Export your data
You can download a copy of what Udibo holds about your identity tenant at any time, without opening a support request. The dashboard's Export page offers two tiers because they carry different risk. The directory export has your users, applications, organizations and audit history. It is available today. The credential export covers password hashes and cannot yet be completed for your tenant.
Download the directory export
In the dashboard, open your tenant and choose Export in the Tenant group.
Under Directory export, choose Download directory export.
Your browser saves udibo-directory-export.ndjson. Downloading needs the
Export directory data permission. Admin and Owner carry it; Support does
not, and the page names the permission when you lack it. Each download is
recorded in the tenant's audit log. One person can download it 10 times per
tenant per hour; downloads past that are refused until the hour ends.
What the directory export contains
The file is NDJSON: one JSON object per line. The first line describes the file:
{
"type": "manifest",
"record": {
"format": "udibo.directory-export.v2",
"tenantId": "…",
"createdAt": "…",
"containsCredentials": false
}
}Every later line has the same shape, {"type": …, "record": {…}}. The types
appear in this order:
| Type | What each record holds |
|---|---|
tenant | The tenant's settings, with stored secrets removed |
user | Profile, email and verification state, disabled state, and both metadata buckets |
user_identity | A linked social or OIDC sign-in: provider, subject and email |
mfa_enrollment | Whether a user has an authenticator app, and how many recovery codes remain |
consent_grant | A user's stored consent for an application |
application | Name, type, grants and token lifetimes |
permission, resource_type | Your permission and resource-type registries |
organization, organization_role, organization_membership, organization_invitation, resource, role_assignment | Your organizations, roles, memberships, invitations and role assignments |
audit_event | Your audit log, as far back as it is kept |
Deleted records are included, with their deletedAt time set, so the file also
shows what was removed. The export contains no password hashes, no MFA secrets
and no client secrets.
What to use it for
Backups. Keep a regular copy of your directory under your own control.
Analytics and subject requests. Find everything held about one person. The file holds no credential material.
Leaving or migrating. Load users, linked sign-ins and organizations into another system. Without password hashes, plan how people will sign in there: a password reset, or a social provider they already linked. The migration guide covers the same questions for a move onto Udibo.
Credential export
The second tier is designed to hand over password hashes in a documented format, encrypted to a public key you supply. Optionally, it also includes MFA secrets. It is limited to owners through the Export credentials permission, asks you to confirm your password or a code, and waits 24 hours before anything can be downloaded. Any owner can cancel during that time, and every step is recorded in the audit log.
It cannot be completed for your tenant today. The confirmation step checks you against your tenant's own user directory. Your Udibo account is not in that directory, so the request is refused. The Owner-only form still appears on the Export page. Udibo does not currently offer another self-serve way to export password hashes for your tenant.
Export through the API
The directory export is also a management API operation,
GET /api/identity/{tenantId}/export/directory. Its scope is never issued to
machine tokens. Customers cannot get a token that carries it today; see
the management API.
Download from the dashboard instead.
For the audit log on its own, with filters and CSV or NDJSON output, see the audit log guide.
Limits today
No password hashes for customer tenants. The credential tier cannot be completed, as described above.
Some configuration is not in the file. Redirect URIs, application scope allowlists, webhook endpoints and identity-provider settings are not exported. Record them from the dashboard before you leave.
Audit history stops at the retention window. Events older than the retention period are already gone and cannot be exported.
No scheduled or pushed exports. Every export is a download you start.
Next: read the audit log guide, or review who can download exports in team access.
Last verified 2026-09-29.

