> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybedefend.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Stream Security Champion messages

> Server-Sent Events (SSE) endpoint for streaming AI responses. Send a message and receive real-time token stream. Use heartbeat mode (no message) to maintain connection



## OpenAPI

````yaml get /project/{projectId}/security-champion/{conversationId}/stream
openapi: 3.0.0
info:
  title: Cybedefend API
  description: >-
    CybeDefend is an advanced API for application security analysis. Key
    features include OAuth 2.0 authentication, user/organization/project
    management, and REBAC-based permissions. It excels in static, dynamic, and
    IaC security analyses (SAST, DAST, IaC, etc.).
  version: '1.0'
  contact: {}
servers:
  - url: https://api-eu.cybedefend.com
    description: EU
  - url: https://api-us.cybedefend.com
    description: US
security: []
tags: []
paths:
  /project/{projectId}/security-champion/{conversationId}/stream:
    get:
      tags:
        - AI Agent
      summary: Stream Security Champion messages
      description: >-
        Server-Sent Events (SSE) endpoint for streaming AI responses. Send a
        message and receive real-time token stream. Use heartbeat mode (no
        message) to maintain connection
      operationId: AgentController_sendSecurityChampionMessageStream
      parameters:
        - name: projectId
          required: true
          in: path
          description: Project unique identifier
          schema:
            format: uuid
            type: string
        - name: conversationId
          required: true
          in: path
          description: Conversation unique identifier
          schema:
            type: string
        - name: vulnerabilityType
          required: false
          in: query
          description: Type of vulnerability
          schema:
            type: string
        - name: vulnerabilityId
          required: false
          in: query
          description: Vulnerability ID for context
          schema:
            type: string
        - name: message
          required: false
          in: query
          description: Message to send to the AI (optional - empty for heartbeat mode)
          schema:
            type: string
      responses:
        '200':
          description: SSE stream opened successfully - returns text/event-stream
        '401':
          description: Unauthorized - Invalid or missing authentication token
          content:
            application/json:
              schema:
                example:
                  message: Unauthorized
                  statusCode: 401
                  timestamp: '2025-02-18T12:31:18.491Z'
                  path: /example/path
        '403':
          description: Forbidden - Insufficient permissions
          content:
            application/json:
              schema:
                example:
                  message: Forbidden
                  statusCode: 403
                  timestamp: '2025-02-18T12:31:18.491Z'
                  path: /example/path

````