Compose Clinic — API

Paste the Kotlin, get a senior Compose review and a full refined rewrite.

API tokens Open the app

Review your Compose UI from your own scripts

Send Kotlin — one file, a screen with its ViewModel, several files with file-name comment headers, or a whole grab-bag of composables — and get back one JSON object: an honest sound / refactor / rework verdict, a health check across five UI-code areas, findings ranked by severity each with corrected Kotlin, a twelve-item checklist scored against the paste, and a complete refined rewrite of what you pasted. Everything this app does goes through the SkillSafe App API — plain JSON over HTTPS — so you can wire the review into a CI gate, a pull-request bot, or a pre-merge check that refuses a diff introducing a fresh mutableStateOf with no remember around it. Every code step below is shown in cURL, Python, JavaScript, Go, Java, Ruby, PHP and C#; pick a language once and the whole page follows.

Basics

Base URL: https://api.skillsafe.ai/v1/app-api, app slug compose-clinic. Every request sends Authorization: Bearer <token> and JSON bodies with Content-Type: application/json. Responses are wrapped in an envelope: {"data": …} on success, {"error": {"code", "message"}} on failure. The review itself is produced by the gpt-terra model. Estimates are free; runs are metered against your credit balance. There is a single run task — one paste in, one review out, no follow-up calls and no session state to carry.

StatusMeaning
401Missing or expired token — create a new session.
402Not enough credits — top up at skillsafe.ai/account/credits.
403The token isn't allowed to do this (e.g. a guest reviewing a very large paste).
404Unknown job or record id.
5xxTransient platform error — retry with backoff.

Browsers enforce CORS for this API, so run these examples from a server, script or terminal — not from another website's frontend.

Step 0 — A tiny client

Every task below is a single HTTP call, so start with a short helper that adds the auth header, sends JSON and unwraps the data envelope. The later steps reuse it.

export API="https://api.skillsafe.ai/v1/app-api"
export TOKEN="YOUR_TOKEN"      # see step 1

# every call looks like:
#   curl -s "$API/..." -H "Authorization: Bearer $TOKEN" [-d '{json}']
# jq is used below to pull fields out of the {"data": ...} envelope
import json, requests

API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = "YOUR_TOKEN"  # see step 1 — read it from your shell environment in real code

def api(method, path, body=None, **headers):
    res = requests.request(method, API + path, json=body,
                           headers={"Authorization": f"Bearer {TOKEN}", **headers})
    payload = res.json()
    if not res.ok:
        raise RuntimeError(payload.get("error", {}).get("message", res.reason))
    return payload["data"]
// Node 18+ (built-in fetch)
const API = "https://api.skillsafe.ai/v1/app-api";
const TOKEN = "YOUR_TOKEN"; // see step 1 — read it from your shell environment in real code

async function api(method, path, body, extraHeaders = {}) {
  const res = await fetch(API + path, {
    method,
    headers: { Authorization: `Bearer ${TOKEN}`, "Content-Type": "application/json", ...extraHeaders },
    body: body === undefined ? undefined : JSON.stringify(body),
  });
  const json = await res.json();
  if (!res.ok) throw new Error(json.error?.message ?? res.statusText);
  return json.data;
}
package main

import (
	"bytes"
	"encoding/json"
	"fmt"
	"net/http"
	"os"
)

const API = "https://api.skillsafe.ai/v1/app-api"

var token = os.Getenv("SKILLSAFE_TOKEN") // see step 1

func call(method, path string, body, out any) error {
	var buf bytes.Buffer
	if body != nil {
		json.NewEncoder(&buf).Encode(body)
	}
	req, _ := http.NewRequest(method, API+path, &buf)
	req.Header.Set("Authorization", "Bearer "+token)
	req.Header.Set("Content-Type", "application/json")
	res, err := http.DefaultClient.Do(req)
	if err != nil {
		return err
	}
	defer res.Body.Close()
	var env struct {
		Data  json.RawMessage `json:"data"`
		Error *struct{ Message string `json:"message"` } `json:"error"`
	}
	json.NewDecoder(res.Body).Decode(&env)
	if res.StatusCode >= 400 {
		return fmt.Errorf("api %s %s: %s", method, path, env.Error.Message)
	}
	if out == nil {
		return nil
	}
	return json.Unmarshal(env.Data, out)
}
// Java 17+, no dependencies. Pair with your JSON library (Jackson, Gson…)
// to read fields out of the returned envelope.
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class SkillSafe {
    static final String API = "https://api.skillsafe.ai/v1/app-api";
    static final String TOKEN = System.getenv("SKILLSAFE_TOKEN"); // see step 1
    static final HttpClient HTTP = HttpClient.newHttpClient();

    static String api(String method, String path, String jsonBody) throws Exception {
        var req = HttpRequest.newBuilder(URI.create(API + path))
            .header("Authorization", "Bearer " + TOKEN)
            .header("Content-Type", "application/json")
            .method(method, jsonBody == null
                ? HttpRequest.BodyPublishers.noBody()
                : HttpRequest.BodyPublishers.ofString(jsonBody))
            .build();
        var res = HTTP.send(req, HttpResponse.BodyHandlers.ofString());
        if (res.statusCode() >= 400) throw new RuntimeException(res.body());
        return res.body(); // envelope: {"data": …}
    }
}
require "net/http"
require "json"

API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = ENV.fetch("SKILLSAFE_TOKEN") # see step 1

def api(method, path, body = nil)
  uri = URI(API + path)
  req = Net::HTTP.const_get(method.capitalize).new(uri)
  req["Authorization"] = "Bearer #{TOKEN}"
  req["Content-Type"] = "application/json"
  req.body = body.to_json if body
  res = Net::HTTP.start(uri.host, uri.port, use_ssl: true) { |h| h.request(req) }
  payload = JSON.parse(res.body)
  raise (payload.dig("error", "message") || res.message) unless res.is_a?(Net::HTTPSuccess)
  payload["data"]
end
<?php
const API = "https://api.skillsafe.ai/v1/app-api";
$TOKEN = getenv("SKILLSAFE_TOKEN"); // see step 1

function api(string $method, string $path, ?array $body = null): mixed {
    global $TOKEN;
    $ch = curl_init(API . $path);
    curl_setopt_array($ch, [
        CURLOPT_CUSTOMREQUEST  => $method,
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_HTTPHEADER     => [
            "Authorization: Bearer $TOKEN",
            "Content-Type: application/json",
        ],
        CURLOPT_POSTFIELDS     => $body === null ? null : json_encode($body),
    ]);
    $payload = json_decode(curl_exec($ch), true);
    $status  = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
    curl_close($ch);
    if ($status >= 400) {
        throw new Exception($payload["error"]["message"] ?? "HTTP $status");
    }
    return $payload["data"];
}
// .NET 8+
using System.Net.Http.Json;
using System.Text.Json;

