Security and audit
Download the audit log (CSV)
The audit log as a CSV download for the filters you pass. Each download is itself recorded in the audit log as export.audit_csv.
- Bearer API key
- Scope:
adminonly - or app session
- Workspace:
X-Tenant-ID(optional with a key)
Headers
AuthorizationstringrequiredYour API key as
Bearer <key>. The wordBearerand the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.X-Tenant-IDuuidoptionalWorkspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass
?tenant=<id>instead.
Query parameters
user_iduuidoptionalOnly this teammate (their user id,
user_idin the members list).api_key_iduuidoptionalOnly actions done with this API key (its
id, not the key itself).actionstringoptionalOnly this action, for example
member.role_changed. End it with*to match a prefix:message.*returnsmessage.sent,message.editedandmessage.deleted.fromtimestampoptionalOnly entries from this time on. RFC 3339 (
2026-10-01T00:00:00Z) or a date (2026-10-01).totimestampoptionalOnly entries before this time (exclusive). RFC 3339 or a date: to include all of 8 October, send
to=2026-10-09.
Response
Status codes
- 200OK. A UTF-8 CSV file of the matching events, sent as an attachment. The file name is in the
Content-Dispositionheader. - 400Bad request. A filter is malformed:
invalid fromorinvalid to(neither RFC 3339,YYYY-MM-DDnor unix seconds),invalid user_id,invalid resultorinvalid cursor. A session request without a workspace getsworkspace required (X-Tenant-ID). - 401Unauthorized. The API key is unknown, revoked or expired (
invalid or expired API key), or there is no key and no signed-in session (unauthorized). - 403Forbidden. The API key does not have the
adminscope (this endpoint needs an API key with the admin scope:readandwritekeys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address,code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace,forbidden). The audit log is for owners and admins: agents signed in to the app always get403(admin required). - 500Server error. Something went wrong on our side. Retry with backoff.
Filters work as in List audit events, including action=message.* prefixes; there is no cursor or limit. -OJ makes cURL save the file under the name the server sends.