curl --request GET \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download \
--header 'Authorization: Bearer <token>'import requests
url = "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_bodyPolicy Number,Insured Name,Transaction Action,Policy Version,Effective Date,Transaction Timestamp,Policy Start Date,Policy End Date,Created At,Created By,Policy Premium,Policy Premium Change
POL-2025-001,Mercy General Hospital,NEW_BUSINESS,1,2025-01-01,2025-01-15T10:30:00.000Z,2025-01-01,2026-01-01,2025-01-15T10:30:00.000Z,api-key|abc123,85000,85000
POL-2025-001,Mercy General Hospital,ENDORSE,2,2025-06-01,2025-06-01T14:00:00.000Z,2025-01-01,2026-01-01,2025-06-01T14:00:00.000Z,api-key|abc123,102000,17000Download Bordereau Export Run
Downloads the file a succeeded bordereau export run produced — the file
half of POST /policies/bordereau/export-runs.
By default (format=csv, or no format at all) the response is the CSV
itself (text/csv; charset=utf-8, served as an attachment), streamed from
storage: the first row is the header (each requested column’s header, in
the requested order), followed by one row per policy transaction. A
zero-row export downloads as a header-only CSV.
format=xlsx downloads the same export as an Excel workbook
(application/vnd.openxmlformats-officedocument.spreadsheetml.sheet): one
worksheet with the CSV’s rows and columns, where each cell is typed by its
column’s spreadsheet type: numbers, dates and date-times are real Excel
numbers, dates and date-times carrying that column’s number format, and
everything else is text. The CSV carries the same values as their
formatted text. A value that doesn’t fit its column’s type is written as
its text in both files. The workbook is produced server-side on the
first request and cached, so repeat downloads are cheap. An export whose
rows would not fit on one Excel worksheet (1,048,576 rows including the
header) is refused with a 409 — the CSV download still works and carries
every row.
Only a succeeded run downloads. Every other status is a 404:
queued and running have no file yet, failed never produced one, and
expired means the file passed its retention horizon and was deleted. Poll
GET .../export-runs/{runId} to learn which — the poll stays readable
for every status — and start a new export when the run failed or expired.
The file stays downloadable until the run’s expiresAt, and can be
downloaded any number of times until then.
Required permission: policy.view
curl --request GET \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download \
--header 'Authorization: Bearer <token>'import requests
url = "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/bordereau/export-runs/{runId}/download")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_bodyPolicy Number,Insured Name,Transaction Action,Policy Version,Effective Date,Transaction Timestamp,Policy Start Date,Policy End Date,Created At,Created By,Policy Premium,Policy Premium Change
POL-2025-001,Mercy General Hospital,NEW_BUSINESS,1,2025-01-01,2025-01-15T10:30:00.000Z,2025-01-01,2026-01-01,2025-01-15T10:30:00.000Z,api-key|abc123,85000,85000
POL-2025-001,Mercy General Hospital,ENDORSE,2,2025-06-01,2025-06-01T14:00:00.000Z,2025-01-01,2026-01-01,2025-06-01T14:00:00.000Z,api-key|abc123,102000,17000Authorizations
User-principal OAuth 2.0 Bearer authentication. Send a user-scoped Auth0 access token (audience = the app API audience) as Authorization: Bearer <jwt>. The request resolves to the user's identity and is authorized by their Role on the {companyId} in the path — the same role-based permissions the web app enforces. This is the path the MCP connector uses to act on a user's behalf; endpoints that accept it list both BearerAuth and ApiKeyAuth.
Path Parameters
Company identifier
The run identifier returned by POST /policies/bordereau/export-runs. Runs are scoped to their company AND
their kind: a run id belonging to another company, or to an entity
export run rather than a bordereau one, returns 404, exactly as an id
that exists nowhere does.
Query Parameters
The file format to download: csv (the default) for the export's CSV,
xlsx for its Excel workbook rendition. Any other value is a 400 —
never silently defaulted, because that would serve a different file
than the one asked for.
csv, xlsx Response
The exported file, streamed as an attachment named
bordereau-export-{runId}.{format}.
The response is of type string.