static class SkillSafe
{
    const string Api = "https://api.skillsafe.ai/v1/app-api";
    static readonly HttpClient Http = new();

    static SkillSafe() =>
        Http.DefaultRequestHeaders.Authorization =
            new("Bearer", Environment.GetEnvironmentVariable("SKILLSAFE_TOKEN")); // see step 1

    public static async Task<JsonElement> ApiAsync(HttpMethod method, string path, object? body = null)
    {
        var req = new HttpRequestMessage(method, Api + path);
        if (body != null) req.Content = JsonContent.Create(body);
        var res = await Http.SendAsync(req);
        var json = await res.Content.ReadFromJsonAsync<JsonElement>();
        if (!res.IsSuccessStatusCode)
            throw new Exception(json.GetProperty("error").GetProperty("message").GetString());
        return json.GetProperty("data");
    }
}

Step 1 — Get a token

POST /guest

A guest token lets you check balances and estimate costs for free. For metered review runs billed to your own account, use your personal token: open the token page, sign in with SkillSafe, and press Copy shell export — it puts export SKILLSAFE_TOKEN="…" on your clipboard, which every example below reads. Treat the token like a password: it can spend your credits. For fully headless scripts, POST /guest mints a guest token with no browser involved.

curl -s -X POST "$API/guest" \
  -H "Content-Type: application/json" \
  -d '{"slug":"compose-clinic"}' | jq -r '.data.token'
token = api("POST", "/guest", {"slug": "compose-clinic"})["token"]
const { token } = await api("POST", "/guest", { slug: "compose-clinic" });
var guest struct{ Token string `json:"token"` }
err := call("POST", "/guest", map[string]string{"slug": "compose-clinic"}, &guest)
String envelope = api("POST", "/guest", """
    {"slug":"compose-clinic"}""");
// token is at data.token in the returned JSON
token = api("POST", "/guest", { slug: "compose-clinic" })["token"]
$token = api("POST", "/guest", ["slug" => "compose-clinic"])["token"];
var guest = await SkillSafe.ApiAsync(HttpMethod.Post, "/guest",
    new { slug = "compose-clinic" });
var token = guest.GetProperty("token").GetString();

The app stores this browser's token under the localStorage key skillsafe_app_token:compose-clinic, on the app's own origin. The token page reads and manages it for you — you never need to open developer tools.

Step 2 — Check who you are and your balance

GET /me

Returns subject_type ("user" or "guest"), subject_id and your credits balance. Check this before reviewing a large paste.

curl -s "$API/me" -H "Authorization: Bearer $TOKEN" | jq '.data'
me = api("GET", "/me")
print(me["subject_type"], me["credits"])
const me = await api("GET", "/me");
console.log(me.subject_type, me.credits);
var me struct {
	SubjectType string `json:"subject_type"`
	Credits     int64  `json:"credits"`
}
err := call("GET", "/me", nil, &me)
String envelope = api("GET", "/me", null);
// data.subject_type, data.credits
me = api("GET", "/me")
puts "#{me["subject_type"]}: #{me["credits"]} credits"
$me = api("GET", "/me");
echo "{$me['subject_type']}: {$me['credits']} credits\n";
var me = await SkillSafe.ApiAsync(HttpMethod.Get, "/me");
Console.WriteLine($"{me.GetProperty("subject_type")}: {me.GetProperty("credits")} credits");

Step 3 — Estimate the cost

POST /estimate

Send exactly the input you would send to /run; the response's hold_credits is the worst-case cost. Nothing is charged and no job is created, so estimating is free — useful when you are feeding in a whole diff or a directory of source files and want a ceiling before spending credits.

Input fieldTypeNotes
codestring, requiredThe Kotlin source to review, up to 100000 characters: one file, a screen with its ViewModel, or several files concatenated with file-name comment headers such as // ui/CheckoutScreen.kt. Very long pastes may be clipped middle-out, with a [... clipped ...] marker showing where.
targetstringandroid | multiplatform | library | unknown — what the code is. The review is calibrated to it: android makes lifecycle-aware collection (collectAsStateWithLifecycle), ViewModel scoping, configuration-change survival and Android-idiomatic navigation first-class concerns; multiplatform requires commonMain-safe APIs and flags Android-only imports, Context leaking into shared code and undeliberate platform divergence at the expect/actual seam; library (a design system or reusable component set) makes stateless components with hoisted state, a Modifier parameter on every public composable, theme-token-driven styling, stable public parameter types and previews first-class concerns. On unknown the review infers from the paste and says which it assumed.
notesstring, optionalExtra context, up to 20000 characters: what the screen does, performance constraints, minimum SDK or Compose BOM version, what is intentionally unfinished, which public composable APIs cannot break.
prescan_factsobject, optionalWhat the app's free client-side prescan mechanically detected in the code: {"antipatterns": [], "items": [], "signals": {}}. antipatterns and items hold {id, label, lines} entries — keyword-matched Compose smells (ap:state-no-remember, ap:exposed-mutable-stateflow) and the declarations found (i:composable:CheckoutScreen, i:viewmodel:CheckoutViewModel), each with the line numbers it was seen on. signals is a counter object: {"composables": 0, "viewmodels": 0, "state_types": 0, "effect_handlers": 0, "remember_calls": 0, "lazy_lists": 0, "previews": 0, "tests": 0, "lines": 0}. Every id you send comes back in coverage_check. The web UI fills this from its own scan; API callers may omit the field or send {"antipatterns": [], "items": [], "signals": {}}.
retry_notestring, optionalOnly set by the app's automatic reformat retry when a first reply was not valid JSON. Leave it out.
cat > CheckoutScreen.kt <<'KOTLIN'
import androidx.compose.runtime.*

@Composable
fun CheckoutScreen(total: String) {
    var promo by mutableStateOf("")
    Column {
        Text(total)
        Button(onClick = { promo = "SAVE10" }) { Text(promo) }
    }
}
KOTLIN

jq -n --rawfile c CheckoutScreen.kt \
  '{code: $c, target: "android", notes: "",
    prescan_facts: {antipatterns: [], items: [], signals: {}}}' > input.json

curl -s -X POST "$API/estimate" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -d @input.json | jq '.data.hold_credits'
CODE = """import androidx.compose.runtime.*

