> ## Documentation Index
> Fetch the complete documentation index at: https://developers.vizito.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Exporting the visitor log

> The visitor log as an XLSX file, with the same columns and translated
headers as the Backoffice export.

Capped at **200 rows per call**. For a bulk pull, page through the
visitor log instead: it returns JSON and has no such ceiling.

Exporting requires an administrator. An API key is a global admin on its
locations, so it qualifies.




## OpenAPI

````yaml https://vizito.eu/openapi.yaml get /visitors/export/bycompany/{company_id}
openapi: 3.1.0
info:
  title: Vizito API
  version: 1.0.0
  description: |
    Read and write your Vizito visitor data over HTTPS.

    Every endpoint takes and returns JSON, and is authenticated with an API key
    created by a global admin on the Integrations page of the Backoffice.

    Almost every endpoint names a **location** — `company_id` in the API. Your
    key is pinned to a set of locations; naming one outside that set is refused
    with `403`. Start at `GET /companiesList`, the one endpoint that needs no
    location id.
  contact:
    name: Vizito support
    email: support@vizito.eu
    url: https://vizito.eu
  termsOfService: https://vizito.eu/terms
servers:
  - url: https://api.vizito.eu/api
    description: Production
security:
  - apiKey: []
tags:
  - name: Locations
    description: The locations your credential covers, and their configuration.
  - name: Visitors
    description: The visits themselves — one visitor is one visit, not a person.
  - name: Registered visitors
    description: Expected visitors — pre-register, invite, and sign in on arrival.
  - name: Hosts
    description: The people who can be visited.
  - name: Visit types
    description: The sign-in flows, and the questions they ask.
  - name: Entry points
    description: The doors and desks within a location.
  - name: Agreements
    description: The documents visitors sign, and the signed PDFs that come out.
  - name: Devices
    description: The kiosks at a location.
  - name: Reporting
    description: Counters, graphs and exports.
  - name: Webhooks
    description: The endpoint Vizito calls when something happens.
paths:
  /visitors/export/bycompany/{company_id}:
    get:
      tags:
        - Reporting
      summary: Exporting the visitor log
      description: |
        The visitor log as an XLSX file, with the same columns and translated
        headers as the Backoffice export.

        Capped at **200 rows per call**. For a bulk pull, page through the
        visitor log instead: it returns JSON and has no such ceiling.

        Exporting requires an administrator. An API key is a global admin on its
        locations, so it qualifies.
      operationId: exportVisitorLog
      parameters:
        - $ref: '#/components/parameters/companyId'
        - name: count
          in: query
          required: false
          description: >-
            Rows per page, at most 200. Pass both `count` and `page`, or
            neither.
          schema:
            type: integer
            maximum: 200
        - name: page
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
        - $ref: '#/components/parameters/languageId'
        - $ref: '#/components/parameters/sorting'
        - $ref: '#/components/parameters/filter'
      responses:
        '200':
          description: The export.
          content:
            application/vnd.openxmlformats-officedocument.spreadsheetml.sheet:
              schema:
                type: string
                format: binary
        '400':
          description: >
            `Dataset too large.` above 200 rows, `No data.` when nothing
            matched,

            or only one of `count` and `page` was sent.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Message'
        '403':
          $ref: '#/components/responses/Unauthorized'
components:
  parameters:
    companyId:
      name: company_id
      in: path
      required: true
      description: The location.
      schema:
        $ref: '#/components/schemas/ObjectId'
    languageId:
      name: language_id
      in: query
      required: false
      description: Language for configured text, e.g. `nl`. Falls back to English.
      schema:
        type: string
        example: en
    sorting:
      name: sorting
      in: query
      required: false
      style: deepObject
      explode: true
      description: |
        Sort per field, as `sorting[signed_in]=desc`. `asc` or `desc`.
      schema:
        type: object
        additionalProperties:
          type: string
          enum:
            - asc
            - desc
    filter:
      name: filter
      in: query
      required: false
      style: deepObject
      explode: true
      description: >
        Filter per field, as `filter[company]=acme`. Values match
        case-insensitively

        on any part of the stored value. A date field takes a range instead:

        `filter[signed_in][startDate]` and `filter[signed_in][endDate]`, both
        ISO 8601.
      schema:
        type: object
        additionalProperties: true
  schemas:
    Message:
      type: object
      properties:
        message:
          type: string
    ObjectId:
      type: string
      pattern: ^[0-9a-fA-F]{24}$
      description: A 24-character hexadecimal id.
      example: 5f2a1b9c4d3e2f0011223344
  responses:
    Unauthorized:
      description: |
        The credential was refused, or the endpoint is off limits to API keys.
        Every refusal answers identically — see the Authentication page.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                example: Invalid API key
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >
        An API key issued in the Backoffice, sent as `Authorization: Bearer
        vzk_<key id>_<secret>`.

        A Microsoft Entra ID access token obtained with the client credentials

        grant is accepted on the same header. The same value is also accepted in

        an `X-API-Key` header.

````

## Related topics

- [Signing a visitor in and out](/documentation/signing-in-a-visitor.md)
- [Listing visitors](/api-reference/visitors/listing-visitors.md)
- [Listing registered visitors](/api-reference/registered-visitors/listing-registered-visitors.md)
- [Introduction](/index.md)
- [Authentication](/api-reference/authentication.md)
