Median

Logs

Find what the agent, the tools, the knowledge base and your team did, and what each run cost.

Updated Oct 1, 20269 minute read

Logs is in the sidebar for everyone. Only owners and admins can read it. Members see "Only admins and owners can see logs." See Roles.

The header

ControlDoes
ExploreOpens the explorer on the Activity log. See Explore from Logs.
Range menuSets the time range
Pause or play buttonTurns live updates off or on
RefreshReads the list again, up to now
ExportDownload CSV or Download JSON

The line under the title spells the range out.

Pick a range

OptionSpan
Last hour1 hour
Last 24 hours24 hours
Last 7 days7 days
Last 30 days30 days. The page opens on this range.
Last 90 days90 days
Custom range…A dialog with From and To dates. The range runs from midnight on the first day to the end of the last, on your clock.
  • Presets count back from the moment the list was read, not from midnight.
  • Future dates cannot be picked. An end before the start reads "Pick an end date on or after the start."
  • Selecting a bar on the volume chart also sets a custom range. The menu then reads Custom range.

Live updates

The list reads up to a fixed moment, so paging holds still while new events arrive.

ButtonTooltipState
Pause glyph, Pause live updatesPause new eventsLive. New events wait behind a pill at the top of the list, like 3 new events. Press it to show them.
Play glyph, Resume live updatesShow new events as they happenPaused. No pill appears.
Disabled, Live updates, offlineReconnecting. Showing the last events receivedThe connection dropped
Disabled, Live updates, offThis range has endedA custom range that ends in the past

The pill counts up to 100 and then reads 100+ new events. Refresh and the pill both move the list, the chart and the counts up to now.

Filters

FilterValuesURL key
Search eventsMatches the event label, summary, error, event name and tool names. Up to 160 characters.search
UsageOnly entries that used billed work, meaning model tokens, emails or web pages. Plan changes and credit purchases are not usage.usage=1
TypeAI, API, App access, Background work, Billing, Conversations, Customers, Email, Integrations, Keys, Knowledge, Settings, Signals, Team, Tools, Webhookscategory
StatusSucceeded, Failed, Denied, Pending, Canceledoutcome
Done byTeam, Agent, Assistant, Customer, API, Systemby
PersonA teammate. Someone who has left reads Former member.actorId
One conversationShown after Show in list in an entry's drawerconversationId

Each filter takes one value. Clear resets every filter and any custom range, and keeps the preset.

StatusMeans
SucceededIt worked. Rows show a green dot and no pill.
FailedIt went wrong. The entry keeps the error.
DeniedIt was refused, like a declined tool call, an API limit or running out of credits
PendingIt waits on someone or something, like an approval or a retry
CanceledIt stopped before it finished, like an approval that expired
Done byMeans
TeamA teammate, in the dashboard or signed in through the CLI or MCP
AgentThe support agent, in a customer's conversation
AssistantThe assistant, acting for a teammate
CustomerSomeone on your site
APIA Median key
SystemMedian's own background work

The volume chart

The card above the list shows how many events match, like 1,204 events, and 24 bars across the range.

  • Hover a bar for its time span and count.
  • Select a bar to narrow the range to that slice.
  • A count that hit the reading cap carries a plus, and the tooltips say "at least".
  • The card folds away when nothing matches.

The list

Events run newest first, in one band per day. Each band names the day and counts the rows loaded for it. The list loads 100 events at a time. Load older events reads the next page.

A row reads left to right. The status dot, the area icon, the event label, the summary and a pill for anything but success come first. Who did it, what it used, one number and the time follow.

NumberShown for
Cost, like $0.0042Billed work. Free means nothing was charged. Empty while the price is still pending.
HTTP 502Entries with an HTTP status, like API errors
Duration, like 1.2s or 340 msAnything else that timed itself
Empty stateMeans
No matches in the latest eventsEach page reads at most 1,000 entries, and none of them matched. Keep looking reads further back.
No events match these filtersNothing in the range matches. Clear filters resets them.
No events in the last 30 daysNothing was logged in the range. The preset's name fills in.
No events yetThe organization has no entries

Entries do not expire. Once the range reaches the first entry, the foot of the list reads History starts and the date.

Folded rows

Three or more entries of the same event in a row fold into one line, like 5 Tool calls.

  • The line names what the entries were about, like the tools called.
  • It counts how the entries went. For billed work it also shows their total usage and cost.
  • Its dot takes the worst outcome, so one failure inside shows red.
  • A run broken by another event becomes two runs.
  • Folding is off while a Type filter or a search is set.

Opening a folded line shows the outcome counts, the time span, a Usage total for billed work, and Entries. An entry opens in its place with Back to 5 tool calls.

An entry

Press a row to open its drawer. The title is the event label.

SectionHolds
TopOutcome and area chips, the summary, and the time, like "Sat, Sep 26, 2026, 2:05:22 PM EDT · 3 minutes ago"
ErrorWhat went wrong, when something did
UsageBilled work only. Cost, Tokens with input and output under it, Emails, Pages, Duration and Steps.
Linked toThe Conversation, Doc, Signal and Customer it touched. Each opens its page. Anything deleted since is left out.
DetailsBy, AI feature, Credits, Duration, Tool, Tools used, HTTP status, Changes and Changed. Only what the entry recorded. Credits here means credits bought, like a top-up. Billed work shows its cost and duration under Usage instead.
ReferenceEvent, the event name like tools.call, and Entry ID. Both copy when pressed.
This conversationEverything else logged about the same conversation, oldest first, up to the latest 50. Show in list narrows the list to it.

Only this person, beside a teammate under By, narrows the list to that teammate.

