List what has happened in one group
- Bearer token
- Permission
group-challenge/read - Per organization
Lists what has happened in one group that one of your students is an active member of, newest first: the group created, confirmed, members added, files uploaded, steps submitted, the work sent. It is the log every member of the group can read; notes and details the organizers keep are not included.
Only your own students are named. Every other person — the other members, the teacher, the organizers — is shown by role alone, with studentId and name set to null, and a file’s name only when one of your students uploaded it. What your account did for a student is actor.role: partner with yours: true, and the student in onBehalfOf.
A page at a time: limit is 20 by default and at most 100.
Parameters
Path parameters
| Name | Type | Description |
|---|---|---|
organizationIdrequired | stringpattern ^[0-9a-f]{24}$ | The organization’s Example |
challengeIdrequired | string | The group challenge’s |
groupIdrequired | string | The group’s |
Query parameters
| Name | Type | Description |
|---|---|---|
pageoptional | number | Page number. Defaults to 1. Example |
limitoptional | number | Items per page. Defaults to 20, max 100. Example |
Responses
200 OK
Success: message is "Activity fetched successfully.".
Body
successbooleanrequiredAlways
trueon a success.one of
truemessagestringrequiredexample
Activity fetched successfully.paginationobject · PaginationMetarequiredWhere one page sits in the whole list.
4 fields of pagination
pagenumberrequiredThe page returned, counting from 1.
min
1example1limitnumberrequiredItems per page: the
limityou sent, 20 if you sent none, and never more than 100.min
1max100example20totalnumberrequiredItems across every page.
min
0example57totalPagesnumberrequiredPages at this
limit:total / limit, rounded up.min
0example3
dataarray of GroupChallengeActivityResponserequired9 fields of each item
_idstringrequiredThe entry’s id.
example
6650a1b2c3d4e5f6a7b8c9f0atstringrequiredWhen it happened (UTC).
format
date-timeexample2026-10-20T16:02:11.000ZeventstringrequiredWhat happened. New values may be added; ignore one you do not know.
one of
group_createdgroup_renamedmember_addedmember_removedgroup_finalizedgroup_deletedgroup_restoredstep_unlockedfile_uploadedfile_replacedfile_deletedfile_rejectedstep_submittedstep_reopenedfinal_submittedfinal_revertedexample
step_submittedactorobject · GroupChallengePersonResponserequiredWho did it. Your account acting for a student is
partnerwithyours: true.4 fields of actor
rolestringrequiredstudent,teacher,administrator(the organizers),partner(an API account, acting for a student) orsystem. New values may be added.one of
studentteacheradministratorpartnersystemexample
studentstudentIdobjectnullablerequiredThe student’s
_id, only when they are yours; otherwisenull.example
6650a1b2c3d4e5f6a7b8c9d0nameobjectnullablerequiredTheir name, only when they are yours; otherwise
null.example
Ada LovelaceyoursbooleanrequiredWhether this is one of your students, or your account acting for one.
example
true
viastringrequiredWhere it was done: the panel, the app, an AI assistant (
mcp), this API, or the system itself. New values may be added; ignore one you do not know.one of
panelappmcpapisystemexample
apionBehalfOfobject · GroupChallengePersonResponsenullablerequiredWhom it was done for: the student a partner acted for, or the teacher an administrator acted for.
nullotherwise.4 fields of onBehalfOf
rolestringrequiredstudent,teacher,administrator(the organizers),partner(an API account, acting for a student) orsystem. New values may be added.one of
studentteacheradministratorpartnersystemexample
studentstudentIdobjectnullablerequiredThe student’s
_id, only when they are yours; otherwisenull.example
6650a1b2c3d4e5f6a7b8c9d0nameobjectnullablerequiredTheir name, only when they are yours; otherwise
null.example
Ada LovelaceyoursbooleanrequiredWhether this is one of your students, or your account acting for one.
example
true
subjectobject · GroupChallengePersonResponsenullablerequiredThe student it was about (added or removed), or
null.4 fields of subject
rolestringrequiredstudent,teacher,administrator(the organizers),partner(an API account, acting for a student) orsystem. New values may be added.one of
studentteacheradministratorpartnersystemexample
studentstudentIdobjectnullablerequiredThe student’s
_id, only when they are yours; otherwisenull.example
6650a1b2c3d4e5f6a7b8c9d0nameobjectnullablerequiredTheir name, only when they are yours; otherwise
null.example
Ada LovelaceyoursbooleanrequiredWhether this is one of your students, or your account acting for one.
example
true
stepobject · GroupChallengeActivityStepResponsenullablerequiredThe step it was about, or
null.2 fields of step
_idstringrequiredThe step’s id.
example
6650a1b2c3d4e5f6a7b8c9eeorderobjectnullablerequiredIts position when the entry was written.
example
1
fileobject · GroupChallengeActivityFileResponsenullablerequiredThe file it was about, or
null.2 fields of file
_idstringrequiredThe file’s id.
example
6650a1b2c3d4e5f6a7b8c9efnameobjectnullablerequiredIts name, only when one of your students did what the entry records; otherwise
null.example
proposal.pdf
Headers
X-RateLimit-LimitintegerRequests your account may make to this operation per window (100).
X-RateLimit-RemainingintegerRequests left in the current window.
X-RateLimit-ResetintegerSeconds until the current window ends.
