Skip to main content
GET
List the Triage queue

Authorizations

Authorization
string
header
required

JWT authentication token

Query Parameters

source_id
string<uuid>[]

Only findings of these sources (repeat the parameter for several).

Maximum array length: 50
source_kind
enum<string>[]

Only findings of sources of these kinds.

Maximum array length: 4

hackerone, github and gmail are built-in connections; custom_api is a source you configure.

Available options:
hackerone,
github,
gmail,
custom_api
context
string[]

Only findings of these accounts within a source (a HackerOne program, a GitHub repository, a mailbox), compared without case.

Maximum array length: 50
Maximum string length: 256
view
enum<string>

A saved view of the queue. all: findings that are not closed. needs_decision: untriaged or verdict ready with no decision. critical_high: open findings whose effective severity is critical or high. in_fix: accepted findings being fixed. waiting: open findings older than 7 days. snoozed: findings with an active snooze. Omit to list every stage.

Available options:
all,
needs_decision,
critical_high,
in_fix,
waiting,
snoozed
stage
enum<string>[]

Only findings in these stages.

Maximum array length: 5
Available options:
untriaged,
investigating,
verdict_ready,
in_fix,
closed
severity
enum<string>[]

Only findings whose effective severity (override, then the latest valid run, then the source) is one of these; none also matches an unknown severity.

Maximum array length: 5
Available options:
critical,
high,
medium,
low,
none
state
string[]

Only findings whose status at the source is one of these, compared without case.

Maximum array length: 20
Maximum string length: 128
q
string

Search in the title and the external key, without case.

Maximum string length: 200
sort
enum<string>
default:updated

updated (default): most recently changed first. priority: effective severity, then the oldest first. newest and oldest: by age, the report date at the source when known, else the first time Neo saw the finding.

Available options:
updated,
priority,
newest,
oldest
include_snoozed
boolean
default:false

Include findings with an active snooze in the other views and filters. The snoozed view always lists them, and needs_decision never does (a snooze is a decision until it expires).

include
enum<string>[]

counts adds the queue counts to the response (computed in the same snapshot as the page).

Maximum array length: 1
Available options:
counts
archived
boolean

True lists only archived findings, false only active ones. Omit to list both.

cursor
string

The next_cursor of the previous page.

Required string length: 1 - 200
limit
integer
default:50

Maximum number of findings. Defaults to 50.

Required range: 1 <= x <= 100

Response

One page of findings

count
integer<int64>
required

Number of findings that match the filters (all pages).

findings
object[]
required
counts
object

The queue counts, read in the same snapshot as the page. Each facet ignores its own filter and applies the others; open means a stage other than closed.

next_cursor
string | null

Pass as cursor to read the next page. Null on the last page.