POST
Import a shared audit bundle

Authorizations

Origin
string
header
required

Same-origin CSRF check. The Origin header must match the request host; enforced for every mutating verb (POST, PUT, PATCH, DELETE).

Body

application/json

Curated export for sharing apps + labels + AI summaries + exportable annotations. Private notes (visibility = 'private') are excluded by SQL filter at build time. Recipient imports via POST /api/import/audit-bundle. See Security & trust → Audit-bundle export threat model.

Response

Bundle imported.