Example
{
"success": true,
"message": "Activity fetched successfully.",
"pagination": {
"page": 1,
"limit": 20,
"total": 57,
"totalPages": 3
},
"data": [
{
"_id": "6650a1b2c3d4e5f6a7b8c9f0",
"at": "2026-10-20T16:02:11.000Z",
"event": "step_submitted",
"actor": {
"role": "student",
"studentId": "6650a1b2c3d4e5f6a7b8c9d0",
"name": "Ada Lovelace",
"yours": true
},
"via": "api",
"onBehalfOf": {
"role": "student",
"studentId": "6650a1b2c3d4e5f6a7b8c9d0",
"name": "Ada Lovelace",
"yours": true
},
"subject": {
"role": "student",
"studentId": "6650a1b2c3d4e5f6a7b8c9d0",
"name": "Ada Lovelace",
"yours": true
},
"step": {
"_id": "6650a1b2c3d4e5f6a7b8c9ee",
"order": 1
},
"file": {
"_id": "6650a1b2c3d4e5f6a7b8c9ef",
"name": "proposal.pdf"
}
}
]
}400 Bad request
bad_request:challengeIdis not 24 hexadecimal digits.bad_request:groupIdis not 24 hexadecimal digits.
When
bad_requestchallengeIdis not 24 hexadecimal digits.bad_requestgroupIdis not 24 hexadecimal digits.
Example
{
"error": {
"code": "bad_request",
"documentation_url": "https://hub.main-team.org/api/errors#bad_request",
"message": "Invalid value for 'challengeId': expected ObjectId.",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.
401 Unauthorized
unauthorized: The token is missing or malformed, is not signed with your account’s apiSecret, breaks the iat and exp rules, has expired or been revoked, or its account is not active. All of these answer the same.
When
unauthorizedThe token is missing or malformed, is not signed with your account’s
apiSecret, breaks theiatandexprules, has expired or been revoked, or its account is not active. All of these answer the same.
Example
{
"error": {
"code": "unauthorized",
"documentation_url": "https://hub.main-team.org/api/errors#unauthorized",
"message": "Authentication is required or the provided credentials are invalid.",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.
403 Forbidden
forbidden: The token is valid, but no role on your account allows group-challenge/read on the organization in the path, or a role denies it.
When
forbiddenThe token is valid, but no role on your account allows
group-challenge/readon the organization in the path, or a role denies it.
Example
{
"error": {
"code": "forbidden",
"documentation_url": "https://hub.main-team.org/api/errors#forbidden",
"message": "Insufficient role permissions",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.
404 Not found
not_found:organizationIdis not the_idof an organization.not_found: Group challenges are not switched on for this organization. The answer is the one an unknown path gets; nothing was read.not_found: No group challenge of this organization has this id, or it is not published: a draft, archived or deleted challenge answers the same.not_found: No group of this challenge has this id that one of your students is an active member of: a missing group, a deleted one and another account’s get the same answer.
When
not_foundorganizationIdis not the_idof an organization.not_foundGroup challenges are not switched on for this organization. The answer is the one an unknown path gets; nothing was read.
not_foundNo group challenge of this organization has this id, or it is not published: a draft, archived or deleted challenge answers the same.
not_foundNo group of this challenge has this id that one of your students is an active member of: a missing group, a deleted one and another account’s get the same answer.
Example
{
"error": {
"code": "not_found",
"documentation_url": "https://hub.main-team.org/api/errors#not_found",
"message": "Organization not found!",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.
429 Too many requests
too_many_requests: Your account has made more than 100 requests to this operation in the current 60-second window. Wait the seconds in Retry-After before sending again.
When
too_many_requestsYour account has made more than 100 requests to this operation in the current 60-second window. Wait the seconds in
Retry-Afterbefore sending again.
Headers
Retry-AfterintegerSeconds to wait before sending again; a request sent sooner is refused too.
Example
{
"error": {
"code": "too_many_requests",
"documentation_url": "https://hub.main-team.org/api/errors#too_many_requests",
"message": "Too many requests to this operation. Wait the number of seconds in Retry-After, then try again.",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.
500 Internal error
internal_error: Something failed on our side. Retry later, and quote request_id if it goes on.
When
internal_errorSomething failed on our side. Retry later, and quote
request_idif it goes on.
Example
{
"error": {
"code": "internal_error",
"documentation_url": "https://hub.main-team.org/api/errors#internal_error",
"message": "An unexpected error occurred.",
"request_id": "0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8e"
}
}Fields of the error body
errorobject · ErrorDetailrequiredWhat went wrong.
5 fields of error
codestringrequiredA stable machine code: branch on this. Each one is explained at
documentation_url.one of
invalid_emailbad_requestunauthorizedforbiddennot_foundconflictpayload_too_largeunsupported_media_typeunprocessable_entitytoo_many_requestsinternal_errorservice_unavailableexample
not_foundmessagestringrequiredWritten for a person, and may change: never branch on it.
example
Not found!documentation_urlstringrequiredWhere this code is explained.
format
uriexamplehttps://hub.main-team.org/api/errors#not_foundrequest_idstringrequiredThis request’s id, also sent as the
X-Request-Idresponse header: the one you sent, when it was acceptable, or else one the API made. Quote it when you report a problem.example
0b5c6d0e-8f7a-4b1c-9d2e-3f4a5b6c7d8edetailsobjectPresent only where an operation says so, and then with the shape that operation documents — the rows it could not accept, say. Treat it as absent everywhere else, and ignore a
detailsyou do not recognise.