> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List Triage findings

> List the findings of every active source of your team (HackerOne, GitHub, Security Inbox and custom API sources), most recently seen first, with cursor pagination. Each finding has an opaque id that starts triage runs.




## OpenAPI

````yaml /openapi/neo.public.openapi.json get /api/v1/triage/findings
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/triage/findings:
    get:
      tags:
        - Triage
      summary: List Triage findings
      description: >
        List the findings of every active source of your team (HackerOne,
        GitHub, Security Inbox and custom API sources), most recently seen
        first, with cursor pagination. Each finding has an opaque id that starts
        triage runs.
      operationId: get-v1-triage-findings
      parameters:
        - description: Only findings of this source.
          in: query
          name: source_id
          required: false
          schema:
            format: uuid
            type: string
        - $ref: '#/components/parameters/TriageFindingArchived'
        - $ref: '#/components/parameters/TriageFindingCursor'
        - $ref: '#/components/parameters/TriageFindingLimit'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageFindingListResponse'
          description: One page of findings
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Invalid cursor, or you are not a member of a team
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
        '503':
          $ref: '#/components/responses/TriageSourcesUnavailable'
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  parameters:
    TriageFindingArchived:
      description: >
        True lists only archived findings, false only active ones. Omit to list
        both.
      in: query
      name: archived
      required: false
      schema:
        type: boolean
    TriageFindingCursor:
      description: The next_cursor of the previous page.
      in: query
      name: cursor
      required: false
      schema:
        maxLength: 200
        minLength: 1
        type: string
    TriageFindingLimit:
      description: Maximum number of findings. Defaults to 50.
      in: query
      name: limit
      required: false
      schema:
        default: 50
        maximum: 100
        minimum: 1
        type: integer
  schemas:
    TriageFindingListResponse:
      properties:
        count:
          description: Number of findings that match the filters (all pages).
          format: int64
          type: integer
        findings:
          items:
            $ref: '#/components/schemas/TriageFinding'
          type: array
        next_cursor:
          description: Pass as `cursor` to read the next page. Null on the last page.
          nullable: true
          type: string
      required:
        - findings
        - count
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. `access_restricted`

            (HTTP 403) denies hosted Neo access under the access policy. On team

            invitations, param=email identifies a restricted recipient rather

            than the caller; show the error without redirecting the caller.
            Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        param:
          description: >-
            Field rejected by the policy; email for a restricted invite
            recipient.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
    TriageFinding:
      description: >
        A normalized report of one source (HackerOne report, GitHub security
        advisory, Security Inbox thread or custom API source record). Its id is
        opaque; (source, external_key) is its identity at the source.
      properties:
        archived_at:
          format: date-time
          nullable: true
          type: string
        context:
          description: >
            Scope at the source: HackerOne program handle, GitHub owner/repo, or
            Security Inbox mailbox email. Empty for custom API sources.
          type: string
        description:
          type: string
        external_key:
          description: >
            The record's identity at the source: HackerOne report id, GitHub
            security advisory id, Gmail thread id, or the mapped key of a custom
            API source record.
          type: string
        first_seen_at:
          format: date-time
          type: string
        id:
          format: uuid
          type: string
        last_seen_at:
          format: date-time
          type: string
        latest_run:
          allOf:
            - $ref: '#/components/schemas/TriageFindingRun'
          description: The newest triage run of this finding. Null when none exists.
          nullable: true
        raw:
          additionalProperties: true
          description: >
            The bounded source record (at most 64 KiB) as stored. Only returned
            by the single-finding read. Never contains credentials.
          nullable: true
          type: object
        reporter:
          type: string
        revision:
          description: Increases when the source record's content changes.
