Glossary
Reports API (Admin SDK)
The Admin SDK API that returns Google Workspace audit log events (login, token, Gmail, Drive, admin…) as JSON with full parameters.
The Reports API is part of Google's Admin SDK. Its activities.list method returns Google Workspace audit events per application (login, user_accounts, token, gmail, drive, admin, saml, takeout, groups…) as JSON. Each activity carries the time, actor, IP, network information (ASN, region code) and every event parameter.
For investigations it is the most complete export route. It isn't capped like console exports, and it keeps stable API event names. Gmail requests are limited to 30-day windows. GAM's gam report command wraps it.
See: how to export Google Workspace audit logs and the API reference.