> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Live audit-event stream (Server-Sent Events)

> **Token scope:** `account` · `org` · `project` — read-only tokens allowed.

A long-lived `text/event-stream`. Each `audit` event carries the new row's id, projectId, branchId, source, kind and createdAt — never its payload; read that from `GET /projects/{projectId}/events`. Send the last event `id` back as `Last-Event-ID` to have what followed replayed (the opening frame carries an `id` too, so an idle stream can resume); the replay overlaps, so an event can arrive twice — dedupe by its `id`. A `reset` event means the gap could not be replayed in full (or the server lost its own subscription): refetch every view. A `live` event (projectId, branchId, kind; no `id`) signals progress that records no audit row — a service coming online, a build or deploy changing stage, a template run advancing — so refetch what its kind names; it is never replayed. The server ends each stream after a few minutes; reconnect with the cursor.



## OpenAPI

````yaml /openapi/project.json get /projects/{projectId}/events/stream
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/events/stream:
    get:
      tags:
        - Audit
      summary: Live audit-event stream (Server-Sent Events)
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        allowed.


        A long-lived `text/event-stream`. Each `audit` event carries the new
        row's id, projectId, branchId, source, kind and createdAt — never its
        payload; read that from `GET /projects/{projectId}/events`. Send the
        last event `id` back as `Last-Event-ID` to have what followed replayed
        (the opening frame carries an `id` too, so an idle stream can resume);
        the replay overlaps, so an event can arrive twice — dedupe by its `id`.
        A `reset` event means the gap could not be replayed in full (or the
        server lost its own subscription): refetch every view. A `live` event
        (projectId, branchId, kind; no `id`) signals progress that records no
        audit row — a service coming online, a build or deploy changing stage, a
        template run advancing — so refetch what its kind names; it is never
        replayed. The server ends each stream after a few minutes; reconnect
        with the cursor.
      operationId: streamEvents
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
        - schema:
            type: string
          in: header
          name: last-event-id
          required: false
          description: >-
            the `id` of the last event received; what followed it is replayed
            first
      responses:
        '200':
          description: 'Server-Sent Events: `audit`, `live` and `reset` events'
          content:
            text/event-stream:
              schema:
                type: string
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````