Audit Log Exports
Overview
The Confident AI SDK exposes every Audit Log Export method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.
Methods
Create Audit Log Export
Starts a background export of your organization's audit logs — every audited action across every project — as a gzipped CSV, and responds 202 with the export to poll. Poll GET /v2/organization/audit- logs/exports/{exportId} until status is COMPLETED, then call GET /v2/organization/audit-logs/exports/{exportId}/download for the file; ERRORED is terminal. One export runs at a time per organization and caller, so starting a second returns 409, and a period matching no audit logs, or more than 10,000,000 audit logs, is rejected with 400.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.create_audit_log_export(
start_time="2025-01-01T00:00:00+00:00",
end_time="2025-04-01T00:00:00+00:00",
search_term="jane@acme.com",
)For async mode, call a_create_audit_log_export and await it as shown below:
result = await client.organization.a_create_audit_log_export(...)Parameters
| Parameter | Type | Description |
|---|---|---|
start_time | Optional[str] | Start of the period to export, inclusive, as an ISO 8601 timestamp. Omit along with endTime to export all time. |
end_time | Optional[str] | End of the period to export, inclusive, as an ISO 8601 timestamp. Must be after startTime. Omit along with startTime to export all time. |
search_term | Optional[str] | Only export audit logs matching this term. Matched as a substring against the actor email, API key name, API key id, actor type, action, HTTP method, IP address, resource id, user agent, and status code. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.createAuditLogExport(
{
startTime: "2025-01-01T00:00:00+00:00",
endTime: "2025-04-01T00:00:00+00:00",
searchTerm: "jane@acme.com"
},
);Parameters
| Parameter | Type | Description |
|---|---|---|
startTime | string | Start of the period to export, inclusive, as an ISO 8601 timestamp. Omit along with endTime to export all time. |
endTime | string | End of the period to export, inclusive, as an ISO 8601 timestamp. Must be after startTime. Omit along with startTime to export all time. |
searchTerm | string | Only export audit logs matching this term. Matched as a substring against the actor email, API key name, API key id, actor type, action, HTTP method, IP address, resource id, user agent, and status code. |
Returns
This method returns an object of type AuditLogExport.
Get Audit Log Export
Retrieves an organization audit log export, so you can poll one you started — poll here rather than at the download endpoint, which has nothing to serve until status is COMPLETED. An export is kept for 24 hours, or 5 minutes once it has failed, after which this returns 404. The lookup is not restricted to audit log exports, so another kind of export id comes back with its own exportType.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.get_audit_log_export(
export_id="<AUDIT-LOG-EXPORT-ID>",
)For async mode, call a_get_audit_log_export and await it as shown below:
result = await client.organization.a_get_audit_log_export(...)Parameters
| Parameter | Type | Description |
|---|---|---|
export_id | str | Required. The id of the audit log export, as returned when it was created. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.getAuditLogExport(
"<AUDIT-LOG-EXPORT-ID>",
);Parameters
| Parameter | Type | Description |
|---|---|---|
exportId | string | Required. The id of the audit log export, as returned when it was created. |
Returns
This method returns an object of type AuditLogExport.
Types
AuditLogExport
One run of an audit log export: the period it covers, where it is in its lifecycle, and how many audit logs its file holds once it completes.
class AuditLogExport:
id: str
project_id: Optional[str] = Field(alias="projectId")
organization_id: str = Field(alias="organizationId")
user_id: str = Field(alias="userId")
status: AuditLogExportStatus
export_type: Literal["TRACES", "TRACES_WITH_SPANS", "CONVERSATIONS", "CONVERSATION_METRICS", "ANNOTATIONS", "TEST_RUNS", "AUDIT_LOGS"] = Field(alias="exportType")
start_time: Optional[str] = Field(alias="startTime")
end_time: Optional[str] = Field(alias="endTime")
row_count: Optional[int] = Field(alias="rowCount")
error_message: Optional[str] = Field(alias="errorMessage")
created_at: str = Field(alias="createdAt")
completed_at: Optional[str] = Field(alias="completedAt")idstrRequired
The id of the export, a UUID generated by Confident AI. Poll and download the export by this id.
Example: "<AUDIT-LOG-EXPORT-ID>"
project_idOptional[str]Required
The project whose audit logs the export covers, or null for an organization-wide export covering every project.
organization_idstrRequired
The organization the export belongs to.
