Skip to content

SIEM and Shared Signals

Receive a Security Event Token

POST/ssf/:wid/events

RFC 8935 push. The body is the SET itself (application/secevent+jwt), ES256 or RS256. Account and session events about a person freeze their agents under a security hold. Errors use RFC 8935’s shape.

#Authentication

Issuer signature

No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.

The body is a Security Event Token (application/secevent+jwt) signed with ES256 or RS256 by the transmitter you configured. Issuer, audience, freshness and replay are checked.

#Path parameters

widstringrequired

Workspace id