> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Device Events

> Generic device-telemetry sink for the desktop agent: lifecycle
(app_started / app_stopped / crashed), usage, and tamper.

Persisted as audit records keyed to the device so the admin can see who is
running the agent, who closed it, and who tampered with it (see
docs/DEVICE_PROTECTION_AND_TELEMETRY_PLAN.md, Part B). This complements the
dedicated /tamper-events endpoint, which the durable tamper drainer keeps
using; an unknown ``type`` is recorded as ``lifecycle`` so a newer agent
never has its telemetry silently dropped by an older server.



## OpenAPI

````yaml /api-reference/openapi.json post /api/runtime-security/agent/device-events
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/agent/device-events:
    post:
      tags:
        - runtime-security-agent
      summary: Device Events
      description: >-
        Generic device-telemetry sink for the desktop agent: lifecycle

        (app_started / app_stopped / crashed), usage, and tamper.


        Persisted as audit records keyed to the device so the admin can see who
        is

        running the agent, who closed it, and who tampered with it (see

        docs/DEVICE_PROTECTION_AND_TELEMETRY_PLAN.md, Part B). This complements
        the

        dedicated /tamper-events endpoint, which the durable tamper drainer
        keeps

        using; an unknown ``type`` is recorded as ``lifecycle`` so a newer agent

        never has its telemetry silently dropped by an older server.
      operationId: device_events_api_runtime_security_agent_device_events_post
      parameters:
        - name: X-Blindsight-Device-Token
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Blindsight-Device-Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DeviceEventBatch'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    DeviceEventBatch:
      properties:
        events:
          items:
            $ref: '#/components/schemas/DeviceEvent'
          type: array
          title: Events
      type: object
      title: DeviceEventBatch
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    DeviceEvent:
      properties:
        type:
          type: string
          maxLength: 32
          title: Type
          default: lifecycle
        kind:
          type: string
          maxLength: 64
          title: Kind
        detail:
          anyOf:
            - type: string
              maxLength: 2000
            - type: 'null'
          title: Detail
        occurred_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Occurred At
      type: object
      required:
        - kind
      title: DeviceEvent
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````