> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Change the settings of a Triage source

> Change the supplied settings of one source of your team. Team admins only. Inbox listings and synchronization never write these settings, so a display name survives them. The update policy is stored and never executed. Saving an enabled auto triage rule makes you its actor: the rule runs as you, so your membership, admin role, visibility of the source, the model and your credit eligibility are checked now and again before every run. Disabling the rule cancels its queued jobs. Built-in sources accept settings whatever TRIAGE_CUSTOM_SOURCES_MODE says; enabling auto triage on a custom source needs custom sources on.




## OpenAPI

````yaml /openapi/neo.public.openapi.json patch /api/v1/triage/sources/{id}/settings
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/triage/sources/{id}/settings:
    parameters:
      - $ref: '#/components/parameters/TriageSourceId'
    patch:
      tags:
        - Triage
      summary: Change the settings of a Triage source
      description: >
        Change the supplied settings of one source of your team. Team admins
        only. Inbox listings and synchronization never write these settings, so
        a display name survives them. The update policy is stored and never
        executed. Saving an enabled auto triage rule makes you its actor: the
        rule runs as you, so your membership, admin role, visibility of the
        source, the model and your credit eligibility are checked now and again
        before every run. Disabling the rule cancels its queued jobs. Built-in
        sources accept settings whatever TRIAGE_CUSTOM_SOURCES_MODE says;
        enabling auto triage on a custom source needs custom sources on.
      operationId: patch-v1-triage-sources-id-settings
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TriageSourceSettingsPatch'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageSourceSettings'
          description: The source settings after the change
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Invalid settings (invalid_request), an unknown model
            (invalid_model), or you are not a member of a team
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '402':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Your account has no credits left to run auto triage
            (insufficient_credits)
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Only team admins change source settings (forbidden), or your plan
            cannot start runs outside the web app (free_origin_not_supported)
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Source not found in your team, or a built-in connection you cannot
            see (source_not_found)
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Triage reviews are turned off (triage_reviews_disabled), custom
            sources are turned off and the change enables auto triage on a
            custom source (custom_sources_disabled), or this deployment has not
            finished its database migration (custom_sources_unavailable)
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  parameters:
    TriageSourceId:
      description: Source id
      in: path
      name: id
      required: true
      schema:
        format: uuid
        type: string
  schemas:
    TriageSourceSettingsPatch:
      description: Settings to change; omitted fields keep their value.
      properties:
        auto_triage:
          $ref: '#/components/schemas/TriageAutoTriageRuleInput'
        closed_status_values:
          description: >-
            Source status values that count as closed at the source (custom API
            sources). Replaces the stored values.
          items:
            maxLength: 100
            minLength: 1
            type: string
          maxItems: 50
          type: array
        context_labels:
          additionalProperties:
            maxLength: 80
            type: string
          description: Display labels per context. Replaces the stored labels.
          maxProperties: 200
          type: object
        display_name:
          description: >-
            Name to show for the source. Inbox listings and synchronization
            never change it.
          maxLength: 80
          minLength: 1
          type: string
        update_policy:
          additionalProperties: true
          description: >-
            How the source would be updated after a review. Stored only; never
            executed.
          type: object
      type: object
    TriageSourceSettings:
      description: >
        The settings of a source: its display name, labels per context, update
        policy (stored, never executed), closed status values (custom sources)
        and auto triage rule.
      properties:
        auto_triage:
          $ref: '#/components/schemas/TriageAutoTriageRule'
        closed_status_values:
          description: >-
            Source status values that count as closed at the source (custom API
            sources).
          items:
            type: string
          type: array
        context_labels:
          additionalProperties:
            type: string
          description: >-
            Display labels per context, for example a name for a HackerOne
            program handle.
          type: object
        display_name:
          description: The name set in the settings, or the source name when none is set.
          type: string
        source_id:
          description: The source these settings belong to.
          format: uuid
          type: string
        update_policy:
          additionalProperties: true
          description: >-
            How the source would be updated after a review. Stored only; Neo
            never writes to the source.
          type: object
        updated_at:
          description: When the settings last changed.
          format: date-time
          type: string
      required:
        - source_id
        - display_name
        - context_labels
        - update_policy
        - closed_status_values
        - auto_triage
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. `access_restricted`

            (HTTP 403) denies hosted Neo access under the access policy. On team

            invitations, param=email identifies a restricted recipient rather

            than the caller; show the error without redirecting the caller.
            Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        param:
          description: >-
            Field rejected by the policy; email for a restricted invite
            recipient.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
    TriageAutoTriageRuleInput:
      description: >-
        The auto triage rule to save. Saving it enabled makes you the admin it
        runs as.
      properties:
        contexts:
          description: >-
            Contexts (for example HackerOne programs) to triage. Empty means
            every context.
          items:
            maxLength: 256
            minLength: 1
            type: string
          maxItems: 50
          type: array
        enabled:
          description: Turn the rule on or off. Turning it off cancels its queued runs.
          type: boolean
        interval_minutes:
          $ref: '#/components/schemas/TriageAutoTriageInterval'
        model:
          description: Model of the runs. Empty uses the default triage model.
          maxLength: 100
          type: string
      required:
        - enabled
      type: object
    TriageAutoTriageRule:
      description: >
        The auto triage rule of a source. It runs as its actor, the admin who
        last saved it enabled. A rule pauses (enabled false, last_error_code
        set) when its actor leaves the team (membership_revoked), is no longer
        an admin (actor_not_admin), can no longer see the source
        (source_not_visible), or after repeated failed runs. Turning
        TRIAGE_REVIEWS_MODE off (or custom sources off, for a custom source)
        does not pause it: its runs end with triage_reviews_disabled (or
        custom_sources_disabled) and the rule resumes when the switch is on
        again.
      properties:
        consecutive_failures:
          description: Failed runs in a row. The rule pauses after repeated failures.
          type: integer
        contexts:
          description: >-
            Contexts (for example HackerOne programs) the rule triages; empty
            means every context.
          items:
            type: string
          type: array
        enabled:
          description: Whether the rule runs on its interval.
          type: boolean
        interval_minutes:
          $ref: '#/components/schemas/TriageAutoTriageInterval'
        last_error_code:
          description: Stable code of the last failed run or of the pause.
          type: string
        last_run_at:
          description: When the last run ended.
          format: date-time
          type: string
        last_run_count:
          description: Findings the last run claimed.
          type: integer
        model:
          description: Model of the runs; empty uses the default triage model.
          type: string
        next_run_at:
          description: >-
            When the schedule starts the next run. Empty while the rule is
            disabled.
          format: date-time
          type: string
        user_email:
          description: >-
            Email of the admin the rule runs as; null while the rule has no
            actor.
          nullable: true
          type: string
      required:
        - enabled
        - interval_minutes
        - contexts
        - model
        - consecutive_failures
      type: object
    TriageAutoTriageInterval:
      description: Minutes between two auto triage runs of a source.
      enum:
        - 15
        - 30
        - 60
        - 120
        - 360
        - 1440
      type: integer
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.