          type: integer
        severity:
          enum:
            - none
            - low
            - medium
            - high
            - critical
            - unknown
          type: string
          x-enum-varnames:
            - TriageFindingSeverityNone
            - TriageFindingSeverityLow
            - TriageFindingSeverityMedium
            - TriageFindingSeverityHigh
            - TriageFindingSeverityCritical
            - TriageFindingSeverityUnknown
        source_id:
          format: uuid
          type: string
        source_kind:
          $ref: '#/components/schemas/TriageSourceKind'
        source_name:
          type: string
        source_status:
          description: The record's status at the source, as the source reports it.
          type: string
        title:
          type: string
        url:
          type: string
      required:
        - id
        - source_id
        - source_kind
        - source_name
        - external_key
        - title
        - description
        - severity
        - source_status
        - url
        - reporter
        - context
        - revision
        - first_seen_at
        - last_seen_at
      type: object
    TriageFindingRun:
      description: One triage run of a finding. Runs are append-only.
      properties:
        completed_at:
          format: date-time
          nullable: true
          type: string
        created_at:
          format: date-time
          type: string
        error_code:
          description: Stable failure code when status is failed, such as enqueue_failed.
          nullable: true
          type: string
        finding_id:
          format: uuid
          type: string
        finding_revision:
          description: The finding revision this run triages.
          type: integer
        id:
          format: uuid
          type: string
        internal_summary:
          nullable: true
          type: string
        model:
          description: Model requested for the run. Empty means the default.
          type: string
        status:
          enum:
            - queued
            - running
            - completed
            - failed
            - cancelled
          type: string
          x-enum-varnames:
            - TriageFindingRunStatusQueued
            - TriageFindingRunStatusRunning
            - TriageFindingRunStatusCompleted
            - TriageFindingRunStatusFailed
            - TriageFindingRunStatusCancelled
        suggested_response:
          nullable: true
          type: string
        task_id:
          description: Neo task id of this run once dispatched.
          format: uuid
          nullable: true
          type: string
        task_status:
          description: Current Neo task status, when the run has a task.
          enum:
            - pending
            - active
            - completed
            - error
            - aborted
            - suspended
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTaskStatusPending
            - TriageFindingRunTaskStatusActive
            - TriageFindingRunTaskStatusCompleted
            - TriageFindingRunTaskStatusError
            - TriageFindingRunTaskStatusAborted
            - TriageFindingRunTaskStatusSuspended
        triage_severity:
          description: Neo suggested severity. Only set when triage_status is valid.
          enum:
            - none
            - low
            - medium
            - high
            - critical
            - unknown
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTriageSeverityNone
            - TriageFindingRunTriageSeverityLow
            - TriageFindingRunTriageSeverityMedium
            - TriageFindingRunTriageSeverityHigh
            - TriageFindingRunTriageSeverityCritical
            - TriageFindingRunTriageSeverityUnknown
        triage_status:
          description: Neo disposition. Null until the run records a decision.
          enum:
            - valid
            - need_more_info
            - duplicate
            - informative
            - not_applicable
            - spam
            - unknown
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTriageStatusValid
            - TriageFindingRunTriageStatusNeedMoreInfo
            - TriageFindingRunTriageStatusDuplicate
            - TriageFindingRunTriageStatusInformative
            - TriageFindingRunTriageStatusNotApplicable
            - TriageFindingRunTriageStatusSpam
            - TriageFindingRunTriageStatusUnknown
      required:
        - id
        - finding_id
        - finding_revision
        - status
        - model
        - created_at
      type: object
    TriageSourceKind:
      description: >
        hackerone, github and gmail are built-in connections; custom_api is a
        source you configure.
      enum:
        - hackerone
        - github
        - gmail
        - custom_api
      type: string
      x-enum-varnames:
        - TriageSourceKindHackerone
        - TriageSourceKindGithub
        - TriageSourceKindGmail
        - TriageSourceKindCustomApi
  responses:
    TriageSourcesUnavailable:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
      description: >-
        This deployment has no custom source tables yet: its database migration
        has not run (custom_sources_unavailable). Retry later.
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.