curl --request POST \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_id": "user-123"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_id: 'user-123'})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export"
payload = { "user_id": "user-123" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"exported_at": "2026-01-15T10:00:00.000Z",
"user_id": "user-123",
"data": {
"conversations": [],
"shares": [],
"ratings": [],
"access_requests": [],
"agent_bindings": [],
"tasks_archive": [],
"agents": [],
"memories": [],
"files": [],
"vector_stores": [],
"insights": [],
"gdpr_requests": []
},
"counts": {
"conversations": 0,
"shares": 0,
"ratings": 0,
"access_requests": 0,
"agent_bindings": 0,
"tasks_archive": 0,
"agents": 0,
"memories": 0,
"files": 0,
"vector_stores": 0,
"insights": 0,
"gdpr_requests": 0
},
"errors": []
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}Export a user's data (GDPR access)
Collects a user’s data across the platform: conversations, shares,
ratings, access requests, access bindings, archived tasks and owned
agents, plus their memories (Tools Memories), files and knowledge
bases (Knowledges) and insights (AI Insights). Each source is best
effort: failures are reported in errors.
Allowed for a platform administrator (platformRole superadmin or
root) on any user, and for any authenticated user on their own
user_id; other callers get 403. Rate limited to 10 calls per hour
per caller.
curl --request POST \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_id": "user-123"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_id: 'user-123'})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-export"
payload = { "user_id": "user-123" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"exported_at": "2026-01-15T10:00:00.000Z",
"user_id": "user-123",
"data": {
"conversations": [],
"shares": [],
"ratings": [],
"access_requests": [],
"agent_bindings": [],
"tasks_archive": [],
"agents": [],
"memories": [],
"files": [],
"vector_stores": [],
"insights": [],
"gdpr_requests": []
},
"counts": {
"conversations": 0,
"shares": 0,
"ratings": 0,
"access_requests": 0,
"agent_bindings": 0,
"tasks_archive": 0,
"agents": 0,
"memories": 0,
"files": 0,
"vector_stores": 0,
"insights": 0,
"gdpr_requests": 0
},
"errors": []
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}Authorizations
User-bound credential carrying an identity: either a session JWT
or a user access token (at:*) generated from the user settings UI.
Send as Authorization: Bearer <token>.
Org API keys (iak_*) are not accepted here - they carry
no user identity. Use the x-prismeai-api-key header instead
(see OrgApiKeyAuth).
Body
Identifier of the user whose data is exported.
128Response
Consolidated export.
Raw records per source, as stored by each workspace.
Hide child attributes
Hide child attributes
Was this page helpful?