GET
Export a versioned backup bundle

Authorizations

X-Auditor-Admin-Token
string
header
required

Required when AUDITOR_ADMIN_TOKEN is set in the environment, and — on a network-exposed instance — on the sensitive read prefixes listed on the Overview page. Verified with crypto.timingSafeEqual. Missing or wrong token returns 401. Failed attempts are recorded in audit_log with IP + user agent.

Browser callers may send the pt_admin_token HttpOnly cookie instead; it is accepted everywhere this header is. Obtain it from POST /api/auth/admin-token/login.

Response

JSON bundle.

Versioned export of every app, label, snapshot, annotation, notification, focus state, and feature-flag override. Restorable into any release that understands this bundle format or a later one.

Exported envelopes also carry a signature object (HMAC-SHA256 over the canonicalised envelope, keyed per install). Restoring a bundle whose signature doesn't match the target install requires allowUntrusted — see POST /api/backup/restore.

version
integer

Bundle format version — not the app version.

Example:

1

exportedAt
integer<int64>
apps
object[]