Granola API for enterprise: Audit API, usage analytics and compliance archives
October 9
TL;DR: The Granola API gives product teams programmatic access to meeting notes, transcripts, and summaries on Business ($14 per user per month) and Enterprise ($35 per user per month) plans. Enterprise adds an Audit API showing who did what in the workspace, workspace usage analytics, admin controls over what the API can reach, and a Legal Holds API that stops Granola from permanently deleting covered notes. The main uses are tracking adoption, keeping archives that outlast staff changes, and giving IT a workspace activity log. Developers handle the setup, and Granola's API docs cover the details.
As Granola spreads across a product team, three questions usually come up: who can see which notes, how the team is using it, and what happens to the notes when people leave.
The Granola API and the Enterprise audit tools answer all three. This article explains what each does and who it is for, with technical detail kept light.
What the API lets you pull out of Granola
The API reads the same material you see in the app:
- Meeting notes and AI summaries in plain text or markdown
- Full transcripts with speaker labels and timestamps
- Attendees and calendar details
- Folders and where each note lives
- A link back to each note in the Granola web app
Access is controlled by scope. Personal notes covers notes you own or that were shared directly with you. Public notes covers notes visible to everyone in the workspace, such as notes in a folder in the Team space.
Notes are private by default, so nothing appears in the public scope until it sits in a folder everyone can see.
Webhooks notify your systems when a note is generated, edited, or shared, and are available on Business and Enterprise plans.
Which Granola plans include API access
API access is available on Business and Enterprise plans.
| Plan | Price | API access | Webhooks | Audit API and admin controls |
|---|---|---|---|---|
| Basic | $0 | No | No | No |
| Business | $14 per user per month | Yes | Yes | No |
| Enterprise | $35 per user per month | Yes | Yes | Yes |
Any workspace member on Business or Enterprise can create an API key and start pulling meeting data. On Enterprise, admins also get controls for MCP, the API, and integrations.
MCP is a separate connection built for AI assistants like Claude and ChatGPT. It signs in through the browser rather than using an API key, and is available on all plans.
On Basic it covers personal notes from the last 30 days. Enterprise admins can turn MCP on or off for the workspace.
The Audit API shows who did what in your workspace
The Audit API is an activity log for the workspace, available on Enterprise plans. A dedicated Audit API key reads the log and nothing else, so it cannot see any notes, folders, or spaces.
| Question | What the log shows |
|---|---|
| Who opened a note or transcript? | Views by signed-in users only |
| Who can reach a note, and who changed that? | Access granted, removed or changed, and link sharing changes |
| Who joined or left the workspace? | Members added, joined, removed or leaving, and role changes |
| Who signed in? | Sign-ins, failed sign-ins, and logouts |
| How are API keys and MCP being used? | Key creation and use, and MCP tool use |
| What data left Granola? | Data exports and notes transferred out |
| When did Granola transcribe a meeting? | The start and end of each transcription |
The log records reads only from signed-in users, so a missing view is not proof a note went unread. It keeps one year of events, so teams with longer retention needs should copy events into their own system on a schedule.
Security teams can pull these events into a SIEM or other monitoring platform.
For a product manager, it means that when Legal or Security asks who has accessed customer research, the audit log answers it without a manual request.
Usage analytics show how your team uses Granola
Enterprise plans include built-in workspace usage analytics and an admin dashboard covering workspace-level activity: active members, meetings transcribed, and notes created. For custom breakdowns by folder, team, or time period, the API and the audit log fill in the rest. They can answer questions like these:
- How many customer interviews the team ran last quarter, if your interviews live in their own folder
- Whether meeting volume is growing week over week
- How often API keys and MCP tools are being used
- Which folders hold the most notes
Notes data tells you volume, and audit events add sign-ins, API and MCP activity, and how many meetings Granola transcribed.
Count meetings by period
The code below shows how a developer can pull all notes created after a given date. It can also be scoped to a specific folder, which makes it useful for counting interviews in one project area without pulling the whole workspace.
import requests
API_KEY = "grn_YOUR_API_KEY"
BASE_URL = "https://public-api.granola.ai"
HEADERS = {"Authorization": f"Bearer {API_KEY}"}
def list_notes(created_after, folder_id=None):
notes, cursor = [], None
while True:
params = {"created_after": created_after, "page_size": 30}
if folder_id:
params["folder_id"] = folder_id
if cursor:
params["cursor"] = cursor
r = requests.get(f"{BASE_URL}/v1/notes", headers=HEADERS, params=params)
r.raise_for_status()
data = r.json()
notes.extend(data["notes"])
if not data["hasMore"]:
return notes
cursor = data["cursor"]From that list you can count notes by week, or run it once per folder for a breakdown by folder. These figures show activity because they count notes created, and folder counts show where notes live, not which team made them.
