Skip to content

The audit log as CSV, narrowed by the same filters as the list.

GET
/api/v1/audit/export.csv
curl --request GET \
--url https://example.com/api/v1/audit/export.csv \
--header 'Authorization: Bearer <token>'

This is the endpoint that makes Export mean what it says. The button used to write out the rows the browser had scrolled to, which is a different set from “everything matching” — in a log whose purpose is completeness, that is a correctness problem rather than a missing feature. The list endpoint’s filters moved into SQL first; this closes the other half.

before is deliberately not accepted: a cursor is where a page starts, and an export is not paged. Accepting it would let a caller export “the second page” and believe it was the answer.

The response is a download rather than JSON, so a failure has nowhere useful to render — which is why the filter is validated the same way the list validates it, before anything is fetched.

since
string

Only entries at or after this RFC 3339 timestamp.

until
string

Only entries at or before this RFC 3339 timestamp.

q
string

Free text matched against the username and the action (case-insensitive substring).

action
string

Comma-separated action kinds (post, put, patch, delete, login, mcp); empty or absent means every kind. An unknown token is rejected rather than ignored.

status
string

Comma-separated status classes (ok, client, server); empty or absent means every class.

Every matching entry as CSV, newest first, capped

Media typetext/csv

A range bound is not RFC 3339, or action/status is not one of the listed values

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks the view-audit permission

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Skeleton mode keeps no audit log

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}