> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# List a package's audit events

> Returns every audit event recorded against the package, newest first, a page at a time.



## OpenAPI

````yaml /api-reference/openapi.json get /api/v1/packages/{packageId}/audit-events
openapi: 3.0.3
info:
  title: Flowsign API
  version: 1.0.0
  description: >-
    Public v1 API for Flowsign. Every endpoint is authenticated with a Bearer
    API key (prefix `fsk_`). Errors use `{ error, details? }`; success responses
    wrap payload data as `{ data }`.


    An organisation is divided into workspaces. A key is issued for one
    workspace and acts there on every request (see `GET /api/v1/workspaces`);
    `X-Workspace-Id` is optional and may only name that workspace. Packages,
    templates, contacts and members are scoped to the key's workspace.
servers:
  - url: https://my.flowsign.app
    description: Production
security:
  - ApiKey: []
paths:
  /api/v1/packages/{packageId}/audit-events:
    get:
      tags:
        - Packages
      summary: List a package's audit events
      description: >-
        Returns every audit event recorded against the package, newest first, a
        page at a time.
      operationId: getPackagesByPackageIdAudit-events
      parameters:
        - schema:
            type: string
          required: true
          name: packageId
          in: path
        - schema:
            type: integer
            minimum: 1
            default: 1
            description: Which page of results to return, counting from 1.
            example: 1
          required: false
          name: page
          in: query
        - schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 25
            description: How many events per page, from 1 to 100.
            example: 25
          required: false
          name: pageSize
          in: query
        - schema:
            type: string
            description: >-
              The workspace the key was issued for, as returned by `GET
              /api/v1/workspaces`. Optional: omitting it acts in the key's
              workspace, and any other id is rejected with 401.
          required: false
          name: x-workspace-id
          in: header
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      auditEvents:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              description: The event's id.
                              example: cmg4v9d3m0009s7xhj4l6n2q0
                            eventType:
                              type: string
                              description: >-
                                The event's action name, such as package_sent,
                                document_uploaded or package_voided.
                              example: package_sent
                            actorEmail:
                              type: string
                              nullable: true
                              description: >-
                                The email of the member or recipient who caused
                                the event, or null for system events.
                              example: tom.rangi@studiophoenix.co.nz
                            recipientSessionId:
                              type: string
                              nullable: true
                              description: >-
                                The signing session the event belongs to, or
                                null when it concerns the package as a whole.
                              example: null
                            metadata:
                              nullable: true
                              description: >-
                                Event-specific details as a JSON object, or null
                                when the event carries none.
                              example:
                                recipientCount: 2
                            createdAt:
                              type: string
                              description: >-
                                When the event happened, as an ISO 8601
                                timestamp.
                              example: '2026-09-21T02:15:00.000Z'
                          required:
                            - id
                            - eventType
                            - actorEmail
                            - recipientSessionId
                            - createdAt
                        description: The events on this page, newest first.
                      totalCount:
                        type: integer
                        minimum: 0
                        description: >-
                          How many events the package has in total, across every
                          page.
                        example: 12
                      page:
                        type: integer
                        minimum: 1
                        description: The page returned, counting from 1.
                        example: 1
                      pageSize:
                        type: integer
                        minimum: 1
                        description: The page size applied.
                        example: 25
                    required:
                      - auditEvents
                      - totalCount
                      - page
                      - pageSize
                required:
                  - data
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '402':
          description: Caller's plan does not include this feature (publicApi / webhooks)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: API key present but caller lacks the required permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No package with that id is visible to the caller
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Request failed schema validation; details keyed by field
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see `Retry-After`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: What went wrong, in plain words.
          example: 'Missing permission: canSendPackages'
        details:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
          description: >-
            Validation problems keyed by field path. Present only on 422
            responses.
          example:
            recipients.0.email:
              - Invalid email
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: fsk_*

````