> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nekt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Export Token Access Logs

> Build a Parquet file with every token access log of a period: each log's full detail, request body and headers included, plus what its Athena queries scanned and cost.



## OpenAPI

````yaml POST /api/v1/token-access-logs/exports/
openapi: 3.0.3
info:
  title: Nekt API
  version: v1
  description: Nekt API Documentation
  contact:
    email: support@nekt.ai
servers:
  - url: https://api.nekt.ai
security: []
paths:
  /api/v1/token-access-logs/exports/:
    post:
      tags:
        - v1
      summary: Export token access logs
      description: >-
        Starts building a Parquet file with every token access log of a period,
        one row per log. Each row holds what the list returns plus everything
        the single-log endpoint returns in `content`: `query_string`,
        `user_agent`, `content_truncated`, and `request_body`,
        `request_headers`, `response_headers` and `athena_metadata` as JSON
        text. `content_status` is `available` or `unavailable`, as in the
        single-log endpoint; a key added to `content` later arrives in
        `content_other`.


        For reports, the Athena totals also come as typed columns:
        `athena_total_data_scanned_in_bytes`, `athena_total_billed_bytes`,
        `athena_total_estimated_cost_usd`, `athena_query_count` and
        `athena_price_per_tb_usd`. They are null for a log that ran no Athena
        query.


        Answers `202` right away. Poll the export until `status` is `succeeded`
        (then `download_url` is set) or `failed` (then `error` says why). The
        file is written to your workspace's lakehouse bucket.


        `start_date` and `end_date` are UTC days, both inclusive, at most 31
        days apart, and inside the window your plan keeps. The optional filters
        are the ones the list accepts; `token_id` takes one id or a list.


        Who sees what is the same as in the list: Owners and Admins export the
        whole workspace; everyone else exports only the logs of the tokens they
        created. At most 2 exports per workspace run at once; a third answers
        `409`.
      operationId: v1_token_access_logs_exports_create
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TokenAccessLogExportCreate'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/TokenAccessLogExportCreate'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/TokenAccessLogExportCreate'
        required: true
      responses:
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenAccessLogExport'
          description: ''
      security:
        - ApiKeyAuth: []
components:
  schemas:
    TokenAccessLogExportCreate:
      type: object
      description: The period to export and, optionally, the same filters the list accepts.
      properties:
        start_date:
          type: string
          format: date
          description: First day to export (UTC), inclusive.
        end_date:
          type: string
          format: date
          description: >-
            Last day to export (UTC), inclusive. At most 31 days after
            `start_date`.
        token_id:
          type: array
          items:
            type: string
            format: uuid
          description: One token id or a list of them.
        token_kind:
          type: array
          items:
            $ref: '#/components/schemas/TokenKindEnum'
        token_owner_id:
          type: array
          items:
            type: integer
        action:
          type: array
          items:
            type: string
            maxLength: 128
        transport:
          type: array
          items:
            $ref: '#/components/schemas/TransportEnum'
        status_code:
          type: integer
        status_code__lt:
          type: integer
        status_code__gte:
          type: integer
      required:
        - end_date
        - start_date
    TokenAccessLogExport:
      type: object
      description: >-
        A token access log export.


        Poll it until `status` is `succeeded` or `failed`. Once it has
        succeeded, `download_url` is a

        signed link to the Parquet file in your workspace's lakehouse bucket,
        valid until

        `download_url_expires_at`; read the export again for a fresh one.
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        status:
          allOf:
            - $ref: '#/components/schemas/TokenAccessLogExportStatusEnum'
          readOnly: true
        start_date:
          type: string
          format: date
          readOnly: true
          description: Inclusive, UTC.
        end_date:
          type: string
          format: date
          readOnly: true
          description: Inclusive, UTC.
        filters:
          readOnly: true
          description: >-
            The list filters the export was asked for, already validated: lists
            of values per key.
        row_count:
          type: integer
          readOnly: true
          nullable: true
        file_name:
          type: string
          readOnly: true
        error:
          type: string
          readOnly: true
          description: Shown to the customer; no internals.
        created_at:
          type: string
          format: date-time
          readOnly: true
        started_at:
          type: string
          format: date-time
          readOnly: true
          nullable: true
        finished_at:
          type: string
          format: date-time
          readOnly: true
          nullable: true
        download_url:
          type: string
          readOnly: true
          nullable: true
        download_url_expires_at:
          type: string
          format: date-time
          readOnly: true
          nullable: true
      required:
        - created_at
        - download_url
        - download_url_expires_at
        - end_date
        - error
        - file_name
        - filters
        - finished_at
        - id
        - row_count
        - start_date
        - started_at
        - status
    TokenKindEnum:
      enum:
        - api-token
        - mcp-token
      type: string
      description: |-
        * `api-token` - API token
        * `mcp-token` - MCP token
    TransportEnum:
      enum:
        - http
        - websocket
      type: string
      description: |-
        * `http` - HTTP
        * `websocket` - WebSocket
    TokenAccessLogExportStatusEnum:
      enum:
        - pending
        - running
        - succeeded
        - failed
      type: string
      description: |-
        * `pending` - Pending
        * `running` - Running
        * `succeeded` - Succeeded
        * `failed` - Failed
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: 'API Key authentication. Format: ''x-api-key: api_key'''

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.