> This page is for Taurus PROTECT, version v3.54.
> For other versions, use one of these documentation indexes:
> - v3.58 (default): https://taurushq.ferndocs.com/protect-capital/v3.58/llms.txt
> - v3.56: https://taurushq.ferndocs.com/protect-capital/v3.56/llms.txt
> - v3.54: https://taurushq.ferndocs.com/protect-capital/v3.54/llms.txt
> - v3.52: https://taurushq.ferndocs.com/protect-capital/v3.52/llms.txt
> - v3.50: https://taurushq.ferndocs.com/protect-capital/v3.50/llms.txt
> - v3.48: https://taurushq.ferndocs.com/protect-capital/v3.48/llms.txt
> - v3.46: https://taurushq.ferndocs.com/protect-capital/v3.46/llms.txt
> - v3.44: https://taurushq.ferndocs.com/protect-capital/v3.44/llms.txt
> - v3.42: https://taurushq.ferndocs.com/protect-capital/v3.42/llms.txt
> - v3.40: https://taurushq.ferndocs.com/protect-capital/v3.40/llms.txt
> - v3.38: https://taurushq.ferndocs.com/protect-capital/v3.38/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://taurushq.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://taurushq.ferndocs.com/_mcp/server.

# Export audit trails

GET https://your-protect-instance.example.com/api/rest/v1/audit_trails/export

This endpoint exports a list of audit trails as CSV. Note that only a maximum of 10000 trails are exportable at any one time.

Reference: https://taurushq.ferndocs.com/protect-capital/reference/audits/export-trails

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Query parameters

- `externalUserId` (string, optional)
- `entities` (list of string, optional) — The entities for which to get audit trails (defaults to all).
- `actions` (list of string, optional) — The actions for which to get audit trails (defaults to all).
- `creationDateFrom` (datetime, optional)
- `creationDateTo` (datetime, optional)
- `format` (string, optional) — Desired output format. Can be either 'csv' or 'json'.

## Response

### 200

A successful response.

- `result` (string, optional)
- `totalItems` (string, optional)

## Errors

### 400 Bad Request Error

Returned when the tenant ID was not found in the JWT.

- `code` (integer, optional) — The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
- `message` (string, optional) — A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
- `details` (list of protobufAny, optional) — A list of messages that carry the error details. There is a common set of message types for APIs to use.

### 401 Unauthorized Error

Unauthorized: indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource

- `any`

### 403 Forbidden Error

Forbidden: indicates that the server understands the request but refuses to authorize it

- `any`

### 404 Not Found Error

Not Found: indicates that the server cannot find the requested resource

- `any`

### 500 Internal Server Error

Returned when the service encountered an error.

- `code` (integer, optional) — The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
- `message` (string, optional) — A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
- `details` (list of protobufAny, optional) — A list of messages that carry the error details. There is a common set of message types for APIs to use.

### 503 Service Unavailable Error

Service Unavailable: indicates that the server is not ready to handle the request.

- `any`

## Types

### protobufAny

`Any` contains an arbitrary serialized protocol buffer message along with a URL that describes the type of the serialized message. Protobuf library provides support to pack/unpack Any values in the form of utility functions or additional generated methods of the Any type. Example 1: Pack and unpack a message in C++. Foo foo = ...; Any any; any.PackFrom(foo); ... if (any.UnpackTo(\&foo)) \{ ... } Example 2: Pack and unpack a message in Java. Foo foo = ...; Any any = Any.pack(foo); ... if (any.is(Foo.class)) \{ foo = any.unpack(Foo.class); } Example 3: Pack and unpack a message in Python. foo = Foo(...) any = Any() any.Pack(foo) ... if any.Is(Foo.DESCRIPTOR): any.Unpack(foo) ... Example 4: Pack and unpack a message in Go foo := \&pb.Foo\{...} any, err := anypb.New(foo) if err != nil \{ ... } ... foo := \&pb.Foo\{} if err := any.UnmarshalTo(foo); err != nil \{ ... } The pack methods provided by protobuf library will by default use 'type.googleapis.com/full.type.name' as the type URL and the unpack methods only use the fully qualified type name after the last '/' in the type URL, for example "foo.bar.com/x/y.z" will yield type name "y.z". JSON The JSON representation of an `Any` value uses the regular representation of the deserialized, embedded message, with an additional field `@type` which contains the type URL. Example: package google.profile; message Person \{ string first\_name = 1; string last\_name = 2; } \{ "@type": "type.googleapis.com/google.profile.Person", "firstName": \<string>, "lastName": \<string> } If the embedded message type is well-known and has a custom JSON representation, that representation will be embedded adding a field `value` which holds the custom JSON in addition to the `@type` field. Example (for message \[google.protobuf.Duration]\[]): \{ "@type": "type.googleapis.com/google.protobuf.Duration", "value": "1.212s" }

- `@type` (string, optional) — A URL/resource name that uniquely identifies the type of the serialized protocol buffer message. This string must contain at least one "/" character. The last segment of the URL's path must represent the fully qualified name of the type (as in `path/google.protobuf.Duration`). The name should be in a canonical form (e.g., leading "." is not accepted). In practice, teams usually precompile into the binary all types that they expect it to use in the context of Any. However, for URLs which use the scheme `http`, `https`, or no scheme, one can optionally set up a type server that maps type URLs to message definitions as follows: * If no scheme is provided, `https` is assumed. * An HTTP GET on the URL must yield a [google.protobuf.Type][] value in binary format, or produce an error. * Applications are allowed to cache lookup results based on the URL, or have them precompiled into a binary to avoid any lookup. Therefore, binary compatibility needs to be preserved on changes to types. (Use versioned type names to manage breaking changes.) Note: this functionality is not currently available in the official protobuf release, and it is not used for type URLs beginning with type.googleapis.com. Schemes other than `http`, `https` (or the empty scheme) might be used with implementation specific semantics.

## Examples

**Response**

```json
{
  "result": "string",
  "totalItems": "string"
}
```

**SDK Code**

```python
import requests

url = "https://your-protect-instance.example.com/api/rest/v1/audit_trails/export"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://your-protect-instance.example.com/api/rest/v1/audit_trails/export';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://your-protect-instance.example.com/api/rest/v1/audit_trails/export"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://your-protect-instance.example.com/api/rest/v1/audit_trails/export")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://your-protect-instance.example.com/api/rest/v1/audit_trails/export")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://your-protect-instance.example.com/api/rest/v1/audit_trails/export', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://your-protect-instance.example.com/api/rest/v1/audit_trails/export");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://your-protect-instance.example.com/api/rest/v1/audit_trails/export")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```