Audit events
Audit events are GitLab’s record of who changed what, kept for compliance. These actions list them and read one, at each of the three levels GitLab keeps them: the instance, a group and a project. The instance level needs an administrator.
Sample questions
Section titled “Sample questions”- “Show last week’s audit events for group platform”
- “Who changed the settings of project 42 yesterday?”
- “List instance audit events since 2026-09-01”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asaudit_event.get_group, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_audit_eventwithactionset to the action’s name, such asget_group, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_get_group_audit_event, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 6:
- Free: 0
- Premium: 6
- Ultimate: 6
Read-only actions: 6 of 6, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.
| Action | Individual |
|---|---|
audit_event.get_group | gitlab_get_group_audit_event |
audit_event.get_instance | gitlab_get_instance_audit_event |
audit_event.get_project | gitlab_get_project_audit_event |
audit_event.list_group | gitlab_list_group_audit_events |
audit_event.list_instance | gitlab_list_instance_audit_events |
audit_event.list_project | gitlab_list_project_audit_events |
audit_event.get_group
Section titled “audit_event.get_group”Get a single group-level audit event by group_id and ID. Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also:
audit_event.list_group,audit_event.get_project,audit_event.get_instance.
- Meta-tool:
gitlab_audit_event, actionget_group - Individual tool:
gitlab_get_group_audit_event - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
event_id | integer | yes | Audit event ID |
group_id | string/integer | yes | Group ID or URL-encoded path |
audit_event.get_instance
Section titled “audit_event.get_instance”Get a single instance-level audit event by ID (administrator only). Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also:
audit_event.list_instance,audit_event.get_group,audit_event.get_project.
- Meta-tool:
gitlab_audit_event, actionget_instance - Individual tool:
gitlab_get_instance_audit_event - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
event_id | integer | yes | Audit event ID |
audit_event.get_project
Section titled “audit_event.get_project”Get a single project-level audit event by project_id and ID. Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also:
audit_event.list_project,audit_event.get_group,audit_event.get_instance.
- Meta-tool:
gitlab_audit_event, actionget_project - Individual tool:
gitlab_get_project_audit_event - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
event_id | integer | yes | Audit event ID |
project_id | string/integer | yes | Project ID or URL-encoded path |
audit_event.list_group
Section titled “audit_event.list_group”List group-level audit events for a group. Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also:
audit_event.get_group,audit_event.list_project,audit_event.list_instance.
- Meta-tool:
gitlab_audit_event, actionlist_group - Individual tool:
gitlab_list_group_audit_events - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
created_after | string | no | Return events created after this date (ISO 8601 YYYY-MM-DD) |
created_before | string | no | Return events created before this date (ISO 8601 YYYY-MM-DD) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
audit_event.list_instance
Section titled “audit_event.list_instance”List instance-level audit events (administrator only). Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also:
audit_event.get_instance,audit_event.list_group,audit_event.list_project.
- Meta-tool:
gitlab_audit_event, actionlist_instance - Individual tool:
gitlab_list_instance_audit_events - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
created_after | string | no | Return events created after this date (ISO 8601 YYYY-MM-DD) |
created_before | string | no | Return events created before this date (ISO 8601 YYYY-MM-DD) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
audit_event.list_project
Section titled “audit_event.list_project”List project-level audit events for a project. Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also:
audit_event.get_project,audit_event.list_group,audit_event.list_instance.
- Meta-tool:
gitlab_audit_event, actionlist_project - Individual tool:
gitlab_list_project_audit_events - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
created_after | string | no | Return events created after this date (ISO 8601 YYYY-MM-DD) |
created_before | string | no | Return events created before this date (ISO 8601 YYYY-MM-DD) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |