Porta v1.11.0
Skip to content

Data Export API ​

The data export API enables bounded CSV or JSON downloads. Every endpoint requires admin:export:read plus the entity-specific read permission. Exports exclude passwords, secrets, private keys, raw audit metadata, and infrastructure details.

Endpoints ​

MethodPathPermissionDescription
GET/api/admin/export/usersadmin:export:read + admin:user:readExport tenant users
GET/api/admin/export/organizationsadmin:export:read + admin:org:readExport organizations
GET/api/admin/export/clientsadmin:export:read + admin:client:readExport tenant clients
GET/api/admin/export/rolesadmin:export:read + admin:role:readExport roles for an exact tenant/application relationship
GET/api/admin/export/auditadmin:export:read + admin:audit:readExport allowlisted audit details
POST/api/admin/export/manifestadmin:export:read + selected category permissionsExport a selective portability manifest

Selective Manifest Export ​

Manifest export is the transfer format for moving selected Porta configuration and users between installations. It is separate from the CSV/JSON report endpoints above.

http
POST /api/admin/export/manifest
Authorization: Bearer <token>
Content-Type: application/json

{
  "scope": { "kind": "organization", "organization_slug": "acme" },
  "categories": ["organizations", "applications_authorization", "users_assignments"],
  "application_selection": {
    "all_applications": false,
    "application_slugs": ["customer-portal"]
  }
}

Choose one organization scope or the complete environment scope. Environment export requires a super-administrator. The supported categories are organizations, applications_authorization, users_assignments, and oidc_clients. Application-related categories require either explicit application_slugs or all_applications: true; organization-only exports require neither.

The response body is the strict version 1.0 manifest. The attachment filename is returned in Content-Disposition. The manifest contains portable configuration but excludes passwords, password hashes, existing client secrets, signing keys, sessions, recovery material, audit logs, database identifiers, and control-plane records.

Required permissions are the union of admin:export:read and the read permissions for every selected category. A manifest larger than 64 MiB is rejected with 413 and export_manifest_too_large.

Query Parameters ​

ParameterTypeDefaultDescription
formatstringjsonExport format: json or csv
organizationIdUUID—Required for users, clients, roles, and audit exports
applicationIdUUID—Required with organizationId for roles
startDateISO datetime—Required inclusive audit-window start
endDateISO datetime—Required inclusive audit-window end

Export Users ​

http
GET /api/admin/export/users?format=csv&organizationId=uuid
Authorization: Bearer <token>

Exported Fields ​

FieldDescription
idUser UUID
emailEmail address
statusAccount status
given_nameFirst name
family_nameLast name
nicknameNickname
localePreferred locale
email_verifiedEmail verification status
phone_numberPhone number
created_atCreation timestamp
updated_atLast update timestamp
last_login_atLast login timestamp
login_countTotal login count

Security: Password hashes, secrets, and other sensitive fields are never included in exports.

Export Organizations ​

http
GET /api/admin/export/organizations?format=json
Authorization: Bearer <token>

No organizationId parameter required — exports all organizations.

Export Audit Log ​

http
GET /api/admin/export/audit?format=csv&organizationId=uuid&startDate=2026-01-01T00:00:00Z&endDate=2026-01-31T23:59:59Z
Authorization: Bearer <token>
  • Limited to 10,000 rows per export; 10,001 or more returns export_too_large with no partial body
  • Date range filtering via startDate and endDate
  • Audit rows expose only id, event classification, actor ID, timestamp, and event-specific safe_details; raw metadata, IP address, user agent, descriptions, bodies, and errors are omitted

Response Headers ​

Report and manifest export responses include an attachment filename. The content type matches the selected report format or is application/json for a manifest:

http
Content-Type: text/csv
Content-Disposition: attachment; filename="users-export-2026-01-15T10-30-00.csv"

CSV Format ​

  • First row is the column header
  • Values containing commas, quotes, or newlines are properly escaped
  • Cells whose first non-whitespace character is =, +, -, or @ receive an inert apostrophe before RFC-compatible quoting
  • Null values are represented as empty strings
  • Dates are formatted as ISO 8601

JSON Format ​

json
{
  "data": [...],
  "exportedAt": "2026-01-15T10:30:00Z",
  "total": 42
}

Released under the MIT License.