The Activity Logs API provides programmatic access to your account’s security history. Use it to retrieve detailed logs of security-related activities across your Stripe account, including API key management, user invitations, role changes, authentication, and money movement configuration.
With the Activity Logs API, you can:
- Monitor API key lifecycle events for security auditing.
- Track user access changes and role modifications.
- Create custom alerting systems for suspicious activities.
- Integrate activity data with your security information and event management (SIEM) system.
Get started
Authenticate requests to the Activity Logs API using a secret API key with the Activity logs permission set to Read. Include the Stripe-Version: 2026-09-30. header in all requests.
Tracked action types
The following sections describe the types of security events the Activity Logs API tracks.
API key actions
api_: When a new API key is createdkey_ created api_: When an API key is deletedkey_ deleted api_: When an API key is modifiedkey_ updated api_: When an API key’s secret is viewedkey_ viewed
Activity Logs might not include API key rotation events for every account. When included, a rotation produces an api_ action for the old key and an api_ action for the replacement key.
Available since April 1, 2026.
User invitation actions
user_: When a user invitation is sentinvite_ created user_: When a user invitation is revokedinvite_ deleted user_: When a user accepts an invitationinvite_ accepted
Available since April 1, 2026.
User role actions
user_: When user roles are modifiedroles_ updated user_: When user roles are removedroles_ deleted
Note
User role actions capture changes made through the Stripe Dashboard, SCIM, and SSO. The details.user_roles.source property identifies how a role change was made.
Available since April 1, 2026. Coverage of role changes made through SCIM or SSO is available since August 12, 2026.
SSO actions
sso_: SSO (SAML) was configured for the account.settings_ created sso_: SSO (SAML) settings were updated.settings_ updated sso_: SSO (SAML) configuration was removed.settings_ deleted sso_: A domain was verified for SSO.domain_ verified
Available since October 5, 2026.
SCIM group actions
scim_: A SCIM group’s details were updated.group_ updated scim_: A SCIM group was deleted.group_ deleted scim_: A member was added to a SCIM group.group_ member_ added scim_: A member was removed from a SCIM group.group_ member_ removed scim_: Roles for a SCIM group were changed.group_ roles_ updated
Available since October 5, 2026.
User profile actions
user_: A user changed their email address.email_ changed user_: A user verified their email address.email_ verified user_: A user changed the phone number on their Express account.express_ phone_ number_ changed
Available since October 5, 2026.
Account security actions
anomaly_: Anomaly detection settings were updated.detection_ settings_ updated two_: A two-step authentication requirement was enabled.step_ authentication_ mandate_ enabled two_: A two-step authentication requirement was disabled.step_ authentication_ mandate_ disabled
Available since October 5, 2026.
Authentication actions
user_: The user changed their account password.password_ changed user_: The user set a password on their account.password_ initialized user_: A password reset was requested for the user.password_ reset_ requested user_: The user successfully reset their password.password_ reset_ succeeded user_: A password reset attempt failed due to an invalid one-time code.password_ reset_ failed user_: A user connected a Google account for sign-in.google_ account_ connected user_: A user disconnected their Google account.google_ account_ disconnected user_: The user added a two-step authentication method.two_ step_ authentication_ method_ added user_: The user updated an existing two-step authentication method.two_ step_ authentication_ method_ updated user_: A two-step authentication method was removed from the account.two_ step_ authentication_ method_ removed user_: A two-step authentication method was reset.two_ step_ authentication_ method_ reset user_: The user used an emergency backup code to disable two-step authentication.two_ step_ authentication_ backup_ code_ used user_: An account admin requested a two-step authentication reset for another user.two_ step_ authentication_ reset_ requested user_: The user registered a passkey.passkey_ added user_: The user removed a passkey.passkey_ removed user_: The user renamed a passkey.passkey_ updated user_: The user upgraded a device to a passkey.passkey_ upgraded user_: An identity verification challenge failed.auth_ challenge_ failed
Available since October 5, 2026.
Payout actions
payout_: A payout destination was added.destination_ added payout_: A payout destination was updated.destination_ updated payout_: A payout destination was removed.destination_ removed payout_: The Connect platform disabled the connected account’s ability to edit its payout schedule.schedule_ edits_ disabled payout_: The Connect platform enabled the connected account’s ability to edit its payout schedule.schedule_ edits_ enabled manual_: The Connect platform disabled the connected account’s ability to create manual payouts.payouts_ disabled manual_: The Connect platform enabled the connected account’s ability to create manual payouts.payouts_ enabled
Available since October 9, 2026.
Issuing actions
issuing_: Issuing was activated for the account.activated issuing_: An Issuing card was created.card_ created issuing_: An Issuing card was updated.card_ updated issuing_: An Issuing card’s sensitive details (card number, CVC, or PIN) were viewed.card_ sensitive_ details_ viewed issuing_: An Issuing cardholder was created.cardholder_ created issuing_: An Issuing cardholder was updated.cardholder_ updated issuing_: An Issuing dispute was created.dispute_ created issuing_: An Issuing dispute was submitted for review.dispute_ submitted issuing_: An Issuing dispute was updated.dispute_ updated issuing_: An Issuing balance transfer was created to move funds between balances.balance_ transfer_ created
For card, cardholder, dispute, and balance transfer actions, the related_object property references the affected Issuing resource.
Available since October 9, 2026.
Stripe retains activity logs for 6 months.
Access your activity
Each Activity Log object contains details about the security event, including the actor, timestamp, affected resources, and contextual metadata.
Use the List activity logs endpoint to retrieve a paginated list of activity logs. Filter results by action group or specific action types to narrow your search.
The response returns results in ascending order by the created timestamp. Events appear in a list response 10 minutes after they occur.
Pagination
The list response always includes next_, even at the end of the available logs. Store the URL and use it to poll for new events for up to 10 days, after which you must restart pagination from the beginning.
The page token must be used with the same filters as the original request. Changing filters while reusing a page token returns a 400 error with invalid_.
Retrieve a specific activity log
Use the Retrieve an activity log endpoint to fetch a single activity log by its ID.
The endpoint returns a not_ error if the record doesn’t exist, falls outside the 6-month retention window, or doesn’t belong to the requested account.
Use cases
You can use your activity detail to help with the following business needs:
- Security monitoring: Build automated alerts for sensitive account changes. Poll the list endpoint to detect unexpected API key creation, unusual role changes, or access from unfamiliar actors.
- Compliance reporting: Export activity logs to generate audit reports for compliance frameworks such as SOC 2 or PCI DSS. Each log entry includes timestamps, actor details, and affected resource information.