TeamIntegrationLogs
Gets the integration logs for the current team. This method can only be called by Admins.
Select
The TeamIntegrationLogs view returns integration audit log entries for the current team. The AppId, ChangeType, ServiceId, and UserId columns are processed server side with the = operator. All other filters are processed client side.
SELECT * FROM TeamIntegrationLogs SELECT * FROM TeamIntegrationLogs WHERE ChangeType = 'added' SELECT * FROM TeamIntegrationLogs WHERE AppId = 'A012BC34DEF' SELECT * FROM TeamIntegrationLogs WHERE ChangeType = 'disabled' AND UserId = 'U064PUU751Q'
Org-Level Token Considerations
Note: The TeamId pseudo column is only relevant when using an org-level token. Passing this parameter results in an invalid_auth error if the org owner is not part of the team. When you connect with a workspace-level token, the Slack API accepts the TeamId but ignores it and returns data for the authenticated workspace. Filtering on an invalid or empty TeamId therefore does not raise an error and does not return an empty result set.
SELECT * FROM TeamIntegrationLogs WHERE TeamId = 'T0123ABCD'
Service vs Application Logs
Each log entry pertains to either a service or an API application. Service entries populate ServiceId and ServiceType; API-application entries populate AppId and AppType. RSS feed integrations additionally populate IsRssFeed, RssFeedChangeType, RssFeedTitle, and RssFeedUrl.
Disabled Event Reason
When ChangeType is disabled, the Reason column indicates why. Possible values are user, rate_limits, slack, errors, system, admin, api_decline, and deauth.
Limitations
This method can only be called by Admins. Non-admin tokens return access_denied or missing_scope.
Columns
| Name | Type | References | Description |
| ServiceId | Integer | The Id of the service. Present for service-style integrations. | |
| ServiceType | String | The type of service. Present for service-style integrations. | |
| AppId | String | The Id of the Slack app. Present for API-application integrations. | |
| AppType | String | The type of Slack app. Present for API-application integrations. | |
| UserId | String |
Users.Id | The Id of the user who performed the action. |
| UserName | String | The username of the user who performed the action. | |
| Channel | String |
Channels.Id | The channel the integration is associated with, when applicable. |
| Date | Datetime | Unix timestamp of when the log entry was recorded. | |
| ChangeType | String | Type of change. Possible values are added, removed, enabled, disabled, expanded, and updated.
The allowed values are added, removed, enabled, disabled, expanded, updated. | |
| Scope | String | OAuth scopes associated with the integration. | |
| Reason | String | Reason the integration was disabled. Present only on disabled events. Possible values: user, rate_limits, slack, errors, system, admin, api_decline, and deauth. | |
| IsRssFeed | Boolean | Set to true when the log entry pertains to an RSS feed integration. | |
| RssFeedChangeType | String | Change type specific to RSS feed integrations. Present only when IsRssFeed is true. | |
| RssFeedTitle | String | Title of the RSS feed. Present only when IsRssFeed is true. | |
| RssFeedUrl | String | URL of the RSS feed. Present only when IsRssFeed is true. |
Pseudocolumns
Pseudocolumn fields are used in the WHERE clause of SELECT statements and offer more granular control over the data returned from the data source.
| Name | Type | Description | |
| TeamId | String | The Id of the team. Required if org token is used. It is only relevant when you connect with an org-level token. This will be ignored if workspace-level token is used. |