1
Fire and subscribe
The first time a token shows up on your side, call
GET /api/audit-contract?chain=<chain>&address=<address>&async=true&subscribe=true.
It returns immediately. If the token is already audited you get the audit in the response. Otherwise the finished verdict is pushed to you.2
Hold one SSE stream
Keep a single long-lived
GET /api/stream open with your API key. Every finished audit and every later verdict change (a safe/unsafe flip, an owner change, a honeypot or gate turning on or off, a closed-source token re-audited on its verified source) arrives there as an audit.changed event.3
Serve your own cache
Store
payload.audit as-is, keyed by audit.chain + audit.address exactly as returned. EVM addresses come back lowercase; a Solana mint keeps its case, so never lowercase it. It gets updated by what you receive on the stream. Your app reads only your cache.Last-Event-ID and we replay what you missed. Dedupe on event_id.
That is the whole loop. The rest of this page is the detail.
1. Fire the audit
{ "audit": { ... } }: the token was already audited. Store it, you are done. The subscription is created either way.{ "status": "FETCHING" | "DECOMPILING" | "ANALYZING" }: a fresh audit is running. Do nothing. The finished verdict arrives on your stream.
2. Hold the stream
- The stream carries events for the tokens you are subscribed to.
- Solana works the same way:
chain=solanaand the token’s mint address, exactly as written. See Solana tokens. evt.auditis the complete new verdict, the exact same object/audit-contractreturns. Storing it is the entire update.- Reconnection and resume are automatic (
Last-Event-ID): after a disconnect you receive everything you missed, in order. - We send a keepalive comment every 25 seconds. Reconnect on any disconnect, with your own backoff.
What it gives you
- Every subscribed token is re-checked onchain continuously, and every verdict change is pushed: a safe/unsafe flip, an owner change or renounce, a gate or a honeypot turning on or off.
- Re-audits we trigger are free, including closed-source tokens whose source verifies later: you receive the verified verdict automatically.
- Your users always see the current verdict. There is no stale-data window.
- Your credit spend drops: a subscription is 2 credits once per token, instead of refresh calls forever. See Credits & Billing.
What NOT to build
- No polling loop. Do not re-call
/audit-contractto keep a verdict fresh. Changes come to you. - No cache TTL. A stored verdict stays valid until an
audit.changedevent replaces it. - No re-fetch on push. The event already contains the full audit. Do not call the API back.
- No status polling. With
async=true&subscribe=truethe result is pushed. Polling still works, it is just never needed.
Alternatives, when they fit better
- Synchronous + subscribe: call
/audit-contractwith onlysubscribe=trueand get the audit directly in the response (the call stays open while a fresh audit runs). The stream still handles all future changes. - Webhooks instead of SSE: we POST each event, HMAC-signed, to your HTTPS endpoint. Same payloads, same guarantees. See SSE & Webhooks.
- Catch-up replay:
GET /api/events?since=<last_id>returns anything you missed. It is the durable backstop behind both transports.
For LLMs and coding agents: the full documentation is one markdown file at
https://docs.serializedaudit.io/llms-full.txt.