@Composable
fun CheckoutScreen(total: String) {
    var promo by mutableStateOf("")
    Column {
        Text(total)
        Button(onClick = { promo = "SAVE10" }) { Text(promo) }
    }
}"""

payload = {
    "code": CODE,
    "target": "android",
    "notes": "",
    "prescan_facts": {"antipatterns": [], "items": [], "signals": {}},
}

est = api("POST", "/estimate", payload)
print("worst case:", est.get("hold_credits", est.get("credits")), "credits")
const code = `import androidx.compose.runtime.*

@Composable
fun CheckoutScreen(total: String) {
    var promo by mutableStateOf("")
    Column {
        Text(total)
        Button(onClick = { promo = "SAVE10" }) { Text(promo) }
    }
}`;

const payload = {
  code,
  target: "android",
  notes: "",
  prescan_facts: { antipatterns: [], items: [], signals: {} },
};

const est = await api("POST", "/estimate", payload);
console.log("worst case:", est.hold_credits ?? est.credits, "credits");
const code = `import androidx.compose.runtime.*

@Composable
fun CheckoutScreen(total: String) {
    var promo by mutableStateOf("")
    Column {
        Text(total)
        Button(onClick = { promo = "SAVE10" }) { Text(promo) }
    }
}`

payload := map[string]any{
	"code":   code,
	"target": "android",
	"notes":  "",
	"prescan_facts": map[string]any{
		"antipatterns": []any{}, "items": []any{}, "signals": map[string]any{},
	},
}

var est struct{ HoldCredits int64 `json:"hold_credits"` }
err := call("POST", "/estimate", payload, &est)
String code = """
    import androidx.compose.runtime.*

    @Composable
    fun CheckoutScreen(total: String) {
        var promo by mutableStateOf("")
        Column {
            Text(total)
            Button(onClick = { promo = "SAVE10" }) { Text(promo) }
        }
    }""";

String jsonPayload = """
    {"code": %s, "target": "android",
     "notes": "",
     "prescan_facts": {"antipatterns": [], "items": [], "signals": {}}}
    """.formatted(toJsonString(code));

String envelope = api("POST", "/estimate", jsonPayload);
// worst-case cost is at data.hold_credits
CODE_TEXT = <<~'KOTLIN'
  import androidx.compose.runtime.*

  @Composable
  fun CheckoutScreen(total: String) {
      var promo by mutableStateOf("")
      Column {
          Text(total)
          Button(onClick = { promo = "SAVE10" }) { Text(promo) }
      }
  }
KOTLIN

payload = { code: CODE_TEXT, target: "android",
            notes: "",
            prescan_facts: { antipatterns: [], items: [], signals: {} } }

est = api("POST", "/estimate", payload)
puts "worst case: #{est["hold_credits"] || est["credits"]} credits"
$code = <<<'KOTLIN'
import androidx.compose.runtime.*

@Composable
fun CheckoutScreen(total: String) {
    var promo by mutableStateOf("")
    Column {
        Text(total)
        Button(onClick = { promo = "SAVE10" }) { Text(promo) }
    }
}
KOTLIN;

$payload = [
    "code"          => $code,
    "target"        => "android",
    "notes"         => "",
    "prescan_facts" => ["antipatterns" => [], "items" => [], "signals" => new stdClass()],
];

$est = api("POST", "/estimate", $payload);
echo "worst case: " . ($est["hold_credits"] ?? $est["credits"]) . " credits\n";
var code = """
    import androidx.compose.runtime.*

    @Composable
    fun CheckoutScreen(total: String) {
        var promo by mutableStateOf("")
        Column {
            Text(total)
            Button(onClick = { promo = "SAVE10" }) { Text(promo) }
        }
    }
    """;

var payload = new {
    code,
    target = "android",
    notes = "",
    prescan_facts = new {
        antipatterns = Array.Empty<object>(), items = Array.Empty<object>(),
        signals = new { },
    },
};

var est = await SkillSafe.ApiAsync(HttpMethod.Post, "/estimate", payload);
Console.WriteLine($"worst case: {est.GetProperty("hold_credits")} credits");

prescan_facts is how you make the review answer for things you already know about. Send {"antipatterns": [{"id": "ap:state-no-remember", "label": "mutableStateOf in composition with no remember", "lines": [5]}], "items": [{"id": "i:composable:CheckoutScreen", "label": "@Composable CheckoutScreen", "lines": [4]}], "signals": {"composables": 1, "viewmodels": 0, "state_types": 0, "effect_handlers": 0, "remember_calls": 0, "lazy_lists": 0, "previews": 0, "tests": 0, "lines": 10}} and every one of those ids comes back in coverage_check — addressed, or explained away as a false positive (a mutableStateOf declared inside a ViewModel rather than in composition is fine, and the review says so). Nothing you flag is silently dropped.

Step 4 — Run the review and wait for the result

POST /run
GET /jobs/{job_id}

/run takes the same input as /estimate, places a credit hold and returns a job_id. Poll /jobs/{job_id} every 1–2 seconds until status is succeeded or failed (a run typically takes 30–90 s, since the refined rewrite is written out in full). Always send an Idempotency-Key header so a network retry can't start a second, double-charged run. The review is in output — usually nested as output.output, and as a JSON string, so parse defensively. The samples below print the review name and verdict, the five health areas and the findings, then write rewrite.code to Refined.kt using rewrite.filename.

JOB_ID=$(curl -s -X POST "$API/run" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -H "Idempotency-Key: review-$(date +%s)" \
  -d @input.json | jq -r '.data.job_id')

while :; do
  JOB=$(curl -s "$API/jobs/$JOB_ID" -H "Authorization: Bearer $TOKEN")
  STATUS=$(echo "$JOB" | jq -r '.data.status')
  [ "$STATUS" = "succeeded" ] || [ "$STATUS" = "failed" ] && break
  sleep 2
done

# unwrap the review once, then read it
echo "$JOB" | jq -r '.data.output.output' > review.json

jq -r '
  "\(.review_name) [\(.verdict_level)]: \(.verdict)",
  "",
  "HEALTH",
  (.health[] | "  [\(.status)] \(.area) - \(.note)"),
  "",
  "FINDINGS",
  (.findings[] | "  (\(.severity)) \(.category): \(.title)"),
  "",
  "CHECKLIST",
  (.checklist[] | "  [\(.status)] \(.item) - \(.note)")' review.json

