Skip to content
Seal
Esc
↑↓navigate↵open⌘Jpreview

Export sealed audit entries as NDJSON for SIEM pull (SEA-67)

Admin-only pull export for SIEM / log pipeline backfill. Returns one JSON object per line (application/x-ndjson), ordered by sealed sequence. Pass after_sequence from the prior response’s x-seal-next-sequence header to page.

Retention: workspace audit entries (including IP when present via Cloudflare connecting IP) are retained for the life of the organization unless the org is deleted. Export to your SIEM for customer-controlled retention.

Push alternative: create a webhook subscribed to audit.entry.created, audit.*, or *. Seal fans sealed rows out on the */5 cron (and via POST .../audit/siem/flush).

GET/organizations/{organizationSlug}/audit/export
Authorization
AuthorizationBearer token · headerrequired

Pass your API key as a Bearer token. API keys are scoped to specific operations — configure scopes in your organization's Settings → Developer → API Keys.

Path parameters
organizationSlugstringrequired
Query parameters
after_sequenceinteger
min 0 · default: 0
limitinteger
min 1 · max 500 · default: 100
Responses
200

NDJSON audit entries

string
401

Missing or invalid API key

typestringrequired

Machine-readable error code

statusintegerrequired

HTTP status code

titlestringrequired

Human-readable error message

detailsobject

Field-level validation errors

403

Forbidden

Try it
Server
Authorization
Parameters
Request
curl -X GET "https://api.seal.nyc/api/v1/organizations/string/audit/export" \
  -H "Authorization: Bearer YOUR_TOKEN"
Response
"string"