> ## Documentation Index
> Fetch the complete documentation index at: https://docs.uselemma.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Export audit events as CSV

> Organization-wide audit log for owners, admins, and org-wide admin API keys. Project-scoped keys are rejected. Defaults to the last 7 days; the window may not exceed 90 days. Returns every matching event as text/csv (columns: occurred_at, event_id, actor_type, actor_id, impersonator_user_id, action, target_type, target_id, ip, user_agent, metadata). More than 10,000 matching events is a 400; narrow the filters. Each export is itself recorded in the audit log as data.audit_log.export.



## OpenAPI

````yaml https://api.uselemma.ai/openapi.json get /audit-events/export
openapi: 3.1.0
info:
  title: Lemma Platform API
  description: Lemma Platform HTTP API for AI observability and workspace operations.
  version: 0.1.0
servers:
  - url: https://api.uselemma.ai
    description: Lemma production API
security:
  - bearerAuth: []
paths:
  /audit-events/export:
    get:
      tags:
        - Audit log
      summary: Export audit events as CSV
      description: >-
        Organization-wide audit log for owners, admins, and org-wide admin API
        keys. Project-scoped keys are rejected. Defaults to the last 7 days; the
        window may not exceed 90 days. Returns every matching event as text/csv
        (columns: occurred_at, event_id, actor_type, actor_id,
        impersonator_user_id, action, target_type, target_id, ip, user_agent,
        metadata). More than 10,000 matching events is a 400; narrow the
        filters. Each export is itself recorded in the audit log as
        data.audit_log.export.
      operationId: export_audit_events
      parameters:
        - name: actor_type
          in: query
          required: false
          description: 'Who acted: user, api_key, staff, or system.'
          schema:
            type: string
            enum:
              - user
              - api_key
              - staff
              - system
        - name: actor_id
          in: query
          required: false
          description: Exact actor id (user id or API key id).
          schema:
            type: string
        - name: action
          in: query
          required: false
          description: >-
            Audit action from the catalog, e.g. api_key.create. Repeatable;
            comma-separated values are also accepted. Unknown actions are a 400.
          schema:
            type: array
            items:
              type: string
        - name: target_type
          in: query
          required: false
          description: Exact target type, e.g. project or user.
          schema:
            type: string
        - name: target_id
          in: query
          required: false
          description: Exact target id.
          schema:
            type: string
        - name: start
          in: query
          required: false
          description: Inclusive ISO 8601 start. Defaults to 7 days before end.
          schema:
            type: string
            format: date-time
        - name: end
          in: query
          required: false
          description: Inclusive ISO 8601 end. Defaults to now.
          schema:
            type: string
            format: date-time
      responses:
        '200':
          description: CSV file of the matching audit events
          content:
            text/csv:
              schema:
                type: string
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                  code:
                    type: string
                required:
                  - detail
                additionalProperties: false
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                  code:
                    type: string
                required:
                  - detail
                additionalProperties: false
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.