Skip to main content
This is the integration we recommend to every client. It is how the largest trading platforms run us in production, and it removes polling entirely. Three steps:
1

Fire and subscribe

The first time a token shows up on your side, call GET /api/audit-contract?chain=<chain>&address=<address>&async=true&subscribe=true. It returns immediately. If the token is already audited you get the audit in the response. Otherwise the finished verdict is pushed to you.
2

Hold one SSE stream

Keep a single long-lived GET /api/stream open with your API key. Every finished audit and every later verdict change (a safe/unsafe flip, an owner change, a honeypot or gate turning on or off, a closed-source token re-audited on its verified source) arrives there as an audit.changed event.
3

Serve your own cache

Store payload.audit as-is, keyed by audit.chain + audit.address exactly as returned. EVM addresses come back lowercase; a Solana mint keeps its case, so never lowercase it. It gets updated by what you receive on the stream. Your app reads only your cache.
On reconnect, send the last event id as Last-Event-ID and we replay what you missed. Dedupe on event_id. That is the whole loop. The rest of this page is the detail.

1. Fire the audit

Two possible responses:
  • { "audit": { ... } }: the token was already audited. Store it, you are done. The subscription is created either way.
  • { "status": "FETCHING" | "DECOMPILING" | "ANALYZING" }: a fresh audit is running. Do nothing. The finished verdict arrives on your stream.

2. Hold the stream

  • The stream carries events for the tokens you are subscribed to.
  • Solana works the same way: chain=solana and the token’s mint address, exactly as written. See Solana tokens.
  • evt.audit is the complete new verdict, the exact same object /audit-contract returns. Storing it is the entire update.
  • Reconnection and resume are automatic (Last-Event-ID): after a disconnect you receive everything you missed, in order.
  • We send a keepalive comment every 25 seconds. Reconnect on any disconnect, with your own backoff.

What it gives you

  • Every subscribed token is re-checked onchain continuously, and every verdict change is pushed: a safe/unsafe flip, an owner change or renounce, a gate or a honeypot turning on or off.
  • Re-audits we trigger are free, including closed-source tokens whose source verifies later: you receive the verified verdict automatically.
  • Your users always see the current verdict. There is no stale-data window.
  • Your credit spend drops: a subscription is 2 credits once per token, instead of refresh calls forever. See Credits & Billing.

What NOT to build

  • No polling loop. Do not re-call /audit-contract to keep a verdict fresh. Changes come to you.
  • No cache TTL. A stored verdict stays valid until an audit.changed event replaces it.
  • No re-fetch on push. The event already contains the full audit. Do not call the API back.
  • No status polling. With async=true&subscribe=true the result is pushed. Polling still works, it is just never needed.

Alternatives, when they fit better

  • Synchronous + subscribe: call /audit-contract with only subscribe=true and get the audit directly in the response (the call stays open while a fresh audit runs). The stream still handles all future changes.
  • Webhooks instead of SSE: we POST each event, HMAC-signed, to your HTTPS endpoint. Same payloads, same guarantees. See SSE & Webhooks.
  • Catch-up replay: GET /api/events?since=<last_id> returns anything you missed. It is the durable backstop behind both transports.
For LLMs and coding agents: the full documentation is one markdown file at https://docs.serializedaudit.io/llms-full.txt.