# Activity

> The audit history: who added, moved, approved or commented, when, and through which channel or agent.

- **URL**: https://orshot.com/docs/api-reference/approvals-events-list

---

The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs [`read` access](/docs/api-reference/approvals-overview#access-levels).
See [Enterprise pricing](https://orshot.com/pricing) to get access.

The audit history: who added, moved, approved or commented, when, and through which channel or agent. Filter by template, approval flow or event kind; newest first.

Results come in pages: pass `nextCursor` back as `cursor` until it is `null`.

## Endpoint

```markdown tab="Endpoint"
https://api.orshot.com/v1/activity
```

## Query Parameters

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `templateId` | Integer | No | Only this template's history. |
| `flow` | String | No | Only this approval flow's history. A number is an id, anything else a slug. |
| `kind` | String | No | One of `approval.item.added`, `approval.item.moved`, `approval.item.removed`, `approval.decision.created`, `approval.decision.revoked`, `approval.edit.started`, `approval.override.used`, `approval.render.blocked`, `template.edited`, `template.render_gate.changed`, `comment.created`, `comment.resolved`, `comment.hidden`, `approval_flow.created`, `approval_flow.updated`, `approval_flow.archived`, `approval_flow.duplicated`, `workspace_group.updated`. |
| `cursor` | String | No | Cursor from the previous page's nextCursor. A cursor the API didn't write starts again from the first page. Up to 200 characters. |
| `limit` | Integer | No | Results per page (1 to 100). Default `50`. |

## Headers

| Header | Required | Description |
| ------ | -------- | ----------- |
| `Authorization` | Yes | `Bearer <API key or OAuth token>` |
| `x-workspace-id` | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
| `X-Orshot-User-Id` | No | API keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below. |
| `X-Session-Id` | No | Groups the calls of one agent or MCP session in the activity history. |

## Acting for a Team Member

With an API key, you can send `X-Orshot-User-Id` with the user id of an owner, admin or member of the workspace to make this call for them. The answer then follows both the key's access level and that person's own access. See [acting for a team member](https://orshot.com/docs/api-reference/approvals-overview#acting-for-a-team-member).

## Request

**Request**
```js
await fetch("https://api.orshot.com/v1/activity?templateId=101&limit=2", {
  headers: { Authorization: "Bearer <ORSHOT_API_KEY>" },
});
```

**Response**
```json
{
  "events": [
    {
      "id": 36,
      "kind": "comment.created",
      "label": "Jordan Lee commented on 'Spring sale banner'",
      "actor": {
        "id": "b5d2e8f1-7a3c-4b69-9e0d-3c8a1f6b2e45",
        "name": "Jordan Lee",
        "email": "jordan@acme.com",
        "role": "member"
      },
      "via": "api",
      "source": "api",
      "client": null,
      "subject": {
        "type": "template",
        "id": 101
      },
      "flowId": null,
      "itemId": null,
      "payload": {
        "template": {
          "id": 101,
          "name": "Spring sale banner"
        },
        "commentId": 5,
        "parentId": null,
        "excerpt": "Note to self: swap the photo",
        "mentioned": []
      },
      "createdAt": "2026-09-28T09:30:00.000Z"
    },
    {
      "id": 35,
      "kind": "comment.resolved",
      "label": "Priya Shah resolved a comment on a template",
      "actor": {
        "id": "9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61",
        "name": "Priya Shah",
        "email": "priya@acme.com",
        "role": "member"
      },
      "via": "api",
      "source": "api",
      "client": null,
      "subject": {
        "type": "template",
        "id": 101
      },
      "flowId": null,
      "itemId": null,
      "payload": {
        "commentId": 4
      },
      "createdAt": "2026-09-28T09:30:00.000Z"
    }
  ],
  "nextCursor": "eyJpZCI6MzV9"
}
```

## Response Fields

Responds `200` with:

| Field | Type | Description |
| ----- | ---- | ----------- |
| `events` | Array | List of ActivityEvent, fields below. |
| `events[].id` | Integer | Numeric id. |
| `events[].kind` | Object | `event kind (events.js)`. |
| `events[].label` | String | Readable line. |
| `events[].actor` | Object | One Person or `{ type: api_key, label }` or `{ type: system }`. The team member when an API key acted for one (X-Orshot-User-Id). |
| `events[].postedVia` | Object | `{ type: api_key, id, label }`. Only when an API key acted for a team member: the key it came through. The label then ends with "via API key". |
| `events[].via` | String |  |
| `events[].source` | String | Can be `null`. |
| `events[].client` | String | Can be `null`. |
| `events[].subject` | Object | `{ type, id }`. |
| `events[].flowId` | Integer | Can be `null`. |
| `events[].itemId` | Integer | Can be `null`. |
| `events[].payload` | Object |  |
| `events[].createdAt` | String | ISO 8601 timestamp. |
| `nextCursor` | String | Can be `null`. Pass it back as `cursor` for the next page; `null` on the last page. |

## Error Responses

Every error has the same body: `error`, `code`, `message` and `helpUrl`, plus the fields that apply (`required`, `role`, `context`, `blockers`, `violations`, `issues`, `current`). Branch on `error`; `code` is more specific. See the [error reference](https://orshot.com/docs/error-reference).

| Status Code | Error | Description |
| ----------- | ----- | ----------- |
| 401 | `oauth_token_invalid` | The OAuth token is invalid, expired or revoked. |
| 403 | `api_key_missing` | No `Authorization: Bearer` header. |
| 403 | `permission_denied` | You don't have access to do this. Ask an owner or admin. `code` names the capability, for example `approval.item.decide_denied`; `required` and `role` say what was missing. With `code: insufficient_scope`: the OAuth token lacks `workspace:approvals:read`. With `code: approval.member_header_not_member`: `X-Orshot-User-Id` names someone who isn't an owner, admin or member of the workspace now. With `code: approval.member_header_not_allowed`: an OAuth token sent `X-Orshot-User-Id`. |
| 403 | `plan_required` | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | `enterprise_api_required` | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | `not_found` | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 422 | `validation_failed` | Some fields aren't valid: the fields listed in issues. `issues` lists each field with a path and a reason. |
| 422 | `validation_failed` | With `code: approval.member_header_invalid`: `X-Orshot-User-Id` isn't a user id. |
| 429 | `rate_limit_exceeded` | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | `approvals_unavailable` | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |