# Read a preview and refresh gateway access

Inspect the existing preview without starting it or resuming an archived workspace. Use the POST start endpoint with thread:update to start or resume. Supply frameOrigin as an exact HTTPS origin in the query. When a gateway URL exists, receive a fresh five-minute server-only credential. Relay HTTP and WebSocket requests through your authenticated backend; do not expose the credential to browsers. Responses the preview proxy generates itself carry X-Preview-State (starting, unavailable, not_found or unauthorized) with an unbranded body; relayed application responses never do, so your gateway can substitute its own page.

`GET /api/platform/v1/apps/{appId}/threads/{threadId}/preview`

Required permission: `thread:read`.

## Parameters

| Name | In | Type | Required | Description |

| --- | --- | --- | --- | --- |

| `frameOrigin` | query | `string<uri>` | Yes | Exact HTTPS dashboard origin, without a trailing slash. |

| `appId` | path | `string` | Yes | — |

| `threadId` | path | `string` | Yes | — |

## Example request

```bash
curl --request GET \
  --url https://api.hoplite.sh/api/platform/v1/apps/appId/threads/threadId/preview?frameOrigin=https%3A%2F%2Fdashboard.example.com \
  --header "X-Api-Key: $HOPLITE_API_KEY"
```

## 200 response

Success

Content type: `application/json`. Response type: `object`.

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `ok` | `boolean` | Yes | true | — |
| `preview` | `object` | Yes | — | — |
| `preview.status` | `string` | Yes | ready · unsupported · reconciling · blocked · starting · stopped · crashed · inactive | — |
| `preview.name` | `string` | No | min length 1 | — |
| `preview.port` | `integer` | No | min 1, max 65535 | — |
| `preview.reason` | `string` | No | — | — |
| `preview.url` | `string<uri>` | No | — | — |
| `preview.gateway` | `object` | Yes | — | — |
| `preview.gateway.header` | `string` | Yes | x-hoplite-preview-token | — |
| `preview.gateway.token` | `string` | Yes | — | — |
| `preview.gateway.expiresAt` | `string<date-time>` | Yes | — | — |

```json

```

## Status codes

- `200` — Success

- `400` — Invalid request

- `401` — Authentication required

- `403` — Permission, app scope or entitlement denied

- `404` — App, source or thread not found

- `409` — Idempotency conflict or request in progress

- `413` — Request too large

- `503` — Source storage or execution unavailable