> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List Triage sources

> List the active Triage sources of your team, oldest first. Removed sources are not listed. Credentials are never returned; a source shows only whether one is configured.




## OpenAPI

````yaml /openapi/neo.public.openapi.json get /api/v1/triage/sources
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/triage/sources:
    get:
      tags:
        - Triage
      summary: List Triage sources
      description: >
        List the active Triage sources of your team, oldest first. Removed
        sources are not listed. Credentials are never returned; a source shows
        only whether one is configured.
      operationId: get-v1-triage-sources
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageSourceListResponse'
          description: Active sources of the team
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: You are not a member of a team
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
        '503':
          $ref: '#/components/responses/TriageSourcesUnavailable'
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    TriageSourceListResponse:
      properties:
        count:
          type: integer
        sources:
          items:
            $ref: '#/components/schemas/TriageSource'
          type: array
      required:
        - sources
        - count
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. `access_restricted`

            (HTTP 403) denies hosted Neo access under the access policy. On team

            invitations, param=email identifies a restricted recipient rather

            than the caller; show the error without redirecting the caller.
            Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        param:
          description: >-
            Field rejected by the policy; email for a restricted invite
            recipient.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
    TriageSource:
      description: >
        A Triage source of your team. Credentials are never returned:
        credential_configured shows whether one is stored.
      properties:
        configuration_version:
          description: >-
            Incremented by every change of documentation, request template,
            pagination or mapping.
          type: integer
        created_at:
          format: date-time
          type: string
        credential_configured:
          type: boolean
        documentation:
          $ref: '#/components/schemas/TriageSourceDocumentation'
        enabled:
          description: True when scheduled synchronization is on.
          type: boolean
        id:
          format: uuid
          type: string
        kind:
          $ref: '#/components/schemas/TriageSourceKind'
        last_error_code:
          description: >-
            Stable code of the last failure, such as target_not_public or
            upstream_status. On a ready source it is a warning from the last
            synchronization, such as record_limit or page_limit when the listing
            was longer than one synchronization reads.
          type: string
        last_synced_at:
          format: date-time
          type: string
        mapping:
          $ref: '#/components/schemas/TriageSourceMapping'
        name:
          type: string
        next_sync_at:
          format: date-time
          type: string
        pagination:
          $ref: '#/components/schemas/TriageSourcePagination'
        request_template:
          $ref: '#/components/schemas/TriageSourceRequestTemplate'
        schedule:
          $ref: '#/components/schemas/TriageSourceSyncInterval'
        setup_mode:
          $ref: '#/components/schemas/TriageSourceSetupMode'
        status:
          $ref: '#/components/schemas/TriageSourceStatus'
        team_id:
          format: uuid
          type: string
        tested_configuration_version:
          description: >-
            Configuration version that last passed a test (0 when none).
            Synchronization needs it to equal configuration_version.
          type: integer
        updated_at:
          format: date-time
          type: string
      required:
        - id
        - team_id
        - kind
        - name
        - status
        - enabled
        - setup_mode
        - schedule
        - documentation
        - credential_configured
        - configuration_version
        - tested_configuration_version
        - created_at
        - updated_at
      type: object
    TriageSourceDocumentation:
      description: Documentation reference of a source. Pasted documents are not returned.
      properties:
        format:
          type: string
        inline_configured:
          description: True when a pasted document is stored.
          type: boolean
        url:
          type: string
      type: object
    TriageSourceKind:
      description: >
        hackerone, github and gmail are built-in connections; custom_api is a
        source you configure.
      enum:
        - hackerone
        - github
        - gmail
        - custom_api
      type: string
      x-enum-varnames:
        - TriageSourceKindHackerone
        - TriageSourceKindGithub
        - TriageSourceKindGmail
        - TriageSourceKindCustomApi
    TriageSourceMapping:
      description: >
        Dot paths from each provider record to the normalized finding fields.
        external_key identifies a record inside the source.
      properties:
        description:
          maxLength: 256
          type: string
        external_key:
          maxLength: 256
          type: string
        reporter:
          maxLength: 256
          type: string
        severity:
          maxLength: 256
          type: string
        severity_values:
          additionalProperties:
            items:
              maxLength: 256
              type: string
            maxItems: 20
            type: array
          description: >-
            Provider values for each Neo severity (none, low, medium, high,
            critical).
