# Receive a Security Event Token

Source: https://immiscible.fly.dev/docs/api/post-ssf-wid-events

`POST /ssf/:wid/events`

RFC 8935 push. The body is the SET itself (`application/secevent+jwt`), ES256 or RS256. Account and session events about a person freeze their agents under a security hold. Errors use RFC 8935's shape.

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. The body is a Security Event Token (`application/secevent+jwt`) signed with ES256 or RS256 by the transmitter you configured. Issuer, audience, freshness and replay are checked.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/ssf/$IMMISCIBLE_WORKSPACE/events" \
  -H "content-type: application/secevent+jwt" \
  --data-binary "$SECURITY_EVENT_TOKEN"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/ssf/$IMMISCIBLE_WORKSPACE/events', {
  method: 'POST',
  headers: {
    'content-type': 'application/secevent+jwt',
  },
  body: securityEventToken,
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

res = requests.post(
    "https://immiscible.fly.dev/ssf/$IMMISCIBLE_WORKSPACE/events",
    headers={
        "content-type": "application/secevent+jwt",
    },
    data=security_event_token,
)
print(res.status_code, res.json())
```
