EvoHub Docs Sign in

EvoTrail API › Audit trail

Export the audit trail as CSV

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}
GET/api/v1/evotrail/audit/export.csv

Every event the filters match, newest first, streamed as CSV with the columns occurred_at, product, action, class, actor_type, actor_id, actor_name, resource_type, resource_id, resource_name, team_id, request_id, ip, user_agent, event_id, id. More than 100,000 matching events is refused: narrow the range or filters. A cell that starts with =, +, -, @, a tab or a carriage return is prefixed with '. The export is itself recorded in the trail as evotrail audit.exported.

Permission (API-key scope): evotrail:audit:read. Each product's rows also need that product's *:audit:read.

Authorization

Any one of:

Parameters

Query parameters

  • product array of Product
    Only these products; repeat it (product=oncall&product=uptime) or comma-separate. Products the key cannot read are dropped. Default: every product it can read.
  • actor_id string
    Who did it: a user, API key or agent id.
    Max length: 200
  • actor_type string
    One of: user api_key agent system evohub_staff
  • action string
    An exact action, or a prefix ending in * (alert.*). Lower case, digits, _ and ..
    Example: member.* · Max length: 200 · Pattern: ^[a-z0-9_.]+\*?$
  • resource_type string
    Max length: 200
  • resource_id string
    Max length: 200
  • team_id string
    Events on resources of this team.
    Max length: 200
  • request_id string
    Every event one API request caused.
    Max length: 200
  • ip string
    An IPv4 or IPv6 address.
  • class string
    One of: audit activity
  • from string
    YYYY-MM-DD (UTC) or RFC 3339. Default 30 days before to.
    Example: 2026-09-10
  • to string
    YYYY-MM-DD (inclusive) or RFC 3339. Default now.
    Example: 2026-10-09

Responses

200

The CSV, as an attachment named evotrail-audit-<from>-<to>.csv.

Content type: text/csv

Type: string

400

A filter is not valid (VALIDATION_ERROR), or more than 100,000 events match (EXPORT_TOO_LARGE).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

401

No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

403

The key lacks the EvoTrail scope, or may read none of the products asked for (FORBIDDEN).

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

429

Too many requests (RATE_LIMITED). Wait Retry-After seconds.

Headers

  • Retry-After integer
    Seconds to wait.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

500

Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.

Content type: application/json

Type: Error

  • error object required
    • code string required
      Machine-readable code. Branch on this.
    • message string required
      Human-readable explanation.
    • request_id string
      This request's id, also in X-Request-ID.
  • success boolean
    Value: false

Example request

curl -X GET 'https://evohub.io/api/v1/evotrail/audit/export.csv' \
  -H 'Authorization: Bearer <TOKEN>'

Last updated