Skip to content
LiveGraph

Share a run people can watch, not a log they can't

October 4, 2026

The most convincing artifact a LiveGraph run produces is the run itself — nodes lighting up in order, an edge animating as a hop resolves, a run parking at an approval gate. Until now that artifact lived behind your login, which meant the standard industry workaround: a screenshot of a canvas, which is a canvas that already went inert, or a pasted log nobody reads.

Shared runs fix that. One API call mints a link — and anyone holding it sees a read-only, live-updating canvas of that run, no account required.

How it works

POST /runs/:id/share          →  { token, expiresAt, embedUrl }

<iframe src="https://livegraph.ai/embed/runs/<id>?t=<token>" />

POST /runs/:id/share returns a token and a ready-made embedUrl. Drop the URL in an iframe — a docs page, an internal status board, a client deliverable — and it renders the run's canvas: the graph's topology laid out as you arranged it, each node tinted by its state (idle, running, done, failed), edges animating as hops resolve. While the run is live the embed updates in real time over a WebSocket, with a slow poll as backup. When it finishes, the canvas settles into the run's final state — still a better artifact than a screenshot, because the shape and the path taken are the story.

The token is stateless — a signed payload (run id + graph id + expiry) with an HMAC keyed by a domain-prefixed secret, so a share token can never collide with a session token. You choose the lifetime: anywhere from a minute to 24 hours, two hours by default. Expiry is the revocation story — nothing to revoke server-side because nothing is stored — and deleting the run or its graph ends the link early. Minting is owner/editor-only, and scoped API keys can carry just runs:share if you want a service (say, your SaaS backend) minting links on demand without broader access.

What an embed shows — and what it structurally can't

The public view is a whitelist decided in one place in the API, not a blacklist you have to keep trimming:

  • Shown: the run's status and timestamps; the graph's topology — node names, roles, positions, edge kinds; per-hop status and timing.
  • Never shown: hop inputs, outputs, error text, prompts, tools, credentials, usage. The link is public to whoever holds it — the content of what your agents said to each other is not part of the deal.

The same discipline applies to the plumbing. The embed endpoint is unauthenticated by design — the token is the grant, and it names exactly one run. A bad, expired, or wrong-run token all return the same 404, so the endpoint can't be probed for which runs exist. It's rate-limited, served no-store, and the live socket only ever carries the whitelisted event types (a hop dispatched, a run parked at approval) — never the event payloads.

And it's genuinely read-only: the canvas ignores drags, there are no actions, no “reroute this for me” for the person watching. Sharing a run changes what people can see, never what they can do — the steering stays with the people inside the workspace.

Where it came from

The first consumer is one of our own spawned products. Its scan page kicks off a LiveGraph run — four specialist engines fanning out over a user's request — and the visitor watching the scan sees the actual canvas behind it, embedded inline, updating as each engine finishes. “Your scan is running” became “here is your scan, running.” The trust difference between those two sentences is the whole feature.

Why visibility is the missing primitive

Agent platforms have converged on logging as the answer to “what did it do” — traces you can query after the fact, if you know what to ask. Logs are for debugging. They are not for showing a client that their deliverable is mid-flight, or putting a status page next to a job that takes an hour, or letting a teammate watch a fix round self-heal without handing them your login.

A run people can watch is worth more than a log they can't. The topology is already the honest map of what's happening — sharing it turned out to be less a feature than the removal of an artificial wall. If your product already runs agents on LiveGraph, the embed is one POST away; if it doesn't, the live demo shows the same canvas the embed renders.

See it running

The live demo needs no account and no API key — a scripted model drives the real engine while you reroute a run in flight. When you want your own graphs, sign up and the included model runs them; bring a key when you want a different provider.

Keep reading

  • We gave LiveGraph a paragraph. It built citepath.ai — and it hasn't stopped. — citepath.ai is a live GEO SaaS built entirely by a LiveGraph bootstrap run and its improvement loop: provisioning, self-hosted CI, thirty-three merged PRs, every failure — and what each failure became.
  • A loop wrote a complete SaaS for $23.85 — then handed over the keys. — findefend.com went from a paragraph-long brief to a live, self-improving product: one bootstrap run, fourteen reviewed PRs, real incidents that became platform fixes — and a credential handoff where the model never saw the password.
  • Our engineering team is a LiveGraph graph. Here is what broke. — LiveGraph's own repo is improved by a LiveGraph loop: a tick fires the Lead, an engineer works through the GitHub MCP, CI routes its own verdict, and a human gate decides every merge. Including the three ways it failed.
  • LangGraph edits a run's state. LiveGraph edits a run's route. — LangGraph compiles your topology into code; LiveGraph keeps it in data you can mutate between hops. Two different primitives — an honest map of where each one fits.
  • We pointed LiveGraph at an empty domain. It shipped a product. — modelright.dev went from a domain name to a live, self-improving app through one bootstrap run and a 10-minute improvement loop — approvals, conflicts, and all.
  • Steer a running agent workflow — LiveGraph re-reads the graph after every hop, so dragging an edge changes where this run goes next.
  • Why you can't reroute a running n8n workflow (and why you can in LiveGraph) — Most engines compile a run before executing it, so mid-run edits only affect the next run. A per-hop engine makes rerouting free — here's the architecture.
  • Giving agents write access to real code without losing sleep — Worktree isolation, operator allowlists, encrypted secrets, and pushes only a human's literal keystrokes can trigger — the safety model, decision by decision.

LiveGraph

Model-agnostic agent orchestration on a live canvas. Hosted at livegraph.ai.

Product

  • Live demo
  • Pricing
  • Security
  • Automations
  • Compare
  • Migrate from Flowise
  • Migrate from Agent Builder
  • Sign up

Resources

  • Blog
  • Docs
  • Changelog
  • Model Radar
  • Status
  • RSS

Agents

  • Agent guide
  • llms.txt
  • llms-full.txt
  • MCP integration

Support

  • [email protected]

Legal

  • Privacy
  • Terms
© 2026 LiveGraphSite by Canweb Ltd.