> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Steer a live task with mid-run user input

> Inject a user message into an actively running (or resuming) task.
The current tool/LLM step finishes, then every live agent loop on
this stream sees a real user message at its next LLM step.

Send `stream_id` from the live SSE you are watching. The API will
not retarget the steer onto a newer run of the same chat.

This does not abort in-flight tools. Do not PATCH working memory
(`user_runtime_input`) for composer text — use this endpoint while
the stream is live.




## OpenAPI

````yaml /openapi/neo.public.openapi.json post /api/v1/tasks/{id}/input
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/tasks/{id}/input:
    post:
      tags:
        - Tasks
      summary: Steer a live task with mid-run user input
      description: |
        Inject a user message into an actively running (or resuming) task.
        The current tool/LLM step finishes, then every live agent loop on
        this stream sees a real user message at its next LLM step.

        Send `stream_id` from the live SSE you are watching. The API will
        not retarget the steer onto a newer run of the same chat.

        This does not abort in-flight tools. Do not PATCH working memory
        (`user_runtime_input`) for composer text — use this endpoint while
        the stream is live.
      operationId: post-v1-tasks-id-input
      parameters:
        - description: Task ID
          in: path
          name: id
          required: true
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TaskInputRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TaskInputResponse'
          description: Input accepted and forwarded to the live stream
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Invalid request (empty text or unsupported mode)
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Task not found
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: |
            No live stream to steer, or the supplied stream_id is not the
            currently live stream (the run ended or a newer turn started).
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    TaskInputRequest:
      properties:
        id:
          description: |
            Idempotency key and mastra_messages id. Reuse the same id on
            retries so a duplicate POST cannot mint a new signal. Go mints
            one when omitted.
          format: uuid
          type: string
        mode:
          default: steer
          description: v1 only supports steer (inject at the next LLM step)
          enum:
            - steer
          type: string
        stream_id:
          description: |
            Live SSE stream this composer send was typed against. When set,
            the API returns 409 if that stream is no longer live — including
            when a newer run on the same chat has started. Prevents a retried
            steer (e.g. "stop") from attaching to the next turn. Send the
            stream_id from the live SSE metadata.
          format: uuid
          type: string
        subagent_run_id:
          description: |
            Optional target for one live subagent invocation. This is the
            subagent stream `srid`, which is also the parent trigger toolCallId.
            When omitted, the steer is broadcast to the parent and all
            subagents on the live stream.
          maxLength: 512
          minLength: 1
          type: string
        text:
          description: Composer text to inject into the live run
          maxLength: 32000
          minLength: 1
          type: string
      required:
        - text
      type: object
    TaskInputResponse:
      properties:
        applied_locally:
          type: boolean
        id:
          type: string
        message:
          type: string
        stream_id:
          type: string
        success:
          type: boolean
      required:
        - success
        - message
        - stream_id
        - id
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````