Example: "<ORGANIZATION-ID>"
user_idstrRequired
The actor that started the export. api for an export started with an organization API key, or the user's id when started through an MCP OAuth session. An export is only visible to the actor that started it.
Example: "api"
statusAuditLogExportStatusRequired
See AuditLogExportStatus.
export_typeLiteral["TRACES", "TRACES_WITH_SPANS", "CONVERSATIONS", "CONVERSATION_METRICS", "ANNOTATIONS", "TEST_RUNS", "AUDIT_LOGS"]Required
The kind of data the file contains. Always AUDIT_LOGS for an export started at an audit log export endpoint.
Example: "AUDIT_LOGS"
start_timeOptional[str]Required
Start of the period the export covers, inclusive. For an all-time export this is the timestamp of the oldest audit log matched.
Example: "2025-01-01T00:00:00+00:00"
end_timeOptional[str]Required
End of the period the export covers, inclusive. For an all-time export this is the timestamp of the newest audit log matched.
Example: "2025-04-01T00:00:00+00:00"
row_countOptional[int]Required
How many audit logs were written to the file. Null until the export completes.
Example: 18432
error_messageOptional[str]Required
Why the export failed, when status is ERRORED. Null otherwise.
created_atstrRequired
When the export was started.
Example: "2025-04-02T09:15:00+00:00"
completed_atOptional[str]Required
When the export finished or failed. Null while it is still running.
Example: "2025-04-02T09:17:42+00:00"
interface AuditLogExport {
id: string;
projectId: string | null;
organizationId: string;
userId: string;
status: AuditLogExportStatus;
exportType: "TRACES" | "TRACES_WITH_SPANS" | "CONVERSATIONS" | "CONVERSATION_METRICS" | "ANNOTATIONS" | "TEST_RUNS" | "AUDIT_LOGS";
startTime: string | null;
endTime: string | null;
rowCount: number | null;
errorMessage: string | null;
createdAt: string;
completedAt: string | null;
}idstringRequired
The id of the export, a UUID generated by Confident AI. Poll and download the export by this id.
Example: "<AUDIT-LOG-EXPORT-ID>"
projectIdstring | nullRequired
The project whose audit logs the export covers, or null for an organization-wide export covering every project.
organizationIdstringRequired
The organization the export belongs to.
Example: "<ORGANIZATION-ID>"
userIdstringRequired
The actor that started the export. api for an export started with an organization API key, or the user's id when started through an MCP OAuth session. An export is only visible to the actor that started it.
Example: "api"
statusAuditLogExportStatusRequired
See AuditLogExportStatus.
exportType"TRACES" | "TRACES_WITH_SPANS" | "CONVERSATIONS" | "CONVERSATION_METRICS" | "ANNOTATIONS" | "TEST_RUNS" | "AUDIT_LOGS"Required
The kind of data the file contains. Always AUDIT_LOGS for an export started at an audit log export endpoint.
Example: "AUDIT_LOGS"
startTimestring | nullRequired
Start of the period the export covers, inclusive. For an all-time export this is the timestamp of the oldest audit log matched.
Example: "2025-01-01T00:00:00+00:00"
endTimestring | nullRequired
End of the period the export covers, inclusive. For an all-time export this is the timestamp of the newest audit log matched.
Example: "2025-04-01T00:00:00+00:00"
rowCountnumber | nullRequired
How many audit logs were written to the file. Null until the export completes.
Example: 18432
errorMessagestring | nullRequired
Why the export failed, when status is ERRORED. Null otherwise.
createdAtstringRequired
When the export was started.
Example: "2025-04-02T09:15:00+00:00"
completedAtstring | nullRequired
When the export finished or failed. Null while it is still running.
Example: "2025-04-02T09:17:42+00:00"
AuditLogExportStatus
Where an export is in its lifecycle. It is created IN_PROGRESS, becomes COMPLETED once its file is written to storage, and becomes ERRORED if the run failed. Only a COMPLETED export has a file to download, and both COMPLETED and ERRORED are terminal.
class AuditLogExportStatus(Enum):
IN_PROGRESS = "IN_PROGRESS"
COMPLETED = "COMPLETED"
ERRORED = "ERRORED"enum AuditLogExportStatus {
IN_PROGRESS = "IN_PROGRESS",
COMPLETED = "COMPLETED",
ERRORED = "ERRORED",
}IN_PROGRESS · COMPLETED · ERRORED
Last updated on