POST
Export an audit bundle

Authorizations

Origin
string
header
required

Same-origin CSRF check. The Origin header must match the request host; enforced for every mutating verb (POST, PUT, PATCH, DELETE).

Body

application/json

Optional. The bundle always covers every tracked app — there is no per-app selection on this route.

recommenderName
string | null

Free-text name attached to your annotations on the recipient's view. Falls back to "your friend".

includeRecommenderProfile
boolean
default:true

Include the privacy profile you assessed against.

migrationFlow
boolean
default:false

Mark the bundle as a same-user migration, so the receiving install skips the provenance banner.

Response

Bundle ready for download.

Curated export for sharing apps + labels + AI summaries + exportable annotations. Private notes (visibility = 'private') are excluded by SQL filter at build time. Recipient imports via POST /api/import/audit-bundle. See Security & trust → Audit-bundle export threat model.