Prerequisites
- An access token, exported as
AGENTAREA_TOKEN, the API base URL asAGENTAREA_URL, and your workspace slug asWORKSPACE. - Edit access to the stream. Adding or deleting a source is checked as
editon that stream. - A public base URL for webhooks. The URL a source hands out is built from the
same setting webhook triggers use; a sender cannot reach
localhost.
Steps
Create the stream
id. retention_days is how long events stay readable; leave it
out to take the deployment’s default.Store the provider's secret
A source never holds a secret. It refers to a workspace secret, and the
value is read from there each time a delivery is verified, so rotating the
secret needs no change to the source.Note the secret’s
id. On the stream’s page in the web app, the Add
source dialog can create the secret for you from the same picker.Add the source
GET /v1/workspaces/{workspace}/streams/source-types lists every type with
the credentials and settings it needs. Pass each credential as
{"secret_id": ...}:- Sentry
- GitHub
- YooKassa
webhook_url from the response as its Webhook URL, and tick the
resources to send (Issue, Error, Comment). The integration’s Client
Secret is the value you stored. Sentry signs each body with it into
Sentry-Hook-Signature; the event is named from Sentry-Hook-Resource
and the body’s action, so an issue created arrives as
issue.created.webhook_url. A source creation that lacks a
credential its verifier needs is refused with 422 — a source is never
created unverified. The generic and email types take an optional
signing secret: leave it out and one is issued, returned once as
signing_secret together with the signature_scheme to sign with.Give an agent read_stream
Attach the Its one tool,
agentarea/stream_events toolset to the agent that will read
the stream:read_stream(stream, after_sequence, limit), takes the
stream’s name or id and returns up to limit events (1–200) after
after_sequence, oldest first, with next_after and has_more. It reads
only streams of the agent’s workspace that the run’s user may read, strips
credential headers from each event’s data, and marks the data as
untrusted input from outside senders.Schedule the read
A cron trigger runs the agent weekly. The platform keeps no cursor for the
agent, so choose where
next_after lives:- The retention window. Give the stream a
retention_daysequal to the period, and have the agent read from0, passingnext_afterback whilehas_moreis true. Each run sees what the stream still holds. - A cursor the agent keeps. If the agent can write somewhere durable —
a note in a system it reaches through an MCP server, for example — have
it store
next_afterat the end of a run and pass it asafter_sequencethe next time, which returns exactly what is new.
Verify
Send a test delivery from the provider (GitHub: Recent Deliveries → Redeliver; Sentry: the integration’s test button; YooKassa: a test payment in atest_ shop). The provider sees 202 with {"status": "accepted", "sequence": n}, and the event appears on the stream’s page under Events.
List the sources to see what feeds the stream:
trigger_id: null.
Troubleshooting
400 Signature verification failed. The secret stored is not the one the provider signs with — for Sentry it must be the integration’s Client Secret, for GitHub the webhook’s Secret. For YooKassa it means the API did not confirm the object: a wrong shop id or key, atest_key against a live shop, or the object already moved on to another status.400 Webhook … not found. The source was deleted; its URL stops answering. Add a new source and give the sender the new URL.409when deleting a source or the stream. A webhook trigger owns that source. Delete the trigger, not the source.read_streamreturns an error naming the stream. The name is not a stream of the agent’s workspace, or the run’s user cannot read it.
Related
Event streams
How a stream records, deduplicates and fans out events.
Schedule an agent
Cron triggers, their limits, and how to confirm one fired.