# AI access log (https://developers.asip.io/docs/ai-access-log)

My Account → AI access log shows every read your API keys made as you, which key made it, and whether ASIP served it.

> **Status: Available on request.** API keys, the read-only Data API, the MCP server (with an API key) and signed webhooks are live on app.asip.io. Developer access is off by default for every company: ask ASIP to enable it for yours (https://developers.asip.io/docs/how-to-get-access). One-click OAuth sign-in for AI connectors (claude.ai, ChatGPT, Copilot) is not available yet; use an API key. The changelog at https://developers.asip.io/docs/changelog says when each part becomes available.

Every API key belongs to one person, and reads as that person. The **AI access log** lets that person
see exactly what their keys did. Open it in ASIP from **My Account → AI access log → View AI access
log**.

## What you see

A list of every call your API keys made as you, **newest first, 50 to a page**. Use **Older entries**
to go back and **Newest entries** to return to the top. Times are shown in UTC.

Each entry shows:

| Line           | What it says                                                                                                                                                                                       |
| -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| What was asked | The AI tool and the query, in words, for example *Run an ASIP query — CAPA plans* or *OSHA 300 log*. A request refused before anything was read says *A request refused before anything was read*. |
| Outcome        | **Served**, **Refused** with its code (for example `Refused · restricted`), or **Download started** for a CSV export.                                                                              |
| Which key      | *API key "name" (prefix…)*: the key's name and the start of the key shown when it was created, never the secret.                                                                                   |
| When and how   | The time, the kind of entry, whether it came through the **REST API** or **MCP**, and for a served read, how many records it returned.                                                             |

The kinds of entry are:

* **Data read**: a Data API call, or the data read behind an AI tool call.
* **AI tool call**: a call to one of the [MCP tools](/docs/mcp-reference#the-five-tools). An
  `asip_run_query` call therefore appears twice: once as the tool call your AI made, and once as the
  data read ASIP served for it.
* **CSV export downloaded**: an [`asip_export_csv`](/docs/mcp-reference#asip_export_csv) link was used
  to download a file. An export link that was refused (used already, or the key had lost access)
  appears as a refusal.
* **Refused before any read**: a request ASIP refused before reading anything.

## What you do not see

* **Record content.** The log records the facts of each call (which query, how many records, the
  outcome), never the records themselves.
* **Anyone else's activity.** The list holds your own entries only. Nobody else's keys appear in it,
  and it cannot be widened from the address bar.
* **Secrets.** A key is named by its name and prefix only.

## What to do with it

If you see a call you do not recognise, revoke the key straight away in **My Account → Developer
access**, and tell your company admin. See [When a key stops working](/docs/authentication#when-a-key-stops-working).

The AI access log is shown to people who sign in to a company in ASIP. It is a personal view of
ASIP's audit log, which records every call whatever the outcome.