# and drop the refined code straight into the repo
jq -r '.rewrite.code' review.json > "$(jq -r '.rewrite.filename' review.json)"   # Refined.kt
import time

job_id = api("POST", "/run", payload,
             **{"Idempotency-Key": "review-001"})["job_id"]

while True:
    job = api("GET", f"/jobs/{job_id}")
    if job["status"] in ("succeeded", "failed"):
        break
    time.sleep(1.5)

if job["status"] == "failed":
    raise RuntimeError(job.get("error", "run failed"))

raw = job["output"]
if isinstance(raw, dict) and "output" in raw:
    raw = raw["output"]
review = json.loads(raw) if isinstance(raw, str) else raw

print(f'{review["review_name"]} [{review["verdict_level"]}]: {review["verdict"]}')
for area in review["health"]:
    print(f'  [{area["status"]:>4}] {area["area"]:<32} {area["note"]}')
for f in review["findings"]:
    print(f'  ({f["severity"]}) {f["category"]}: {f["title"]}')
    if f["fix_code"]:
        print(f'      {f["fix_code"]}')
for item in review["checklist"]:
    print(f'  [{item["status"]:>4}] {item["item"]:<42} {item["note"]}')
for c in review["coverage_check"]:
    print(f'  {c["id"]}: {"ok" if c["addressed"] else "SET ASIDE"} - {c["note"]}')

with open(review["rewrite"]["filename"], "w", encoding="utf-8") as fh:   # Refined.kt
    fh.write(review["rewrite"]["code"])
import { writeFileSync } from "node:fs";

const { job_id } = await api("POST", "/run", payload,
  { "Idempotency-Key": crypto.randomUUID() });

let job;
do {
  await new Promise((r) => setTimeout(r, 1500));
  job = await api("GET", `/jobs/${job_id}`);
} while (job.status !== "succeeded" && job.status !== "failed");

if (job.status === "failed") throw new Error(job.error ?? "run failed");

const raw = job.output?.output ?? job.output;
const review = typeof raw === "string" ? JSON.parse(raw) : raw;

console.log(`${review.review_name} [${review.verdict_level}]: ${review.verdict}`);
for (const area of review.health) {
  console.log(`  [${area.status}] ${area.area}: ${area.note}`);
}
for (const f of review.findings) {
  console.log(`  (${f.severity}) ${f.category}: ${f.title}`);
  if (f.fix_code) console.log(`      ${f.fix_code}`);
}
for (const item of review.checklist) console.log(`  [${item.status}] ${item.item}: ${item.note}`);
for (const c of review.coverage_check) {
  console.log(`  ${c.id}: ${c.addressed ? "ok" : "SET ASIDE"} - ${c.note}`);
}

writeFileSync(review.rewrite.filename, review.rewrite.code);   // Refined.kt
var started struct{ JobID string `json:"job_id"` }
if err := call("POST", "/run", payload, &started); err != nil {
	log.Fatal(err)
}

var job struct {
	Status string          `json:"status"`
	Error  string          `json:"error"`
	Output json.RawMessage `json:"output"`
}
for {
	if err := call("GET", "/jobs/"+started.JobID, nil, &job); err != nil {
		log.Fatal(err)
	}
	if job.Status == "succeeded" || job.Status == "failed" {
		break
	}
	time.Sleep(1500 * time.Millisecond)
}

// job.Output is {"output": "<json string>"} — unwrap, unquote, then unmarshal:
type Review struct {
	ReviewName   string `json:"review_name"`
	VerdictLevel string `json:"verdict_level"`
	Verdict      string `json:"verdict"`
	Health       []struct {
		Area, Status, Note string
	} `json:"health"`
	Findings []struct {
		Severity, Category, Title, Detail string
		FixCode                           string `json:"fix_code"`
	} `json:"findings"`
	Checklist []struct {
		Item, Status, Note string
	} `json:"checklist"`
	Rewrite struct {
		Filename, Code string
	} `json:"rewrite"`
}
var wrapper struct{ Output string `json:"output"` }
json.Unmarshal(job.Output, &wrapper)
var review Review
json.Unmarshal([]byte(wrapper.Output), &review)

fmt.Printf("%s [%s]: %s\n", review.ReviewName, review.VerdictLevel, review.Verdict)
for _, a := range review.Health {
	fmt.Printf("  [%s] %s: %s\n", a.Status, a.Area, a.Note)
}
for _, f := range review.Findings {
	fmt.Printf("  (%s) %s: %s\n", f.Severity, f.Category, f.Title)
}
for _, c := range review.Checklist {
	fmt.Printf("  [%s] %s: %s\n", c.Status, c.Item, c.Note)
}
os.WriteFile(review.Rewrite.Filename, []byte(review.Rewrite.Code), 0o644) // Refined.kt
String envelope = api("POST", "/run", jsonPayload);
String jobId = /* data.job_id via your JSON library */;

while (true) {
    String job = api("GET", "/jobs/" + jobId, null);
    String status = /* data.status */;
    if (status.equals("succeeded") || status.equals("failed")) break;
    Thread.sleep(1500);
}
// The review is at data.output.output as a JSON string — parse it again, then read
// review_name, verdict_level, verdict, overview, health[] (five areas with area/status/note),
// findings[] (severity/category/title/detail/fix_code), checklist[] (item/status/note),
// coverage_check[] (id/addressed/note), rewrite{filename, code}, next_steps[] and summary.
// Finally write the refined code to disk:
//   Files.writeString(Path.of(rewriteFilename), rewriteCode);   // Refined.kt
started = api("POST", "/run", payload)

job = nil
loop do
  job = api("GET", "/jobs/#{started["job_id"]}")
  break if %w[succeeded failed].include?(job["status"])
  sleep 1.5
end
raise (job["error"] || "run failed") if job["status"] == "failed"

raw = job["output"].is_a?(Hash) ? job["output"].fetch("output", job["output"]) : job["output"]
review = raw.is_a?(String) ? JSON.parse(raw) : raw

puts "#{review["review_name"]} [#{review["verdict_level"]}]: #{review["verdict"]}"
review["health"].each { |a| puts "  [#{a["status"]}] #{a["area"]}: #{a["note"]}" }
review["findings"].each do |f|
  puts "  (#{f["severity"]}) #{f["category"]}: #{f["title"]}"
  puts "      #{f["fix_code"]}" unless f["fix_code"].to_s.empty?
end
review["checklist"].each { |c| puts "  [#{c["status"]}] #{c["item"]}: #{c["note"]}" }
review["coverage_check"].each { |c| puts "  #{c["id"]}: #{c["addressed"] ? "ok" : "SET ASIDE"}" }

File.write(review["rewrite"]["filename"], review["rewrite"]["code"])   # Refined.kt
$started = api("POST", "/run", $payload);

do {
    sleep(2);
    $job = api("GET", "/jobs/" . $started["job_id"]);
} while (!in_array($job["status"], ["succeeded", "failed"]));

if ($job["status"] === "failed") {
    throw new Exception($job["error"] ?? "run failed");
}

