Skip to main content

Builder Chat

POST 

/v2/auto/chat

Plan Access
All plans, billed per query in credits
Data Recency
Continuous evaluation against live data
Rate Limit
60 to 120 RPM by plan

Ask the AI to help you build an EQL query.

The response message contains the AI's reply in Markdown. When it generates EQL, it will be in a JSON code block that you can extract, validate, and submit.

Use sessionId in follow-up requests to maintain conversation context.

Cost​

API mode: 1 + dynamic credits

  • base request charge: 1 credit
  • dynamic usage charge: ceil(request_cost * 750) credits

x402 mode is quoted in USD per turn, not credits. The 402 response lists the schemes it accepts and the client picks one:

  • exact (flat, charged in full): fast $1, expert $2
  • batch-settlement (Base, when listed: deposit once into a payment channel; each turn is capped at fast $2, expert $6 and charged its actual cost)

Auth​

Required header:

x-elfa-api-key: <api_key>

Chat produces drafts only; subsequent activation goes through POST /queries/drafts/{draftId}/convert.

Request Example​

{
"message": "Alert me when BTC breaks 100k",
"speed": "expert",
"sessionId": "optional-session-id"
}

Response Example (200)​

{
"sessionId": "session-uuid",
"response": "I can help with that...",
"title": "BTC Breakout Alert",
"reasoning": null,
"planIds": [],
"credits": 104
}

credits is what this call cost, and carries the same total as the x-elfa-credits response header. Chat is dynamically priced, so read it rather than assuming a flat cost.

Best practice: persist sessionId and reuse it for follow-up prompts so the model keeps context across turns.

Request​

Responses​

Ok