset for another user.
  • user_passkey_added: The user registered a passkey.
  • user_passkey_removed: The user removed a passkey.
  • user_passkey_updated: The user renamed a passkey.
  • user_passkey_upgraded: The user upgraded a device to a passkey.
  • user_auth_challenge_failed: An identity verification challenge failed.

Available since October 5, 2026.

Payout actions

  • payout_destination_added: A payout destination was added.
  • payout_destination_updated: A payout destination was updated.
  • payout_destination_removed: A payout destination was removed.
  • payout_schedule_edits_disabled: The Connect platform disabled the connected account’s ability to edit its payout schedule.
  • payout_schedule_edits_enabled: The Connect platform enabled the connected account’s ability to edit its payout schedule.
  • manual_payouts_disabled: The Connect platform disabled the connected account’s ability to create manual payouts.
  • manual_payouts_enabled: The Connect platform enabled the connected account’s ability to create manual payouts.

Available since October 9, 2026.

Issuing actions

  • issuing_activated: Issuing was activated for the account.
  • issuing_card_created: An Issuing card was created.
  • issuing_card_updated: An Issuing card was updated.
  • issuing_card_sensitive_details_viewed: An Issuing card’s sensitive details (card number, CVC, or PIN) were viewed.
  • issuing_cardholder_created: An Issuing cardholder was created.
  • issuing_cardholder_updated: An Issuing cardholder was updated.
  • issuing_dispute_created: An Issuing dispute was created.
  • issuing_dispute_submitted: An Issuing dispute was submitted for review.
  • issuing_dispute_updated: An Issuing dispute was updated.
  • issuing_balance_transfer_created: An Issuing balance transfer was created to move funds between balances.

For card, cardholder, dispute, and balance transfer actions, the related_object property references the affected Issuing resource.

Available since October 9, 2026.

Stripe retains activity logs for 6 months.

Access your activity

Each Activity Log object contains details about the security event, including the actor, timestamp, affected resources, and contextual metadata.

Use the List activity logs endpoint to retrieve a paginated list of activity logs. Filter results by action group or specific action types to narrow your search.

The response returns results in ascending order by the created timestamp. Events appear in a list response 10 minutes after they occur.

Pagination

The list response always includes next_page_url, even at the end of the available logs. Store the URL and use it to poll for new events for up to 10 days, after which you must restart pagination from the beginning.

The page token must be used with the same filters as the original request. Changing filters while reusing a page token returns a 400 error with invalid_fields.

Retrieve a specific activity log

Use the Retrieve an activity log endpoint to fetch a single activity log by its ID.

The endpoint returns a not_found error if the record doesn’t exist, falls outside the 6-month retention window, or doesn’t belong to the requested account.

Use cases

You can use your activity detail to help with the following business needs:

  • Security monitoring: Build automated alerts for sensitive account changes. Poll the list endpoint to detect unexpected API key creation, unusual role changes, or access from unfamiliar actors.
  • Compliance reporting: Export activity logs to generate audit reports for compliance frameworks such as SOC 2 or PCI DSS. Each log entry includes timestamps, actor details, and affected resource information.

Related resources

  • Activity Logs API reference
  • Platform security
  • Release phases
Was this page helpful?
YesNo
  • Need help? Contact Support.
  • Chat with Stripe developers on Discord.
  • Check out our changelog.
  • Questions? Contact Sales.
  • LLM? Read llms.txt.
  • Powered by Markdoc
On this page