> ## Documentation Index
> Fetch the complete documentation index at: https://docs.errorbar.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Export the audit log

> Export this workspace's audit rows with their hash-chain fields (seq, prev_hash, row_hash) as CSV or JSON, so a recipient can verify a later export reproduces the same hashes.

Rows ordered by timestamp then seq ascending. Returns an empty set (not an error) if the log store is unavailable. Cache-Control: no-store.



## OpenAPI

````yaml /openapi.json get /v1/audit/export
openapi: 3.1.0
info:
  title: errorbar Management API
  description: >-
    The management API behind the improvement loop: capture and setup, request
    logs and datasets, grades (labels), judges (criteria), evals and deploy
    gates, fine-tuning and reinforcement learning, dedicated GPU endpoints, and
    model aliases and versions. Authenticated with a workspace API key
    (sk_sovereign_...). The inference API (chat, embeddings, rerank, responses)
    is OpenAI-compatible and documented separately.


    Responses are snake_case, list endpoints on the loop products use the
    {"object": "list", "data": [...]} envelope, and refusals use the same nested
    error shape the gateway emits: {"error": {"message", "type", "code"}}.
    Request bodies on the loop products (logs, labels, criteria, evals,
    datasets, aliases) are snake_case; the training and infrastructure products
    (fine-tuning, GRPO, environment tools, dedicated, model-version adoption)
    validate camelCase bodies, and each schema below says which it is. Endpoints
    that spend money require a key minted by a workspace owner or admin and
    return 403 otherwise.
  version: 1.0.0
servers:
  - url: https://gateway.errorbar.ai
    description: Production
  - url: https://www.errorbar.ai/api
    description: Control plane (also served at this base URL)
security:
  - bearerAuth: []
paths:
  /v1/audit/export:
    get:
      tags:
        - Audit & proving
      summary: Export the audit log
      description: >-
        Export this workspace's audit rows with their hash-chain fields (seq,
        prev_hash, row_hash) as CSV or JSON, so a recipient can verify a later
        export reproduces the same hashes.


        Rows ordered by timestamp then seq ascending. Returns an empty set (not
        an error) if the log store is unavailable. Cache-Control: no-store.
      operationId: exportAuditLog
      parameters:
        - name: since
          in: query
          schema:
            type: string
          description: >-
            ISO-8601 datetime lower bound (inclusive) on the row timestamp. 400
            if unparseable.
        - name: until
          in: query
          schema:
            type: string
          description: ISO-8601 datetime upper bound (inclusive). 400 if unparseable.
        - name: format
          in: query
          schema:
            type: string
            enum:
              - csv
              - json
          description: Output format.
        - name: limit
          in: query
          schema:
            type: integer
          description: Max rows, positive integer; silently capped at 50000.
      responses:
        '200':
          description: >-
            format=json: { rows: [{ id, timestamp, event_type, category, status,
            actor_id, actor_email, actor_role, target_type, target_id,
            description, seq, prev_hash, row_hash }], truncated: boolean }.
            format=csv: text/csv attachment (Content-Disposition
            audit-<workspaceId>.csv) with header row
            seq,timestamp,event_type,category,status,actor_id,actor_email,actor_role,target_type,target_id,description,prev_hash,row_hash,id;
            header X-Truncated: true when the limit cut the result.
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  responses:
    BadRequest:
      description: Malformed request or invalid field.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Missing, malformed, or revoked API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              message: Invalid API key
              type: invalid_request_error
              code: invalid_api_key
  schemas:
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            message:
              type: string
            type:
              type: string
              description: >-
                invalid_request_error, insufficient_quota, rate_limit_error, or
                api_error.
            code:
              type: string
              description: >-
                Machine-stable cause, e.g. invalid_api_key, not_found,
                insufficient_permissions, precondition_failed.
          required:
            - message
            - type
            - code
      description: >-
        Every refusal — gateway and management API alike — uses this one
        envelope.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your workspace API key, e.g. `sk_sovereign_...`, sent as `Authorization:
        Bearer <key>`.

````