Skip to content

Security and audit

Download the audit log (CSV)

The audit log as a CSV download for the filters you pass. Each download is itself recorded in the audit log as export.audit_csv.

GET/api/v1/security/audit.csv
  • Bearer API key
  • Scope: admin only
  • or app session
  • Workspace: X-Tenant-ID (optional with a key)

Headers

  • Authorizationstringrequired

    Your API key as Bearer <key>. The word Bearer and the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.

    Constraints
    Keys start with pk_live_ and are 56 characters long.
    Example
    Bearer pk_live_…
  • X-Tenant-IDuuidoptional

    Workspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Query parameters

  • user_iduuidoptional

    Only this teammate (their user id, user_id in the members list).

  • api_key_iduuidoptional

    Only actions done with this API key (its id, not the key itself).

  • actionstringoptional

    Only this action, for example member.role_changed. End it with * to match a prefix: message.* returns message.sent, message.edited and message.deleted.

    Example
    message.*
  • fromtimestampoptional

    Only entries from this time on. RFC 3339 (2026-10-01T00:00:00Z) or a date (2026-10-01).

    Example
    2026-10-01
  • totimestampoptional

    Only entries before this time (exclusive). RFC 3339 or a date: to include all of 8 October, send to=2026-10-09.

Response

Status codes

  • 200OK. A UTF-8 CSV file of the matching events, sent as an attachment. The file name is in the Content-Disposition header.
  • 400Bad request. A filter is malformed: invalid from or invalid to (neither RFC 3339, YYYY-MM-DD nor unix seconds), invalid user_id, invalid result or invalid cursor. A session request without a workspace gets workspace required (X-Tenant-ID).
  • 401Unauthorized. The API key is unknown, revoked or expired (invalid or expired API key), or there is no key and no signed-in session (unauthorized).
  • 403Forbidden. The API key does not have the admin scope (this endpoint needs an API key with the admin scope: read and write keys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address, code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace, forbidden). The audit log is for owners and admins: agents signed in to the app always get 403 (admin required).
  • 500Server error. Something went wrong on our side. Retry with backoff.

Filters work as in List audit events, including action=message.* prefixes; there is no cursor or limit. -OJ makes cURL save the file under the name the server sends.