$raw = is_array($job["output"]) ? ($job["output"]["output"] ?? $job["output"]) : $job["output"];
$review = is_string($raw) ? json_decode($raw, true) : $raw;

echo "{$review['review_name']} [{$review['verdict_level']}]: {$review['verdict']}\n";
foreach ($review["health"] as $a) {
    echo "  [{$a['status']}] {$a['area']}: {$a['note']}\n";
}
foreach ($review["findings"] as $f) {
    echo "  ({$f['severity']}) {$f['category']}: {$f['title']}\n";
    if ($f["fix_code"] !== "") { echo "      {$f['fix_code']}\n"; }
}
foreach ($review["checklist"] as $item) {
    echo "  [{$item['status']}] {$item['item']}: {$item['note']}\n";
}
foreach ($review["coverage_check"] as $c) {
    echo "  {$c['id']}: " . ($c["addressed"] ? "ok" : "SET ASIDE") . "\n";
}

file_put_contents($review["rewrite"]["filename"], $review["rewrite"]["code"]);   // Refined.kt
var started = await SkillSafe.ApiAsync(HttpMethod.Post, "/run", payload);
var jobId = started.GetProperty("job_id").GetString();

JsonElement job;
while (true)
{
    job = await SkillSafe.ApiAsync(HttpMethod.Get, $"/jobs/{jobId}");
    var status = job.GetProperty("status").GetString();
    if (status is "succeeded" or "failed") break;
    await Task.Delay(1500);
}

var rawText = job.GetProperty("output").GetProperty("output").GetString();
using var doc = JsonDocument.Parse(rawText!);
var review = doc.RootElement;

Console.WriteLine($"{review.GetProperty("review_name")} " +
                  $"[{review.GetProperty("verdict_level")}]: {review.GetProperty("verdict")}");
foreach (var a in review.GetProperty("health").EnumerateArray())
{
    Console.WriteLine($"  [{a.GetProperty("status")}] {a.GetProperty("area")}: {a.GetProperty("note")}");
}
foreach (var f in review.GetProperty("findings").EnumerateArray())
{
    Console.WriteLine($"  ({f.GetProperty("severity")}) {f.GetProperty("category")}: " +
                      $"{f.GetProperty("title")}");
}
foreach (var c in review.GetProperty("checklist").EnumerateArray())
{
    Console.WriteLine($"  [{c.GetProperty("status")}] {c.GetProperty("item")}: {c.GetProperty("note")}");
}

var rewrite = review.GetProperty("rewrite");
await File.WriteAllTextAsync(rewrite.GetProperty("filename").GetString()!,   // Refined.kt
                             rewrite.GetProperty("code").GetString()!);

The model is asked for one JSON object and nothing else, but a stray code fence or preamble is always possible. Strip a leading ```json fence, take the text between the first { and the last }, and only then parse — that is what the app does before it falls back to a retry_note reformat run.

The review object — output schema

One JSON object, always the same shape. Every array is present (findings is empty only if genuinely nothing applies); health always has exactly the five areas, checklist always has exactly the twelve items, and rewrite.code is never empty. If the paste was too thin to review responsibly, you still get this object: what is there gets reviewed, the verdict says the paste is thin, and what you would need to show lands in next_steps. If the paste is not Kotlin/Compose at all, you still get the object — one high-severity finding explaining what arrived, every health area at risk, every checklist item at na, and a rewrite.code block of // comments saying what to paste instead. A paste spanning several files keeps its // ui/... file-name comment headers, and each one is refined in place.

FieldTypeMeaning
review_namestringA short name for the review, taken from the code's own domain naming — its composable, ViewModel or file names.
verdict_levelstringsound (nothing material found), refactor (findings exist but are medium/low or only bite at scale) or rework (a high finding means the UI is broken as pasted — state that resets on recomposition, effects that refire or leak, blocking work jamming the main thread, list state corrupting on reorder).
verdictstringOne or two sentences: the overall state and the single most important change.
overviewstringOne or two paragraphs: what this UI code does, and the pattern behind what was found.
healtharray of 5{area, status, note} — the five areas listed below, each exactly once. status is good (nothing material), risk (works, with caveats) or bad (a high-severity finding lives here). Each note references something concrete in the pasted code; an area the paste does not exercise at all is good with a note saying so, unless its absence is itself the risk (a screen that loads data with no effect or ViewModel in sight), which is risk with the reason. An area a high finding touches is never good.
findingsarray{severity, category, title, detail, fix_code}. severity is high (a real defect in the code as pasted — a mutableStateOf in composition with no remember, business work or a bare blocking call executed directly in composition, GlobalScope/runBlocking on the UI path, a public MutableStateFlow that lets the UI mutate ViewModel state, a one-shot navigation effect modeled as sticky state, a DisposableEffect that leaks its listener, a lazy list whose reordering corrupts state because items have no keys) | medium (works today but degrades or misleads — plain collectAsState on Android, unkeyed but stateless lazy items, unstable parameters defeating skippability, a fan of callback lambdas where a sealed event type belongs, a reusable composable missing its Modifier parameter, hardcoded colors in feature code, !! assertions on state) | low (polish — naming drift, missing previews, a stateless split that would help testing, minor structure); category is state, recomposition, effects, design, navigation, theming, structure, performance, multiplatform or naming. detail quotes the composable, ViewModel, type or expression it concerns; fix_code is corrected Kotlin in your own naming and style, or an empty string when the finding is a question or trade-off rather than a mechanical fix.
checklistarray of 12{item, status, note} — the twelve items listed below, each exactly once and in order. status is pass (the paste shows it handled), fail (the paste shows it mishandled — a finding backs this) or na (the paste gives no evidence either way — no lazy lists, no events to funnel). The note says what was seen or what is missing.
coverage_checkarray{id, addressed, note} — one entry per prescan_facts item you sent (ap:state-no-remember, i:composable:CheckoutScreen, …), saying where the review covers it or why it was set aside (a keyword hit can be a false positive — a mutableStateOf inside a ViewModel is fine, and GlobalScope inside a code comment is inert; the note says so). Nothing you flagged is silently dropped.
rewriteobject{filename, code}filename is normally Refined.kt (unless the paste's own file-name headers suggest a better name), and code is your own code refined: same screen, same intent, findings fixed — state consolidated into one immutable object behind asStateFlow(), remember added where composition state needed it, collection made lifecycle-aware, the stateful/stateless split made, Modifier parameters added and forwarded, events funneled through a sealed type, effects given honest keys and disposal, lazy items keyed, blocking work moved into viewModelScope, hardcoded values replaced with theme tokens. Your naming, domain vocabulary and comments are preserved, and it is a complete replacement for what you pasted, not a fragment.
next_stepsstring[]Ordered and concrete: wrap ItemRow's expanded flag in remember, key the LazyColumn items on item.id, replace the exposed MutableStateFlow with asStateFlow(), and so on.
summarystring3–5 sentences a code reviewer could paste into a PR review.

