> ## Documentation Index
> Fetch the complete documentation index at: https://docs.meshqu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Stream decisions (SSE)

> Server-Sent Events stream for real-time decision updates.

**v1 contract**: live push stream. Missed events during disconnect are NOT
replayed — clients needing completeness after reconnect should re-query
`GET /v1/decisions` and reconcile locally.

Events:
- **connected**: Sent once, after the server's LISTEN subscription is active
- **decision**: New decision recorded (pushed via Postgres LISTEN/NOTIFY)
- **heartbeat**: Keep-alive ping (every 15s)
- **error**: Stream-level error (connection will close)

Example:
```javascript
const es = new EventSource('/v1/decisions/stream', {
  headers: { 'Authorization': 'Bearer <api-key>' }
});
es.addEventListener('decision', (e) => console.log(JSON.parse(e.data)));
```



## OpenAPI

````yaml /api/openapi.json get /v1/decisions/stream
openapi: 3.1.0
info:
  title: MeshQu API
  description: >-
    Governance infrastructure for policy-aware AI decisions. MeshQu does not run
    tools. It governs decisions about them.
  version: 1.9.0
  contact:
    name: MeshQu Support
    email: support@meshqu.com
  license:
    name: Proprietary
servers:
  - url: https://api.meshqu.com
    description: Deployed environment
security:
  - apiKey: []
    tenantId: []
tags:
  - name: Operations
    description: Health, readiness, metrics, and signing keys
  - name: Policies
    description: Policy management
  - name: Policy Groups
    description: Policy group management
  - name: Decisions
    description: Policy evaluation and recording
  - name: Chains
    description: Decision chain verification and sealing
  - name: Receipts
    description: Public receipt and bundle retrieval
  - name: Forms
    description: Attestation forms and public submission
  - name: Alerts
    description: Alert management and webhooks
  - name: Audit
    description: Audit log retrieval and verification
  - name: API Keys
    description: API key administration
  - name: Admin
    description: Tenant and platform administration
  - name: Dashboard
    description: Console dashboard data
  - name: Metrics
    description: Decision and overview metrics
  - name: Fields
    description: Field catalogue
  - name: Settings
    description: Tenant settings
  - name: Rule Creation Logs
    description: Rule authoring telemetry
paths:
  /v1/decisions/stream:
    get:
      tags:
        - Decisions
      summary: Stream decisions (SSE)
      description: >-
        Server-Sent Events stream for real-time decision updates.


        **v1 contract**: live push stream. Missed events during disconnect are
        NOT

        replayed — clients needing completeness after reconnect should re-query

        `GET /v1/decisions` and reconcile locally.


        Events:

        - **connected**: Sent once, after the server's LISTEN subscription is
        active

        - **decision**: New decision recorded (pushed via Postgres
        LISTEN/NOTIFY)

        - **heartbeat**: Keep-alive ping (every 15s)

        - **error**: Stream-level error (connection will close)


        Example:

        ```javascript

        const es = new EventSource('/v1/decisions/stream', {
          headers: { 'Authorization': 'Bearer <api-key>' }
        });

        es.addEventListener('decision', (e) => console.log(JSON.parse(e.data)));

        ```
      operationId: getV1DecisionsStream
      responses:
        '200':
          description: SSE stream
          content:
            application/json:
              schema:
                type: string
                description: SSE stream
components:
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: mqu_<token>
      description: >-
        MeshQu API key passed as a bearer token: `Authorization: Bearer mqu_…`.
        Mint one in the console (Settings → API keys).
    tenantId:
      type: apiKey
      name: X-MeshQu-Tenant-Id
      in: header
      description: >-
        Tenant UUID for multi-tenant isolation. Required on all authenticated
        routes — validated before authentication (middleware/tenant.ts), so a
        missing or non-UUID header returns 400 (MISSING_TENANT_ID /
        INVALID_TENANT_ID) before the API key is checked.

````