Live audit-log stream (SSE)

API key required (`Authorization: Bearer <key>` header, or the `apiKey` query param — EventSource cannot set headers). A server-sent events feed of the caller's tenant audit log: emits `event: receipt` frames with `id:` set to the receiptId, plus `: ping` heartbeats while held. The server long-polls up to `timeout` seconds (default 10, max 12 — the Lambda timeout is 15s) waiting for new receipts, then closes the connection; the client reconnects and resumes with `since` (or `Last-Event-ID`, which EventSource sends automatically). Omit `since` to replay the most recent `replay` receipts (default 20, max 50, 0 for none) and then go live. If `since` names a receipt that has aged out of the recent window, the stream starts live from now rather than erroring. `decision` filters the stream to one decision (case-insensitive) — e.g. `?decision=DENY` streams only stopped writes. The filter applies to the initial replay and to every frame emitted while held. The resume cursor still tracks *every* receipt, so a filtered stream never skips or duplicates on reconnect. This is the SIEM ingestion path: pipe every gated write into Splunk, Datadog, or your warehouse in near real time. One tenant's stream never carries another tenant's receipts, and each event is a complete receipt — no joins needed downstream.

Authentication

AuthorizationBearer
Your Writ API key (writ_...) as an Authorization Bearer header. The sponsor token (writ_sp_...) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.

Query parameters

sincestringOptional

receiptId to resume after; only newer receipts replay. Falls back to Last-Event-ID header.

timeoutintegerOptionalDefaults to 10

Seconds to hold the connection waiting for new receipts. Clamped to 1-12; non-numeric values fall back to 10.

replayintegerOptionalDefaults to 20

Recent receipts to replay on connect when since is omitted. Clamped to 0-50; non-numeric values fall back to 20.

decisionenumOptional

Filter the stream to one decision (case-insensitive). Applies to the replay and to frames emitted during the hold. Anything else returns 400.

Allowed values:
apiKeystringOptional

API key as an alternative to the Authorization header (for EventSource).

Response

text/event-stream — event: receipt frames with id: set to the receiptId and the full receipt JSON as data:, plus : ping heartbeats.

Errors

400
Bad Request Error
401
Unauthorized Error