---
title: "Export one audit snapshot page"
method: GET
path: "/v1/audit/export"
tags: ["Organizations"]
---

# Export one audit snapshot page

`GET /v1/audit/export`

Organization administrator access to currently captured, retained audit history only; this is not coverage of every cloud action. Requires the latest literal metadata.capabilities.auditLogs=true and deployment visibility; feature disable returns 403 audit_feature_disabled without deleting history or changing capture preference. Legacy arbitrary payloads are preserved separately and are not backfilled or returned. One operation may contain multiple child events. Visibility is independent of capture entitlement. No duration, charge or continuous-drain guarantee is made. Default limit 50, maximum 100. Cursors are signed, organization/filter/mode scoped and expire 24 hours after the first page (not renewed). Repeat the same filters; limit may change. The snapshotSequence is the committed tenant publication watermark, not a timestamp or auto-increment allocation. Events above it are excluded, including later children of an existing operation. Missing retained anchors or changed removal counters return 410 audit_history_unavailable; start a new snapshot. These checks are not lossless-drain or retention protection guarantees. Time filters are inclusive operation-start bounds (ISO date or offset date-time; date-only means UTC midnight). actorId is the initiating user ID; outcome is the current OPERATION outcome, not an event outcome. action matches an exact stable action of any child event within the watermark. searchId is an exact case-sensitive ID match (1..255 characters, no controls), not free-text search: operation ID OR any canonical retained child event ID, child envelope requestId or child resource reference ID, scoped to this organization and operation within the watermark. Legacy payloads are not searched. All other filters are AND combined with searchId. Resource filters match stored references within the watermark, without live-resource joins; resourceType requires resourceId. Operation outcome/count/byte projections remain current rather than historical as-of-watermark values. Exports ALL matching operations' children within the watermark in ascending tenant sequence, not date/ID order. Each response is one bounded attachment, not a continuous drain. Follow X-Audit-Next-Cursor with the same format and filters until that header is absent. X-Audit-Snapshot-Sequence stays fixed. NDJSON has one full envelope per line. CSV has a header on every page and summary fields only: references and changed-field names are JSON cells, no before/after content. Every cell is quoted; formula-leading whitespace/control and =+-@ are prefixed with an apostrophe, backslashes are doubled, controls/multiline characters are encoded as literal backslash-u escapes.

## Query parameters

- `limit` integer
- `cursor` string
- `from` union
  - string, date
  - string, date-time
- `to` union
  - string, date
  - string, date-time
- `actorId` string
- `action` string
- `outcome` 'running' | 'succeeded' | 'failed' | 'partial' | 'unknown'
- `origin` 'api' | 'cloud_ui' | 'mcp' | 'scheduler' | 'webhook' | 'platform_admin'
- `searchId` string
- `resourceId` string
- `resourceType` string
- `format` 'ndjson' | 'csv'

## Response `200`

A bounded attachment page. No next-cursor header means this snapshot is exhausted.

## Other responses

- `400` — Malformed query, cursor, mismatched filters, operation scope or export format.
- `401` — Authentication required.
- `403` — Organization administrator permission, audit feature and visibility required.
- `404` — Organization or retained operation not found, including foreign-tenant targets.
- `410` — Cursor expired or retained snapshot anchors/history are no longer available.
- `503` — Audit storage or required access capture unavailable; no audit content is released.

## Changes

- **2026-09-30** `0d10fe7f6aa1` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openworklabs/apis/den-api/changes/v1/audit/export/get.md)

---

[API](https://skmtc.dev/openworklabs/apis/den-api.md) · [All operations](https://skmtc.dev/openworklabs/apis/den-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openworklabs/apis/den-api/revisions/406852f37cc0?raw)
