Skip to content

Audit events

Audit events are GitLab’s record of who changed what, kept for compliance. These actions list them and read one, at each of the three levels GitLab keeps them: the instance, a group and a project. The instance level needs an administrator.

  • “Show last week’s audit events for group platform”
  • “Who changed the settings of project 42 yesterday?”
  • “List instance audit events since 2026-09-01”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as audit_event.get_group, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_audit_event with action set to the action’s name, such as get_group, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_get_group_audit_event, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 6:

  • Free: 0
  • Premium: 6
  • Ultimate: 6

Read-only actions: 6 of 6, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.

ActionIndividual
audit_event.get_groupgitlab_get_group_audit_event
audit_event.get_instancegitlab_get_instance_audit_event
audit_event.get_projectgitlab_get_project_audit_event
audit_event.list_groupgitlab_list_group_audit_events
audit_event.list_instancegitlab_list_instance_audit_events
audit_event.list_projectgitlab_list_project_audit_events

Get a single group-level audit event by group_id and ID. Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also: audit_event.list_group, audit_event.get_project, audit_event.get_instance.

  • Meta-tool: gitlab_audit_event, action get_group
  • Individual tool: gitlab_get_group_audit_event
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
event_idintegeryesAudit event ID
group_idstring/integeryesGroup ID or URL-encoded path

Get a single instance-level audit event by ID (administrator only). Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also: audit_event.list_instance, audit_event.get_group, audit_event.get_project.

  • Meta-tool: gitlab_audit_event, action get_instance
  • Individual tool: gitlab_get_instance_audit_event
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
event_idintegeryesAudit event ID

Get a single project-level audit event by project_id and ID. Returns: the audit event with author, entity, event name/type, target details, IP address, and timestamp. See also: audit_event.list_project, audit_event.get_group, audit_event.get_instance.

  • Meta-tool: gitlab_audit_event, action get_project
  • Individual tool: gitlab_get_project_audit_event
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
event_idintegeryesAudit event ID
project_idstring/integeryesProject ID or URL-encoded path

List group-level audit events for a group. Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also: audit_event.get_group, audit_event.list_project, audit_event.list_instance.

  • Meta-tool: gitlab_audit_event, action list_group
  • Individual tool: gitlab_list_group_audit_events
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
created_afterstringnoReturn events created after this date (ISO 8601 YYYY-MM-DD)
created_beforestringnoReturn events created before this date (ISO 8601 YYYY-MM-DD)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.

List instance-level audit events (administrator only). Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also: audit_event.get_instance, audit_event.list_group, audit_event.list_project.

  • Meta-tool: gitlab_audit_event, action list_instance
  • Individual tool: gitlab_list_instance_audit_events
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
created_afterstringnoReturn events created after this date (ISO 8601 YYYY-MM-DD)
created_beforestringnoReturn events created before this date (ISO 8601 YYYY-MM-DD)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.

List project-level audit events for a project. Returns: audit events with author, entity, event name/type, details, timestamps, and pagination metadata. See also: audit_event.get_project, audit_event.list_group, audit_event.list_instance.

  • Meta-tool: gitlab_audit_event, action list_project
  • Individual tool: gitlab_list_project_audit_events
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
created_afterstringnoReturn events created after this date (ISO 8601 YYYY-MM-DD)
created_beforestringnoReturn events created before this date (ISO 8601 YYYY-MM-DD)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.