The five health areas, in order, spelled exactly like this:

areaWhat its note covers
State & data flowOne immutable data class per screen exposed as a StateFlow via asStateFlow() and updated with _state.update { it.copy(...) }; no public MutableStateFlow and no var inside a state data class; mutableStateOf in composition is wrapped in remember (or rememberSaveable where it must survive configuration change or process death); collection is lifecycle-aware on Android.
Recomposition & performanceLazy list items carry a stable key, heavy per-item computation is remembered or moved to the ViewModel, derivedStateOf covers values computed from fast-changing state, parameters are stable/immutable types so skipping is not defeated, and state is not read deeper than needed.
Composable design & reuseThe stateful screen composable (collects state, talks to the ViewModel) is split from the stateless content composable (parameters in, lambdas out) so content is previewable and testable; every reusable composable takes a Modifier parameter defaulting to Modifier and forwards it to its root layout exactly once; state is hoisted rather than copied into the component.
Side effects & lifecycleEffects live in LaunchedEffect/DisposableEffect/SideEffect with honest keys rather than as bare calls in composition, DisposableEffect always pairs its onDispose, one-shot effects ride a Channel/SharedFlow rather than a sticky state flag, and long-lived work runs in viewModelScope — never GlobalScope, never runBlocking on the UI path.
Theming & structureColors, type styles and shapes come from MaterialTheme or the project's design system rather than hardcoded Color(0xFF...) literals, repeated dimensions live in a spacing scale, navigation routes are typed/sealed rather than raw string concatenations, ViewModels never hold a NavController, and naming follows PascalCase composables with XxxState/XxxEvent types.

The twelve checklist items, in order, spelled exactly like this:

itemWhat its note covers
Screen state is one immutable objectThe screen's state is a single immutable data class rather than a scatter of independent flows and flags, so the UI can never observe a half-updated combination.
Mutable state never exposed to the UIThe ViewModel keeps its MutableStateFlow private and exposes it through asStateFlow(); no var lives inside the state data class for the UI to write to.
remember guards state created in compositionEvery mutableStateOf created inside a composable is wrapped in remember — or rememberSaveable where it must survive a configuration change or process death — so it does not silently reset.
State collected lifecycle-awareAndroid code collects with collectAsStateWithLifecycle so collection stops when the UI is not visible; plain collectAsState is acceptable in commonMain and the note says so.
Stateless content split from stateful screenA stateful screen composable collects state and talks to the ViewModel, and a stateless content composable takes parameters in and lambdas out, so the content is previewable and testable.
Reusable composables take a ModifierEvery reusable composable accepts a modifier: Modifier = Modifier parameter and forwards it to its root layout exactly once, so callers control layout without wrapper boxes.
Events funneled through a sealed typeComplex screens send user events through a sealed interface handled by one onEvent function, rather than a fan of individual callback lambdas threaded down the tree.
One-shot effects are not sticky stateNavigation, toasts and snackbars ride a Channel or SharedFlow, never a state flag the UI must remember to reset — sticky one-shot state refires on the next recomposition.
Effects keyed honestly and disposedEffects sit in LaunchedEffect/DisposableEffect/SideEffect with keys that reflect what they actually depend on (not a blanket Unit), and every DisposableEffect pairs its onDispose.
Lazy list items carry stable keysLazyColumn/LazyRow items declare a stable key, so reordering or inserting does not corrupt per-item state or force needless recomposition.
No blocking or unscoped work in compositionNo business logic, blocking call, runBlocking or GlobalScope launch runs during composition — long-lived work belongs in viewModelScope, cached results in remember.
Design tokens come from the themeColors, type styles, shapes and repeated dimensions come from MaterialTheme or the project's design system rather than hardcoded Color(0xFF...) and magic dp literals in feature code.

A small, realistic result for the CheckoutScreen.kt paste above, trimmed for length:

