What event streaming is
Event streaming gives you a persistent, real-time connection to theAuth events via Server-Sent Events (SSE). Whenever your code callsstream.emit() (an agent is revoked, a budget is exceeded, and so on), connected clients receive it, no polling required.
Events are also persisted to the database so you can replay anything you missed.
Streaming vs webhooks
Webhooks and SSE are separate mechanisms with separate event sets: the webhook module delivers the events you pass totheauth.webhooks.emit(), and the stream delivers the events you pass to stream.emit(). You can emit the same occurrence to both.
Use webhooks when you need durable delivery to an external service. Use event streaming when you need a live view, a security dashboard, an admin feed, or a CI script watching for
budget.exceeded.
Setup
handleRequest takes a Web Request and returns a Web Response, or null for any request that is not an SSE request: the method must be GET, the path must end in /events/stream, and the Accept header must include text/event-stream. This makes it safe to call inside a catch-all handler. Node (req, res) handlers such as Express need a small adapter to convert to and from Request and Response.Connecting from a browser
The browser’s built-inEventSource API handles reconnection automatically.
Authorization header instead, use the eventsource package or a fetch-based polyfill, since the native EventSource does not support custom headers.
Connecting from Node.js
Event types
The type column below describes the intended meaning of each type.Filtering events
Pass atypes query parameter with a comma-separated list to receive only the events you care about.
types are ignored; if none are valid, the connection receives all types. You can also restrict the types at the module level, which filters live delivery.
Replay and cursor
Events passed toemit() are persisted in the theauth_stream_events table (a failed write is ignored). If a client disconnects and reconnects, pass since to receive everything it missed, oldest first, after the connected event. since must be an ISO 8601 timestamp with an offset or Z; anything else is rejected with a 400.
Last-Event-ID header as a fallback cursor, but it parses the value as a date. Each SSE message uses your event id as its id: field, so the header only works for replay if your event IDs are timestamps (for example ISO strings). With UUID IDs, as in the examples here, an automatic browser reconnect replays nothing, so track the last timestamp yourself and pass since.
Replay applies the connection’s types filter, or the module-level eventTypes if the client sent none. A client that passes its own types can replay types outside the module-level list, and the programmatic replay() method does not apply the module-level list at all.
replay returns up to 1000 events in descending order (newest first). Apply your own pagination on top if you need to page through large windows.
Auth requirements
By defaultrequireAuth: true. Every connection must present a Bearer token, either in the Authorization header or as the token query parameter.
validateToken returns null, the stream sends a single error event and closes (the HTTP status is still 200).
Configuration
Connection limits
The stream rejects connections beyondmaxConnections with a 503 Too many connections response. Size this based on your deployment: a single process can comfortably handle hundreds of concurrent SSE connections; above that, consider a pub/sub layer (Redis, NATS) in front of the module.
Heartbeat
The server sends: heartbeat comments on the configured interval (default 30 seconds) to keep load balancers and proxies from closing idle connections. No action is required on the client side, EventSource ignores comment lines.
Emitting events from plugins
Any part of your application can emit to the stream.Module API
Related
Webhooks
Durable HTTP delivery for the same events to external services.
Audit trail
The audit log. Replay reads from the separate stream events table, not from audit entries.
Hooks
Call
stream.emit() from lifecycle hooks such as onViolation and onAgentRevoke.Dashboard
Visual monitoring of agents and audit entries.