> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Request scan reports CSV export

POST https://api.hiddenlayer.ai/scan/v3/reports/csv

Asynchronously initiates generation of a CSV scan report containing all scan results for the given time range.
Returns an ephemeral job ID that can be used to check the status of the export and download the file.
File is stored for 30 days once generated.

Constraints:
- Both `time[gte]` and `time[lte]` are required
- Date range cannot exceed 31 days
- Dates must be in RFC3339 format (e.g., 2023-01-01T00:00:00Z)
- Only scans with status "done" will be included in the export


Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/reports/export-csv

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Query parameters

- `time` (ScanV3ReportsCsvPostParametersTime, required) — Time range for scan results (both gte and lte are required, max 31 day range)

## Response

### 202

CSV export initiated

- `job_id` (string, optional) — Unique identifier for the CSV export job

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 422 Unprocessable Entity Error

Validation Error

- `loc` (list of ValidationErrorModelLocItems, required)
- `msg` (string, required)
- `type` (string, required)

## Types

### ScanV3ReportsCsvPostParametersTime

- `gte` (datetime, required) — Start of time range (RFC3339 format)
- `lte` (datetime, required) — End of time range (RFC3339 format, max 31 days from gte)

### ValidationErrorModelLocItems

## Examples

**Response**

```json
{
  "job_id": "string"
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/scan/v3/reports/csv"

querystring = {"time":"{\"gte\":\"2024-01-15T09:30:00Z\",\"lte\":\"2024-01-15T09:30:00Z\"}"}

headers = {"Authorization": "Bearer <token>"}

response = requests.post(url, headers=headers, params=querystring)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D';
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/scan/v3/reports/csv?time=%7B%22gte%22%3A%222024-01-15T09%3A30%3A00Z%22%2C%22lte%22%3A%222024-01-15T09%3A30%3A00Z%22%7D")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```