> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nekt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit logs

> Every request made with an MCP or API token in your workspace.

**Audit logs** record every request made with an **MCP or API token** in your workspace—one line per request. When an AI client or script uses one of your tokens to list tables, run SQL, trigger a source, or call an MCP tool, it shows up here with who the token belongs to, what was accessed, and what came back.

Find them in **Settings → Audit logs**.

<Note>
  Audit logs and [Activity](/workspace/activity) answer different questions. **Activity** tracks what **people** do in the workspace (configuration changes, new sources, plan changes). **Audit logs** track what **machine credentials**—API and MCP tokens—do. Use audit logs to review automated and agent access to your data.
</Note>

## What each line records

Every request leaves a single line with:

* **Token** — which token made the request, and who created it.
* **Action** — a client-facing name for what was accessed, such as *List tables*, *Run SQL (Data API)*, *Run SQL (MCP)*, *Trigger source run*, or *Update source*.
* **Transport** — how the request arrived: Data API (HTTP), MCP, or WebSocket.
* **Status** — Success, Denied, Failed, or Rate limited.
* **Time**, **IP address**, and **duration**.
* For requests that ran a warehouse query: **data scanned**, **data billed**, and **estimated cost**.

<Warning>
  The **response body is never recorded**. Nekt keeps the status, content type, and size of a response—so you can see how much data a token read—but never the data itself.
</Warning>

## Availability by plan

Audit logs are a paid feature, and how far back you can look depends on your plan. Logs are retained for a maximum of 90 days.

| Plan | History available |
| - | - |
| Free | Not available |
| Starter | Last 7 days |
| Growth | Last 30 days |
| Custom | Last 90 days |

<Note>
  Upgrading widens the window immediately for logs that were already recorded (for example, Starter → Growth). But nothing is recorded while a workspace is on Free, so if you upgrade from Free, history starts at the moment you upgrade.
</Note>

## Who can see what

| Role | Sees |
| - | - |
| Owner / Admin | Every line in the workspace |
| Member | Only the lines of tokens they created |

Workspace role is what counts: someone who is an admin at the organization level but a plain Member of this workspace sees only their own tokens.

## Filter and search

By default the list shows the **last 30 days**. Narrow it down by:

* **Period** — Last 24 hours, Last 7 days, Last 30 days, or a custom range.
* **Status**, **action**, and **token**.
* **Search** across the entries.

Use **Clear filters** to reset. An empty result for a range beyond your plan's window (or older than 90 days) means there is simply no data there—not an error.

## Inspect a single request

Open any line to see its full detail:

* The **request** — query string, a short allowlist of request headers, and, for MCP tool calls, the tool's arguments.
* The **response** — status, content type, and size.
* **Query cost**, when the request ran SQL: the bytes scanned, the bytes billed, the estimated cost in USD, and timing (how long it queued, planned, and ran).

## MCP tool calls

Every tool an MCP token calls is its own line, with the tool name as the action (for example, `execute_sql`, `generate_sql`, `preview_table`). This includes tools that never reach the API and calls the token's scope refused. Opening a tool call shows its arguments and the requests it triggered.

## View logs for one token

From **Settings → API Keys** or your MCP token, use **View logs** to open the audit logs filtered to that single token. This is the quickest way to answer "what has this token been doing?" and "how much has it scanned?".

## Export

Use **Export audit logs** to download a **Parquet file** with one row per request, including the data scanned and estimated cost for every line in the period. This is the right tool for reporting spend per token or loading the trail into a SIEM or warehouse.

* Up to **31 days** per export, in UTC, within your plan's window.
* Large periods can take a few minutes to build.
* The download link is available once the export finishes.

## Programmatic access

Everything on this page is also available through the Platform API, including incremental pulls and exports. See [Token access logs](/platform-api/token-access-logs/list) in the Platform API reference.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.