> ## Documentation Index
> Fetch the complete documentation index at: https://docs.secapi.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# POST /v1/stream_subscriptions

> Create a stream subscription for event polling and replay

Create a stream subscription for event polling and replay

<Info>
  Audience: signed-in organization administrator.
</Info>

## Canonical metadata

* `requestId`
* `traceparent`

## Example request

<RequestExample>
  ```bash theme={null}
  curl -X POST \
    -H "Authorization: Bearer $SECAPI_BEARER_TOKEN" \
    -H "secapi-version: 2026-03-19" \
    -H "content-type: application/json" \
    -d '{"description":"Monitor matches polling stream","eventTypes":["monitor.match"],"transport":"poll","livemode":false}' \
    "https://api.secapi.ai/v1/stream_subscriptions"
  ```
</RequestExample>

<Info>
  This organization control-plane action requires a signed-in WorkOS browser session. Do not give an API key or an autonomous agent authority to create, change, test, replay, rotate, or delete it.
</Info>

## Example response

<ResponseExample>
  ```json theme={null}
  {
    "object": "stream_subscription",
    "id": "strm_2ZK8Q1W9F4M6P7R3",
    "createdAt": "2026-06-25T15:00:00.000Z",
    "updatedAt": "2026-06-25T15:00:00.000Z",
    "livemode": false,
    "orgId": "org_example_123",
    "description": "Monitor matches polling stream",
    "eventTypes": [
      "monitor.match",
      "webhook.test"
    ],
    "transport": "poll",
    "status": "active",
    "cursor": null,
    "lastEventAt": null,
    "requestId": "req_2ZK8Q1W9F4M6P7R3"
  }
  ```
</ResponseExample>

## Give this prompt to your agent

<Prompt>
  Explain the required fields for POST /v1/stream\_subscriptions, but direct the user to complete the change in the signed-in SEC API dashboard. Do not attempt the mutation with an API key or an autonomous agent. Preserve requestId and traceparent when the dashboard or a human-authenticated session returns them.
</Prompt>

## Failure posture

* treat non-2xx responses as contract-aware failures, not free-form errors
* preserve `requestId` and `traceparent` in logs and downstream reports
* if provenance or freshness metadata is present, return it unchanged so trust is not lost in the handoff