{
  "review_name": "CheckoutScreen - promo code entry",
  "verdict_level": "rework",
  "verdict": "'CheckoutScreen' creates its promo state with 'mutableStateOf' and no 'remember', so
              every recomposition throws the user's input away; wrap it in 'remember' before
              anything else.",
  "overview": "One screen-level composable that renders a total and a button applying a promo code.
               The intent is clear and the parameter is already an immutable 'String', but the one
               piece of local state is created fresh on every recomposition, so the screen cannot
               hold what the user did. There is no ViewModel, no state class and no effect in the
               paste, so the data-flow story stops at this single flag.",
  "health": [
    { "area": "State & data flow", "status": "bad",
      "note": "'var promo by mutableStateOf(\"\")' sits directly in composition with no 'remember',
               so the value resets on every recomposition and no state class or StateFlow exists to
               hold it." },
    { "area": "Recomposition & performance", "status": "risk",
      "note": "No lazy list or heavy computation appears, but the 'Button' lambda writes state read
               by the same composable, so the whole 'CheckoutScreen' body recomposes on each tap." },
    { "area": "Composable design & reuse", "status": "risk",
      "note": "'CheckoutScreen(total: String)' takes no 'modifier' parameter and mixes state
               ownership with layout, so there is no stateless content composable to preview." },
    { "area": "Side effects & lifecycle", "status": "good",
      "note": "No LaunchedEffect, DisposableEffect or coroutine launch appears in the paste, so the
               area is not exercised by this code." },
    { "area": "Theming & structure", "status": "risk",
      "note": "Nothing is hardcoded as a raw color yet, but 'Text(total)' names no MaterialTheme
               type style and the promo string 'SAVE10' is a literal inside the click lambda." }
  ],
  "findings": [
    { "severity": "high", "category": "state",
      "title": "CheckoutScreen owns a mutableStateOf with no remember",
      "detail": "'var promo by mutableStateOf(\"\")' is evaluated on every recomposition, so the
                 promo code the user applied is discarded as soon as anything above it recomposes -
                 the button appears to do nothing.",
      "fix_code": "@Composable\nfun CheckoutScreen(total: String, modifier: Modifier = Modifier) {\n    var promo by rememberSaveable { mutableStateOf(\"\") }\n    Column(modifier = modifier) {\n        Text(total)\n        Button(onClick = { promo = \"SAVE10\" }) { Text(promo) }\n    }\n}" },
    { "severity": "medium", "category": "design",
      "title": "No Modifier parameter on CheckoutScreen",
      "detail": "'fun CheckoutScreen(total: String)' cannot be positioned or padded by its caller,
                 so callers wrap it in an extra Box - and the screen cannot be split into a
                 previewable stateless content composable.",
      "fix_code": "@Composable\nfun CheckoutScreen(total: String, modifier: Modifier = Modifier) {\n    Column(modifier = modifier) { /* ... */ }\n}" },
    { "severity": "low", "category": "theming",
      "title": "The total is rendered with no theme type style",
      "detail": "'Text(total)' inherits whatever style is ambient rather than naming one from
                 MaterialTheme, so the total stops following the design system when it changes.",
      "fix_code": "Text(total, style = MaterialTheme.typography.titleLarge)" }
  ],
  "checklist": [
    { "item": "Screen state is one immutable object", "status": "fail",
      "note": "The only state is a loose 'promo' flag in composition; no XxxState data class." },
    { "item": "Mutable state never exposed to the UI", "status": "na",
      "note": "No ViewModel or StateFlow appears in the paste." },
    { "item": "remember guards state created in composition", "status": "fail",
      "note": "'mutableStateOf(\"\")' on line 5 has no 'remember' around it." },
    { "item": "State collected lifecycle-aware", "status": "na",
      "note": "Nothing is collected; there is no flow in the paste." },
    { "item": "Stateless content split from stateful screen", "status": "fail",
      "note": "'CheckoutScreen' owns the state and the layout in one composable." },
    { "item": "Reusable composables take a Modifier", "status": "fail",
      "note": "'CheckoutScreen(total: String)' declares no 'modifier' parameter." },
    { "item": "Events funneled through a sealed type", "status": "na",
      "note": "One click lambda only; there is nothing to funnel yet." },
    { "item": "One-shot effects are not sticky state", "status": "na",
      "note": "No navigation, toast or snackbar effect in the paste." },
    { "item": "Effects keyed honestly and disposed", "status": "na",
      "note": "No LaunchedEffect or DisposableEffect appears." },
    { "item": "Lazy list items carry stable keys", "status": "na",
      "note": "No LazyColumn or LazyRow in the paste." },
    { "item": "No blocking or unscoped work in composition", "status": "pass",
      "note": "The body only reads 'total' and 'promo'; no blocking call or GlobalScope launch." },
    { "item": "Design tokens come from the theme", "status": "fail",
      "note": "'Text(total)' names no MaterialTheme type style and 'SAVE10' is inline." }
  ],
  "coverage_check": [
    { "id": "ap:state-no-remember", "addressed": true,
      "note": "Covered by the first finding - the flag becomes 'rememberSaveable'." },
    { "id": "i:composable:CheckoutScreen", "addressed": true,
      "note": "The composable under review; refined in full in rewrite.code." }
  ],
  "rewrite": { "filename": "Refined.kt",
               "code": "import androidx.compose.runtime.*\n\n@Composable\nfun CheckoutScreen(total: String, modifier: Modifier = Modifier) { … }" },
  "next_steps": [
    "Wrap the promo flag in 'rememberSaveable' so it survives recomposition and rotation.",
    "Add 'modifier: Modifier = Modifier' to 'CheckoutScreen' and forward it to the Column.",
    "Split a stateless 'CheckoutContent(total, promo, onApplyPromo)' out of the screen.",
    "Move the promo code into a ViewModel and the total's type style into the theme."
  ],
  "summary": "The screen does one thing and its parameter is already immutable, but its single piece
              of state is created without 'remember'. …"
}

The refined rewrite is a starting point, not a sign-off: it is written to be complete and self-consistent with the findings, but it is AI-generated and it only sees what you pasted. Read it, put it through the Kotlin compiler, your lint rules and your Compose UI tests, and keep the human review in the loop before it goes anywhere near production — a change to a published composable's parameters is a contract change.

Step 5 — Stream the review as it is written

POST /run-stream

/run-stream takes exactly the same body as /run but answers with server-sent events, so you can show progress instead of a spinner — useful here because the refined rewrite makes for a long reply. This app's own progress panel is this endpoint. Events are separated by a blank line; each has an event: line and a data: line carrying JSON.

EventPayloadMeaning
job{job_id, status}Sent once, when the job is accepted — show "starting".
delta{text}A chunk of the reply, in order. Append it; the accumulated length is your only progress signal (the total is not known in advance).
done{job_id, status, charged_credits, output}The final, authoritative result — read the review from output.output rather than trusting concatenated deltas, and the settled price from charged_credits.
error{code, message}Replaces done when the run fails.
# -N disables buffering so events print as they arrive
curl -N -s -X POST "$API/run-stream" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -H "Idempotency-Key: review-$(date +%s)" \
  -d @input.json

# event: job
# data: {"job_id":"job_...","status":"running"}
#
# event: delta
# data: {"text":"{\"review_name\":\"CheckoutScreen"}
# ...
# event: done
# data: {"job_id":"job_...","status":"succeeded","charged_credits":612,"output":{"output":"{...}"}}
import json, requests

result = None
with requests.post(
    API + "/run-stream",
    headers={"Authorization": f"Bearer {TOKEN}",
             "Idempotency-Key": "review-001"},
    json=payload,
    stream=True,
) as r:
    r.raise_for_status()
    event = None
    for line in r.iter_lines(decode_unicode=True):
        if not line:
            continue
        if line.startswith("event:"):
            event = line[len("event:"):].strip()
        elif line.startswith("data:"):
            data = json.loads(line[len("data:"):].strip())
            if event == "delta":
                print(".", end="", flush=True)          # live progress
            elif event == "done":
                result = data
            elif event == "error":
                raise RuntimeError(data.get("message", "run failed"))

review = json.loads(result["output"]["output"])         # authoritative
print("charged:", result["charged_credits"], "-", review["review_name"])
for area in review["health"]:
    print(f'  [{area["status"]}] {area["area"]}')
open(review["rewrite"]["filename"], "w", encoding="utf-8").write(review["rewrite"]["code"])
const res = await fetch(API + "/run-stream", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${TOKEN}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify(payload),
});

const reader = res.body.getReader();
const decoder = new TextDecoder();
let buf = "", done = null;

for (;;) {
  const chunk = await reader.read();
  if (chunk.done) break;
  buf += decoder.decode(chunk.value, { stream: true });
  const frames = buf.split("\n\n");
  buf = frames.pop();
  for (const frame of frames) {
    const name = /^event:\s*(.+)$/m.exec(frame)?.[1];
    const body = /^data:\s*(.+)$/m.exec(frame)?.[1];
    if (!name || !body) continue;
    const data = JSON.parse(body);
    if (name === "delta") process.stdout.write(".");   // live progress
    if (name === "done") done = data;
    if (name === "error") throw new Error(data.message ?? "run failed");
  }
}