Billed rows show tokens, emails or pages, and their cost. View all under Recent usage in Settings → Billing opens Logs with Usage on. Plans and prices are on Billing.

Share a view

Every filter, the range and the open entry live in the URL. Copy the address to share the view.

https://median.sh/logs?range=7d&category=tools&outcome=failed
KeyValues
range1h, 24h, 7d, 30d, 90d. Left out for 30d.
from, toA custom range, in Unix milliseconds. Wins over range.
categoryai, api, access, system, billing, conversations, customers, email, integrations, keys, knowledge, settings, signals, team, tools, webhooks
outcomesuccess, failed, denied, pending, canceled
bymember, agent, assistant, customer, api, system
eventAn entry ID. Opens its drawer.

A shared link reads up to the moment it is opened.

Export

Export saves every event that matches the filters and range, not only the rows loaded.

FormatHolds
Download CSVColumns at, outcome, event, message, summary, error, actorKind, actorId, durationMs, conversationId. at is ISO 8601 in UTC.
Download JSON{ snapshot, count, records }, with every field of each entry
  • Files are named like median-logs-2026-09-26.csv.
  • While it runs, the button reads like Exporting 1,200….
  • One export reads up to 500 pages of 200 events. With a search, a Done by filter or two filters at once, a page can hold fewer matches, so the export can reach that limit with far fewer events. Past it the export fails with "Too many events to export at once. Narrow the range and try again."
  • If paging stalls, it fails with "The export stopped partway. Try again."
  • A failure shows an Export failed callout with the reason.

What is logged

Events sit in the areas the Type filter lists.

TypeEvents
AIAgent reply, Assistant reply, AI run, Handed to the team, Resolved automatically
ToolsTool call, Approval requested, Tool call approved, Tool call declined, Approval expired, Tools synced, Tool endpoint changed, Tool switched on or off, Tool suggested
KnowledgeKnowledge sync, Knowledge import, Page read, Knowledge indexing, Doc created, Doc edited, Doc deleted, Change suggested, Suggestion approved, Suggestion dismissed
ConversationsConversation deleted, Outreach sent
CustomersCustomer deleted
SignalsSignal filed, Signals merged, Signal deleted, Marked as spam, Issue sync, Code linked
IntegrationsIntegration connected, Integration disconnected, Integration delivery
WebhooksWebhook added, Webhook changed, Webhook removed, Webhook delivery
EmailEmail settings changed, Incoming email, Email sent, Email delivery
TeamMember invited, Invite revoked, Member joined, Role changed, Member removed, Member left
KeysKey created, Key revoked, Key rotated
App accessApp access approved, App access removed
SettingsAgent settings changed, Workspace settings changed, Help site changed
BillingPlan changed, Credits added, Out of credits, Plan needed
APIAPI limit reached, API error
Background workBackground work failed

An AI run shows what it was for instead of its event label, like Sentiment check or Analytics question.

EventLogged when
Agent reply, Assistant reply, AI runEvery model call made for your organization, with tokens, credits, duration and tools used
Tool callOnce per call, with its duration and any error. A request to see the customer's screen logs once it is answered: Success with a picture, Denied when they choose not to share, Failed when none arrives
Tools syncedA sync added, updated or removed tools, failed with a new error, or recovered
Knowledge syncA sync changed documents, or failed with a new error
Page read, Email sentOnce per charge. A website import adds its pages to its own Knowledge import entry instead.
Knowledge indexing, Incoming email, Email deliveryOnly when something failed
Webhook deliveryAn endpoint stops answering, and again when it answers. Not every retry.
Integration deliveryA Slack or Discord message could not be delivered. The same error logs at most once an hour.
Out of creditsPaid work was refused because credits ran out. At most once an hour. The summary names the service, like "AI stopped".
Plan neededPaid work was refused because the plan doesn't include it, such as AI on Explore. At most once an hour.
API limit reachedA request was refused with 429. See Rate limits.
API errorA request failed on Median's side with a 5xx status
Background work failedA background job failed. The same failure logs at most once an hour.

What is never logged

  • Page views, reads and opened settings, including reading this page
  • API requests that succeed, and API refusals other than rate limits
  • Background work that succeeded
  • Prompts, model answers and model names
  • What customers wrote, and their names and email addresses. Entries link conversations and customers by ID and name them when opened.

Summaries and errors are one line of up to 300 characters. Anything shaped like a secret reads [hidden]. A URL keeps only its scheme and host.

Explore from Logs

Explore opens the explorer on the Activity log, counted per day and split by outcome, over every day the range touches. Its samples are "Failed events by area", "Credits used by AI feature, per day" and "Slowest tools". Queries, datasets and charts are on Analytics.

Over the API, CLI and MCP

Owners and admins can read the log from outside the app.

SurfaceCalls
APIGET /v1/logs and GET /v1/logs/{id}
CLImedian logs list and median logs get <id>
MCPmedian.billing.logs({ filters, paginationOpts }) and median.billing.logEntry({ id })
  • GET /v1/logs takes from, to, search, category, outcome, actorKind, actorId, conversationId and usage=true. The range defaults to the last 30 days.
  • Pages hold up to 200 entries, default 100. Keep snapshot fixed across pages. A page can come back short, or empty, before isDone is true.
  • GET /v1/logs/{id} returns the entry, what it touched, and up to 50 entries about the same conversation.
median logs list --category tools --outcome failed
curl "https://api.median.sh/v1/logs?category=tools&outcome=failed" \
  -H "Authorization: Bearer $MEDIAN_KEY"

Every flag is in the CLI reference.

Still need help?

    Esc