curl --request POST \
--url http://localhost:3000/api/export/audit-bundle \
--header 'Content-Type: application/json' \
--header 'Origin: <api-key>' \
--data '
{
"recommenderName": "<string>",
"includeRecommenderProfile": true,
"migrationFlow": false
}
'import requests
url = "http://localhost:3000/api/export/audit-bundle"
payload = {
"recommenderName": "<string>",
"includeRecommenderProfile": True,
"migrationFlow": False
}
headers = {
"Origin": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Origin: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
recommenderName: '<string>',
includeRecommenderProfile: true,
migrationFlow: false
})
};
fetch('http://localhost:3000/api/export/audit-bundle', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/export/audit-bundle",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recommenderName' => '<string>',
'includeRecommenderProfile' => true,
'migrationFlow' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"Origin: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/export/audit-bundle"
payload := strings.NewReader("{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Origin", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/export/audit-bundle")
.header("Origin", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/export/audit-bundle")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["Origin"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}"
response = http.request(request)
puts response.read_body{}{
"error": "Admin token required"
}{
"error": "Admin token required"
}Export an audit bundle
Curated subset suitable for sharing. Notes flagged private are excluded
by SQL filter at build time. See Security & trust → Audit-bundle export
threat model.
Gated: allowed when the flag.settings.admin.export.audit_bundle feature
flag resolves to on, or when flag.focus.workflow is other_handoff.
Otherwise 403. On a network-exposed instance the admin token is required
too — /api/export is a gated read prefix, and this is a mutation.
curl --request POST \
--url http://localhost:3000/api/export/audit-bundle \
--header 'Content-Type: application/json' \
--header 'Origin: <api-key>' \
--data '
{
"recommenderName": "<string>",
"includeRecommenderProfile": true,
"migrationFlow": false
}
'import requests
url = "http://localhost:3000/api/export/audit-bundle"
payload = {
"recommenderName": "<string>",
"includeRecommenderProfile": True,
"migrationFlow": False
}
headers = {
"Origin": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Origin: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
recommenderName: '<string>',
includeRecommenderProfile: true,
migrationFlow: false
})
};
fetch('http://localhost:3000/api/export/audit-bundle', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/export/audit-bundle",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recommenderName' => '<string>',
'includeRecommenderProfile' => true,
'migrationFlow' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"Origin: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/export/audit-bundle"
payload := strings.NewReader("{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Origin", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/export/audit-bundle")
.header("Origin", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/export/audit-bundle")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["Origin"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recommenderName\": \"<string>\",\n \"includeRecommenderProfile\": true,\n \"migrationFlow\": false\n}"
response = http.request(request)
puts response.read_body{}{
"error": "Admin token required"
}{
"error": "Admin token required"
}Authorizations
Same-origin CSRF check. The Origin header must match the request host;
enforced for every mutating verb (POST, PUT, PATCH, DELETE).
Body
Optional. The bundle always covers every tracked app — there is no per-app selection on this route.
Free-text name attached to your annotations on the recipient's view. Falls back to "your friend".
Include the privacy profile you assessed against.
Mark the bundle as a same-user migration, so the receiving install skips the provenance banner.
Response
Bundle ready for download.
Curated export for sharing apps + labels + AI summaries + exportable
annotations. Private notes (visibility = 'private') are excluded by
SQL filter at build time. Recipient imports via
POST /api/import/audit-bundle. See Security & trust → Audit-bundle
export threat model.