> ## Documentation Index
> Fetch the complete documentation index at: https://docs.infrawatch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upgrade to the controlling browser WebSocket.

> Supply the exact `subprotocol` returned by the stream-ticket endpoint in
`Sec-WebSocket-Protocol`. Tickets are one-use, one controlling stream is
allowed per session, origins are validated, frames are bounded to 8 MiB,
and ownership, permission, entitlement, and session state are rechecked
every 30 seconds.




## OpenAPI

````yaml https://api.infrawatch.com/openapi.json?contract=d15375c get /projects/{project_uuid}/sessions/{session_uuid}/stream
openapi: 3.1.0
info:
  description: >-
    Customer-facing Infrawatch APIs. Authenticate with an API key unless an
    operation documents another supported credential.


    ### Infrawatch Public API


    Public API authenticated exclusively with Infrawatch API keys.


    ### Infrawatch Customer Alerting API


    Project alert rules, destinations, silences, inbox state, and delivery
    history.


    ### Infrawatch Remote Browser API


    Project-scoped interactive browser sessions owned by Platform Core.


    Session admission, lifecycle, RBAC, audit, usage, screenshot history, and

    stream tickets are Platform Core resources. The browser master is private

    infrastructure and its identifiers, proxy routes, process options, and

    credentials are never exposed by this API.


    A session and all of its evidence are private to the credential that created

    it. Project managers may list project session metadata, inspect one
    session's

    metadata, and terminate it, but cannot access its live stream, screenshots,

    or network events.


    Terminal session metadata and screenshots are retained indefinitely. A

    creator can replay a terminal session as a new queued resource while

    preserving a durable link to the source session.


    ### Infrawatch ESI API


    Customer-facing External Surface Intelligence API for project-scoped

    product data authenticated by an Infrawatch API key. API keys

    are constrained to their immutable owner's project ceiling and assigned

    ESI scopes; human project-manager fallback never expands an API key.

    Authorised API-key requests are rate-limited and consume monthly quota.


    ### Infrawatch Reports API


    Threat report discovery API authenticated by an Infrawatch API key.


    ### Infrawatch Public Rules API


    Account-aware rule authoring, taxonomy, catalogue, and runtime observations
    for API clients.


    ### Infrawatch Search API


    Search hosts, services, DNS records, and certificates. Complete
    percent-encoded query strings are limited to 65536 bytes.
  title: Infrawatch Customer API
  version: 1.0.0
servers:
  - description: Infrawatch customer API
    url: https://api.infrawatch.com/api/v1
security: []
tags:
  - name: API Usage
  - name: Projects
  - name: Alert destinations
  - name: Alert rules
  - name: Alert silences
  - name: Alerts
  - name: Browser sessions
  - name: Browser evidence
  - name: Browser streaming
  - name: Access
  - name: Inventory
  - name: Dangling DNS
  - name: Findings
  - name: Secrets
  - name: Typosquatting
  - name: Services
  - name: AI Surface
  - description: Search hosts, services, DNS records, certificates, and open directories.
    name: Search
  - name: Dashboard
  - name: Reports
  - name: Rules
  - name: Rule tags
  - name: Rule observations
paths:
  /projects/{project_uuid}/sessions/{session_uuid}/stream:
    servers:
      - url: https://api.infrawatch.com/api/v1
    get:
      tags:
        - Browser streaming
      summary: Upgrade to the controlling browser WebSocket.
      description: |
        Supply the exact `subprotocol` returned by the stream-ticket endpoint in
        `Sec-WebSocket-Protocol`. Tickets are one-use, one controlling stream is
        allowed per session, origins are validated, frames are bounded to 8 MiB,
        and ownership, permission, entitlement, and session state are rechecked
        every 30 seconds.
      operationId: streamBrowserSession
      parameters:
        - $ref: '#/components/parameters/browser_v1_ProjectUUID'
        - $ref: '#/components/parameters/browser_v1_SessionUUID'
        - in: header
          name: Sec-WebSocket-Protocol
          required: true
          schema:
            type: string
      responses:
        '101':
          description: WebSocket upgrade accepted.
        '401':
          $ref: '#/components/responses/browser_v1_Unauthorized'
        '403':
          $ref: '#/components/responses/browser_v1_Forbidden'
        '404':
          $ref: '#/components/responses/browser_v1_NotFound'
        '409':
          $ref: '#/components/responses/browser_v1_Conflict'
        '410':
          $ref: '#/components/responses/browser_v1_SessionEnded'
        '503':
          $ref: '#/components/responses/browser_v1_Unavailable'
      security: []
components:
  parameters:
    browser_v1_ProjectUUID:
      in: path
      name: project_uuid
      required: true
      schema:
        format: uuid
        type: string
    browser_v1_SessionUUID:
      in: path
      name: session_uuid
      required: true
      schema:
        format: uuid
        type: string
  responses:
    browser_v1_Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: Authentication or stream ticket required.
    browser_v1_Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: Permission, project access, entitlement, or stream origin denied.
    browser_v1_NotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: >-
        Project, session, or screenshot not found or not visible to this
        credential.
    browser_v1_Conflict:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: Idempotency conflict or an existing stream controller.
    browser_v1_SessionEnded:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: |
        The session's browser is gone and the session has been retired. This is
        terminal: reconnecting will not recover it.
    browser_v1_Unavailable:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/browser_v1_APIError'
      description: Browser, egress, Redis, or screenshot storage dependency is unavailable.
  schemas:
    browser_v1_APIError:
      properties:
        error:
          properties:
            code:
              type: string
            field_errors:
              items:
                properties:
                  code:
                    type: string
                  field:
                    type: string
                  message:
                    type: string
                required:
                  - field
                  - code
                  - message
                type: object
              type: array
            message:
              type: string
            request_id:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object

````