Start an async GDPR contact export

POST
/v1/contacts/export

Exports the caller's own tenant's contacts as CSV. Action::Read (not Manage) — exporting your own data is a read. A per-minute cron builds the CSV (keyset-paginated, EXPORT_BATCH = 1000 rows/page within one tick) and writes it to R2; poll GET /v1/contacts/exports/{id} for the download_url.

Authorization

bearerAuth
headerAuthorizationBearer <token>

API key sent as Authorization: Bearer <key>. Looked up by SHA-256 hash (email_core::sha256_hex) against api_keys.hash; revoked keys and keys belonging to a suspended tenant are rejected. See the top-level Authentication section for permission levels.

Response Body

Export job created.

application/json
  1. response
export_id?string
status?"pending"
Value in"pending"
curl -X POST "https://example.com/v1/contacts/export"
{  "export_id": "string",  "status": "pending"}