Export sealed audit entries as NDJSON for SIEM pull (SEA-67)
Admin-only pull export for SIEM / log pipeline backfill.
Returns one JSON object per line (application/x-ndjson), ordered by
sealed sequence. Pass after_sequence from the prior response’s
x-seal-next-sequence header to page.
Retention: workspace audit entries (including IP when present via Cloudflare connecting IP) are retained for the life of the organization unless the org is deleted. Export to your SIEM for customer-controlled retention.
Push alternative: create a webhook subscribed to audit.entry.created,
audit.*, or *. Seal fans sealed rows out on the */5 cron (and via
POST .../audit/siem/flush).
/organizations/{organizationSlug}/audit/exportAuthorizationBearer token · headerrequiredPass your API key as a Bearer token. API keys are scoped to specific operations — configure scopes in your organization's Settings → Developer → API Keys.
organizationSlugstringrequiredafter_sequenceintegerlimitintegerNDJSON audit entries
stringMissing or invalid API key
typestringrequiredMachine-readable error code
statusintegerrequiredHTTP status code
titlestringrequiredHuman-readable error message
detailsobjectField-level validation errors
Forbidden