Get user activity grouped by endpoint
Returns user activity data grouped by endpoint for the last 30 (completed) UTC days. Pass workspace_id to scope the response to a single workspace. Pass group_by=workspace to split each row per workspace and include workspace_id on every item; by default rows are aggregated across workspaces and workspace_id is not returned. Activity recorded before workspace resolution existed is permanently attributed to the account default workspace (no backfill is possible). Management key required.
Authorizations
API key as bearer token in Authorization header
Query Parameters
Filter by a single UTC date in the last 30 days (YYYY-MM-DD format).
"2025-08-24"
Filter by API key hash (SHA-256 hex string, as returned by the keys API).
"abc123def456..."
Filter by org member user ID. Only applicable for organization accounts.
"user_abc123"
Set to 'workspace' to split each row per workspace and include workspace_id on every item. Omitted by default, in which case rows are aggregated across workspaces (by date, model, and endpoint) and workspace_id is not returned — preserving the historical response shape.
workspace "workspace"
Filter by workspace ID (UUID). Returns only activity attributed to that workspace. The workspace must belong to the authenticated account.
"550e8400-e29b-41d4-a716-446655440000"
Response
Returns user activity data grouped by endpoint
List of activity items