# Stream a DCT assistant chat response as SSE.

Endpoint: POST /ai/assistant/chat
Version: 3.30.0
Security: ApiKeyAuth

## Security:

  - `ApiKeyAuth` (unknown)
    apiKey in header Authorization

## Request fields (application/json):

  - `message` (string, required)
    The user's message to the assistant.

  - `session_id` (string)
    Optional conversation ID to continue a prior multi-turn session.

  - `service_context` (string)
    Selects the assistant implementation. Defaults to "synthetic".
    Example: synthetic

  - `context` (object)
    Optional key-value page context (e.g. the current webapp route) used only as an additive grounding and tool-prioritization hint. Never restricts which tools are available.
    Example: {"currentRoute":"/dct/synthetic"}

  - `sensitive_inputs` (object)
    Secret values (e.g. the database password) collected from the user out-of-band in response to a TOOL_CALL_SENSITIVE_INPUT event. Never forwarded to the LLM; injected into the tool at execution time.

  - `confirmation_decision` (string)
    Explicit decision for a pending TOOL_CALL_CONFIRMATION event, sent by the Allow once / Allow always / Cancel buttons. "approve-always" also suppresses future confirmation prompts for that tool for the remainder of the session. Falls back to parsing `message` as a yes/no reply when omitted.
    Enum: "approve", "approve-always", "reject"

## Response 200:

  - `200` (unknown)
    SSE stream of assistant events (text/event-stream).

## Response 200 fields (text/event-stream):

  - `type` (string)
    Enum: "TOKEN", "DONE", "ERROR", "TOOL_CALL_CONFIRMATION", "TOOL_CALL_START", "TOOL_CALL_RESULT", "TOOL_CALL_SENSITIVE_INPUT"

  - `content` (string)

  - `session_id` (string)

  - `tool_call_id` (string)

  - `tool_call_name` (string)

  - `tool_call_description` (string)

  - `tool_call_args` (string)

  - `requires_confirmation` (boolean)

  - `tool_call_result` (string)

  - `tool_call_failed` (boolean)

  - `required_sensitive_fields` (array)
    For TOOL_CALL_SENSITIVE_INPUT events, the secret field names the UI must collect from the user (e.g. ["password"]).

## Response default:

  - `default` (unknown)
    Unexpected Error

## Response default fields (application/json):

  - `error` (string)
    Error code for any failure

  - `error_description` (string)
    Error description for any failure