const review = JSON.parse(done.output.output);
console.log(`\n${done.charged_credits} credits - ${review.review_name}`);
for (const area of review.health) console.log(`  [${area.status}] ${area.area}`);
writeFileSync(review.rewrite.filename, review.rewrite.code);   // Refined.kt
body, _ := json.Marshal(payload)
req, _ := http.NewRequest("POST", API+"/run-stream", bytes.NewReader(body))
req.Header.Set("Authorization", "Bearer "+token)
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Idempotency-Key", "review-001")

res, err := http.DefaultClient.Do(req)
if err != nil {
	log.Fatal(err)
}
defer res.Body.Close()

var event string
var final map[string]any
sc := bufio.NewScanner(res.Body)
sc.Buffer(make([]byte, 0, 64*1024), 4*1024*1024)
for sc.Scan() {
	line := sc.Text()
	switch {
	case strings.HasPrefix(line, "event:"):
		event = strings.TrimSpace(strings.TrimPrefix(line, "event:"))
	case strings.HasPrefix(line, "data:"):
		var data map[string]any
		json.Unmarshal([]byte(strings.TrimPrefix(line, "data:")), &data)
		switch event {
		case "delta":
			fmt.Print(".") // live progress
		case "done":
			final = data
		case "error":
			log.Fatal(data["message"])
		}
	}
}
// final["output"].(map[string]any)["output"].(string) is the review JSON —
// unmarshal it into the Review struct from step 4, then write review.Rewrite.Code to disk.
// Java 17+ — read the stream line by line instead of buffering the body.
var req = HttpRequest.newBuilder(URI.create(API + "/run-stream"))
    .header("Authorization", "Bearer " + TOKEN)
    .header("Content-Type", "application/json")
    .header("Idempotency-Key", "review-001")
    .POST(HttpRequest.BodyPublishers.ofString(jsonPayload))
    .build();

var res = HTTP.send(req, HttpResponse.BodyHandlers.ofLines());
String event = null, done = null;
for (String line : (Iterable<String>) res.body()::iterator) {
    if (line.startsWith("event:")) {
        event = line.substring(6).trim();
    } else if (line.startsWith("data:")) {
        String data = line.substring(5).trim();
        if ("delta".equals(event)) System.out.print(".");   // live progress
        else if ("done".equals(event)) done = data;
        else if ("error".equals(event)) throw new RuntimeException(data);
    }
}
// parse `done`, then parse data.output.output again — it is a JSON string holding
// review_name, verdict_level, health[], findings[], checklist[], rewrite{filename, code} and the rest.
require "net/http"
require "json"

uri = URI(API + "/run-stream")
req = Net::HTTP::Post.new(uri)
req["Authorization"] = "Bearer #{TOKEN}"
req["Content-Type"] = "application/json"
req["Idempotency-Key"] = "review-001"
req.body = payload.to_json

event = nil
done = nil
Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(req) do |res|
    res.read_body do |chunk|
      chunk.each_line do |line|
        line = line.strip
        if line.start_with?("event:")
          event = line.delete_prefix("event:").strip
        elsif line.start_with?("data:")
          data = JSON.parse(line.delete_prefix("data:").strip)
          case event
          when "delta" then print "."           # live progress
          when "done"  then done = data
          when "error" then raise (data["message"] || "run failed")
          end
        end
      end
    end
  end
end

review = JSON.parse(done["output"]["output"])
puts "\n#{done["charged_credits"]} credits - #{review["review_name"]}"
review["health"].each { |a| puts "  [#{a["status"]}] #{a["area"]}" }
File.write(review["rewrite"]["filename"], review["rewrite"]["code"])   # Refined.kt
$event = null;
$done  = null;

$ch = curl_init(API . "/run-stream");
curl_setopt_array($ch, [
    CURLOPT_POST       => true,
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer $TOKEN",
        "Content-Type: application/json",
        "Idempotency-Key: review-001",
    ],
    CURLOPT_POSTFIELDS => json_encode($payload),
    CURLOPT_WRITEFUNCTION => function ($ch, $chunk) use (&$event, &$done) {
        foreach (explode("\n", $chunk) as $line) {
            $line = trim($line);
            if (str_starts_with($line, "event:")) {
                $event = trim(substr($line, 6));
            } elseif (str_starts_with($line, "data:")) {
                $data = json_decode(trim(substr($line, 5)), true);
                if ($event === "delta") { echo "."; }        // live progress
                elseif ($event === "done") { $done = $data; }
                elseif ($event === "error") { throw new Exception($data["message"] ?? "run failed"); }
            }
        }
        return strlen($chunk);
    },
]);
curl_exec($ch);
curl_close($ch);

$review = json_decode($done["output"]["output"], true);
echo "\n{$done['charged_credits']} credits - {$review['review_name']}\n";
foreach ($review["health"] as $a) { echo "  [{$a['status']}] {$a['area']}\n"; }
file_put_contents($review["rewrite"]["filename"], $review["rewrite"]["code"]);   // Refined.kt
var req = new HttpRequestMessage(HttpMethod.Post, Api + "/run-stream") {
    Content = JsonContent.Create(payload),
};
req.Headers.Add("Idempotency-Key", "review-001");

using var res = await Http.SendAsync(req, HttpCompletionOption.ResponseHeadersRead);
using var reader = new StreamReader(await res.Content.ReadAsStreamAsync());

string? evt = null, done = null;
while (await reader.ReadLineAsync() is { } line)
{
    if (line.StartsWith("event:")) evt = line[6..].Trim();
    else if (line.StartsWith("data:"))
    {
        var data = line[5..].Trim();
        if (evt == "delta") Console.Write(".");            // live progress
        else if (evt == "done") done = data;
        else if (evt == "error") throw new Exception(data);
    }
}

using var final = JsonDocument.Parse(done!);
var text = final.RootElement.GetProperty("output").GetProperty("output").GetString();
using var reviewDoc = JsonDocument.Parse(text!);
var review = reviewDoc.RootElement;
Console.WriteLine(review.GetProperty("review_name"));
foreach (var a in review.GetProperty("health").EnumerateArray())
    Console.WriteLine($"  [{a.GetProperty("status")}] {a.GetProperty("area")}");
var rewrite = review.GetProperty("rewrite");
await File.WriteAllTextAsync(rewrite.GetProperty("filename").GetString()!,   // Refined.kt
                             rewrite.GetProperty("code").GetString()!);

In a browser, the native EventSource only speaks GET, and this endpoint is a POST — read the fetch response body incrementally, as the JavaScript sample above does. On an idempotent replay the server may answer with a plain JSON envelope instead of an event stream; check the Content-Type before you start parsing frames.