Compliance archives keep meeting records after people leave
A compliance archive is a copy of meeting notes, summaries, and transcripts that your own team controls. The API returns all three, and Granola discards audio after transcription, so an archive holds text only.
For archives that need to keep running after staff changes, use a workspace API key. Admins create it, it belongs to the workspace rather than a person, and it keeps working if the admin who made it leaves.
It reads public notes and notes in spaces where API access is turned on, but not private notes. A note's private notes come back only through the key of the person who wrote them.
On Enterprise, admins set a workspace-wide policy for transcript retention and auto-deletion. On Basic and Business, each person sets their own.
A Data Processing Addendum (DPA) is available on all plans. Granola is SOC 2 Type 2 certified as of July 2025, with security documentation available for procurement.
Enterprise workspaces can use the Legal Holds API, which lets an eDiscovery or case-management system place, update, and release holds. While a hold is active, Granola does not permanently delete the notes, transcripts, or attachments of the people it covers.
For whoever owns that workspace, that means customer interview notes and research tied to a matter are preserved automatically, with no manual export needed.
A hold can cover the whole workspace, named people, or both. To turn it on, email hey@granola.so.
How to get started
Setup is handled by a developer, but the process starts with a plan decision and a key created in Granola's settings. The steps below cover both, along with the technical notes your developer will need.
Getting access to the API takes five steps
- Pick a plan. Business or Enterprise gives you API access. Enterprise adds admin controls over scopes and integrations.
- Set scopes on Enterprise. A workspace admin chooses which scopes members can use at Settings → Workspace → General → API access for members.
- Create a key. Individuals create personal keys at Settings → Connectors → API keys. Admins create workspace-level keys at Settings → Connectors → Workspace API keys, and Audit API keys at Settings → Connectors → Audit API keys.
- Hand it to a developer. Pass the key alongside the API docs. Store it in a secrets manager — not in code.
- Test on a small folder. There is no sandbox environment. Start with a dedicated test folder with a few notes before connecting to live data.
Note: key revocation is permanent and cannot be undone.
Notes for your developer
- Personal and workspace API keys share the same rate limit, applying per user or per workspace depending on the key's scope. Check the API docs for current limits.
- The Audit API key draws from the same rate limit pool as every other key in the workspace. Run backfills sequentially rather than in parallel to avoid hitting the ceiling.
- Full references: API docs, webhooks guide, Audit API guide, and audit events reference.
The API and audit tools answer the three questions that surface as Granola spreads across a team. Scopes and workspace keys control who can see which notes, usage analytics and audit events show how the team is using Granola, and compliance archives with workspace API keys ensure records outlast staff changes.
Try Granola for free. Download the Mac or Windows app, connect your calendar, and run your next meeting to see it in action. Teams that need API access for audit or archive workflows can upgrade to Business or Enterprise, or get in touch at hey@granola.so.
FAQs
Is the Granola API available on all plans?
No. Business ($14 per user per month) and Enterprise ($35 per user per month) include API access and webhooks. The Audit API, admin controls over scopes and integrations, workspace usage analytics, and the Legal Holds API are Enterprise only. Basic has no API access.
What can the Audit API tell me?
The Audit API covers at least seven categories: when Granola transcribed meetings, who opened notes and transcripts, who can reach a note and who changed that, who joined or left the workspace, sign-in activity, how API keys and MCP are being used, and what data left Granola. New event types are added over time. A missing view is not proof a note went unread, because the log only captures reads by signed-in users.
Can I export meeting data for an archive?
Yes. The API returns notes, summaries, and transcripts as JSON. For archives that must keep running after staff changes, use a workspace API key. It belongs to the workspace rather than a person, so it keeps working if the admin who created it leaves.
How do I get Granola data into my BI tool?
A developer reads notes by date and folder through the API and loads them into your tool. Audit events add sign-in, API, and MCP activity on top of that. Both come back as JSON.
What are the API rate limits?
API keys are rate limited, applying per user or per workspace depending on the key's scope. Check the API docs for current limits. For MCP access, rate limits will vary depending on your Granola subscription plan and the MCP tool that you're using. Rate limits currently average around 100 requests per minute across all tools. Rate limits are subject to change.
Does the Granola API support webhooks?
Yes, on Business and Enterprise plans. They notify your system when a note is generated, edited, or shared, and you fetch the note through the API.
Key terms glossary
API key: A credential that authenticates a script, automation, or integration when it makes requests to an API.
Audit log: A chronological record of who performed what action on which resource and when, used to establish accountability and support investigation.
Rate limit: A constraint on how many API requests a client can make within a given time window.
Webhook: A notification sent by one system to another when a specific event occurs, allowing the receiving system to act on new data without polling.





