Export agent audit logs as CSV
Streams the project's agent audit entries as a CSV file, newest first, honoring the same credential, event, decision, source and date-range filters as the list endpoint. The full filtered set is streamed (no pagination); the result is suitable for spreadsheets, SIEM ingestion, and compliance archives.
JWT issued by Better Auth. Verified via JWKS.
In: header
Path Parameters
Unique project identifier (prefixed, e.g. prj_xxx).
^[a-zA-Z0-9_.-]+$Query Parameters
Filter to a single agent credential.
^[a-zA-Z0-9_.-]+$Filter to a single event type (e.g. blocked, masked, query).
^[a-z_]+$Coarse outcome filter that groups events. allow = query; block = blocked, budget_exhausted, auth_failed, credential_expired; mask = masked; truncate = truncated.
Value in
- "allow"
- "block"
- "mask"
- "truncate"
Filter by statement origin (wire, mcp, rest, or control).
Value in
- "wire"
- "mcp"
- "rest"
- "control"
Return entries at or after this timestamp (inclusive lower bound).
date-timeReturn entries strictly older than this timestamp (cursor / upper bound).
date-timeResponse Body
text/csv
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/projects/string/audit-logs/export""string"{ "error": { "code": "string", "message": "string" }}{ "error": { "code": "string", "message": "string" }}{ "error": { "code": "string", "message": "string" }}{ "error": { "code": "string", "message": "string" }}{ "error": { "code": "string", "message": "string" }}