Audit logs and Activity answer different questions. Activity tracks what people do in the workspace (configuration changes, new sources, plan changes). Audit logs track what machine credentials—API and MCP tokens—do. Use audit logs to review automated and agent access to your data.
What each line records
Every request leaves a single line with:- Token — which token made the request, and who created it.
- Action — a client-facing name for what was accessed, such as List tables, Run SQL (Data API), Run SQL (MCP), Trigger source run, or Update source.
- Transport — how the request arrived: Data API (HTTP), MCP, or WebSocket.
- Status — Success, Denied, Failed, or Rate limited.
- Time, IP address, and duration.
- For requests that ran a warehouse query: data scanned, data billed, and estimated cost.
Availability by plan
Audit logs are a paid feature, and how far back you can look depends on your plan. Logs are retained for a maximum of 90 days.Upgrading widens the window immediately for logs that were already recorded (for example, Starter → Growth). But nothing is recorded while a workspace is on Free, so if you upgrade from Free, history starts at the moment you upgrade.
Who can see what
Workspace role is what counts: someone who is an admin at the organization level but a plain Member of this workspace sees only their own tokens.
Filter and search
By default the list shows the last 30 days. Narrow it down by:- Period — Last 24 hours, Last 7 days, Last 30 days, or a custom range.
- Status, action, and token.
- Search across the entries.
Inspect a single request
Open any line to see its full detail:- The request — query string, a short allowlist of request headers, and, for MCP tool calls, the tool’s arguments.
- The response — status, content type, and size.
- Query cost, when the request ran SQL: the bytes scanned, the bytes billed, the estimated cost in USD, and timing (how long it queued, planned, and ran).
MCP tool calls
Every tool an MCP token calls is its own line, with the tool name as the action (for example,execute_sql, generate_sql, preview_table). This includes tools that never reach the API and calls the token’s scope refused. Opening a tool call shows its arguments and the requests it triggered.
View logs for one token
From Settings → API Keys or your MCP token, use View logs to open the audit logs filtered to that single token. This is the quickest way to answer “what has this token been doing?” and “how much has it scanned?”.Export
Use Export audit logs to download a Parquet file with one row per request, including the data scanned and estimated cost for every line in the period. This is the right tool for reporting spend per token or loading the trail into a SIEM or warehouse.- Up to 31 days per export, in UTC, within your plan’s window.
- Large periods can take a few minutes to build.
- The download link is available once the export finishes.