GET
Download one server-local snapshot file

Authorizations

Origin
string
header
required

Same-origin CSRF check. The Origin header must match the request host; enforced for every mutating verb (POST, PUT, PATCH, DELETE).

Path Parameters

filename
string
required

Response

JSON bundle.

Versioned export of every app, label, snapshot, annotation, notification, focus state, and feature-flag override. Restorable into any release that understands this bundle format or a later one.

Exported envelopes also carry a signature object (HMAC-SHA256 over the canonicalised envelope, keyed per install). Restoring a bundle whose signature doesn't match the target install requires allowUntrusted — see POST /api/backup/restore.

version
integer

Bundle format version — not the app version.

Example:

1

exportedAt
integer<int64>
apps
object[]