# Replay events for all apps

Replay the events of every app in publication order: platform.app.created, platform.app.updated and platform.app.deleted, sources, applies, builds, the app head, threads, runs, messages and tools. Each event names its app in appId. A credential restricted to specific apps receives only their events; when its apps change, earlier cursors return 410 cursor_scope_changed and an open stream closes with that error. Pass cursor with the same filters; limit defaults to 100, at most 500. Events are retained for seven days; an expired cursor returns 410 cursor_expired, after which you capture a new head and reread snapshots.

`GET /api/platform/v1/events`

Required permission: `thread:read`.

## Parameters

| Name | In | Type | Required | Description |

| --- | --- | --- | --- | --- |

| `threadId` | query | `string` | No | Only this thread's events. |

| `runId` | query | `string` | No | Only this run's events. |

| `types` | query | `string` | No | Comma-separated event types, at most 30. Reuse identical filters with a returned cursor. |

| `cursor` | query | `string` | No | A head, nextCursor or event cursor. Omit to start at the oldest retained event. |

| `limit` | query | `integer` | No | Maximum events per page, 1-500 (default 100). |

## Example request

```bash
curl --request GET \
  --url https://api.hoplite.sh/api/platform/v1/events \
  --header "X-Api-Key: $HOPLITE_API_KEY"
```

## 200 response

Success

Content type: `application/json`. Response type: `object`.

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `ok` | `boolean` | Yes | true | — |
| `events` | `object[]` | Yes | — | — |
| `events.id` | `string` | Yes | — | — |
| `events.orgId` | `string` | Yes | — | — |
| `events.projectId` | `string` | Yes | — | — |
| `events.threadId` | `string` | Yes | — | — |
| `events.runId` | `string` | Yes | — | — |
| `events.sequence` | `string` | Yes | pattern ^\d+$ | — |
| `events.type` | `string` | Yes | — | — |
| `events.data` | `object` | Yes | — | — |
| `events.data.id` | `string` | Yes | — | Resource ID: thread, run, message, tool call, approval, checkpoint, preview, pull request, automation execution, operation receipt, platform source, apply or build. platform.head.updated uses the project ID and platform.app.* events the app ID. |
| `events.data.status` | `string` | No | — | Current resource status or state, when the resource has one. |
| `events.data.role` | `string` | No | — | Message role for message.persisted. |
| `events.data.sourceEventId` | `string` | No | — | Run event that requested an approval. |
| `events.data.sourceId` | `string` | No | — | Platform source version: an apply's result, a build's input or the project's new head. |
| `events.data.revision` | `integer` | No | min -9007199254740991, max 9007199254740991 | Platform project head revision for platform.head.updated. |
| `events.data.sha256` | `string` | No | — | Content hash of an imported platform source. |
| `events.data.byteSize` | `integer` | No | min -9007199254740991, max 9007199254740991 | Size of an imported platform source archive. |
| `events.data.fileCount` | `integer` | No | min -9007199254740991, max 9007199254740991 | Files in an imported platform source. |
| `events.data.artifactSha256` | `string` | No | — | Hash of a ready platform build artifact. |
| `events.data.externalId` | `string` | No | — | Your identifier for the app on platform.app.* events; null when unset or cleared. |
| `events.data.createdAt` | `string<date-time>` | No | — | When the app was created, on platform.app.* events. |
| `events.data.updatedAt` | `string<date-time>` | No | — | When the app was last updated, on platform.app.* events. |
| `events.occurredAt` | `string<date-time>` | Yes | — | — |
| `events.publishedAt` | `string<date-time>` | Yes | — | — |
| `events.cursor` | `string` | Yes | — | — |
| `events.appId` | `string` | Yes | — | — |
| `nextCursor` | `string` | Yes | — | — |
| `hasMore` | `boolean` | Yes | — | — |

```json

```

## Status codes

- `200` — Success

- `400` — Invalid request

- `401` — Authentication required

- `403` — Permission, app scope or entitlement denied

- `404` — App, source or thread not found

- `409` — Idempotency conflict or request in progress

- `410` — Event cursor expired

- `413` — Request too large

- `503` — Source storage or execution unavailable