          maxProperties: 6
          type: object
        status:
          maxLength: 256
          type: string
        title:
          maxLength: 256
          type: string
        updated_at:
          maxLength: 256
          type: string
        url:
          maxLength: 256
          type: string
      required:
        - external_key
      type: object
    TriageSourcePagination:
      description: How a synchronization walks the listing.
      properties:
        cursor_param:
          maxLength: 256
          type: string
        cursor_path:
          maxLength: 256
          type: string
        items_path:
          description: Dot path of the record array in each page.
          maxLength: 256
          type: string
        next_url_path:
          maxLength: 256
          type: string
        page_param:
          maxLength: 256
          type: string
        page_size:
          maximum: 1000
          minimum: 1
          type: integer
        size_param:
          maxLength: 256
          type: string
        start:
          minimum: 0
          type: integer
        type:
          enum:
            - none
            - page
            - offset
            - cursor
            - link_header
            - next_url
          type: string
          x-enum-varnames:
            - TriageSourcePaginationTypeNone
            - TriageSourcePaginationTypePage
            - TriageSourcePaginationTypeOffset
            - TriageSourcePaginationTypeCursor
            - TriageSourcePaginationTypeLinkHeader
            - TriageSourcePaginationTypeNextUrl
      required:
        - type
      type: object
    TriageSourceRequestTemplate:
      description: >
        The request a synchronization sends. Header and query values are stored
        and returned as typed, so never put a credential in them.
      properties:
        auth:
          $ref: '#/components/schemas/TriageSourceAuth'
        body:
          description: Optional JSON request body (at most 8 KiB).
        headers:
          additionalProperties:
            maxLength: 256
            type: string
          maxProperties: 20
          type: object
        method:
          enum:
            - GET
            - POST
            - PUT
            - PATCH
          type: string
          x-enum-varnames:
            - TriageSourceRequestTemplateMethodGET
            - TriageSourceRequestTemplateMethodPOST
            - TriageSourceRequestTemplateMethodPUT
            - TriageSourceRequestTemplateMethodPATCH
        query:
          additionalProperties:
            maxLength: 256
            type: string
          maxProperties: 20
          type: object
        url:
          description: Public https URL of the findings listing.
          maxLength: 2048
          type: string
      required:
        - method
        - url
      type: object
    TriageSourceSyncInterval:
      description: Interval between scheduled synchronizations.
      enum:
        - 1h
        - 6h
        - 12h
        - 24h
      type: string
      x-enum-varnames:
        - TriageSourceSyncIntervalN1h
        - TriageSourceSyncIntervalN6h
        - TriageSourceSyncIntervalN12h
        - TriageSourceSyncIntervalN24h
    TriageSourceSetupMode:
      description: >
        documentation reads an OpenAPI 3 or Swagger 2 document to propose the
        configuration; manual takes the configuration as entered.
      enum:
        - documentation
        - manual
      type: string
      x-enum-varnames:
        - TriageSourceSetupModeDocumentation
        - TriageSourceSetupModeManual
    TriageSourceStatus:
      description: >-
        Server-controlled lifecycle state of a source. A failed scheduled or
        manual synchronization sets failed and backs the next one off (the
        schedule interval times 2^min(failures, 4), at most 24 hours later).
        After 10 failed synchronizations in a row the source is paused:
        disabled, enabled false, last_error_code kept. A successful
        synchronization or re-enabling the source resets the count.
      enum:
        - draft
        - analyzing
        - configuration_required
        - testing
        - setting_up
        - ready
        - syncing
        - failed
        - disabled
        - removed
      type: string
      x-enum-varnames:
        - TriageSourceStatusDraft
        - TriageSourceStatusAnalyzing
        - TriageSourceStatusConfigurationRequired
        - TriageSourceStatusTesting
        - TriageSourceStatusSettingUp
        - TriageSourceStatusReady
        - TriageSourceStatusSyncing
        - TriageSourceStatusFailed
        - TriageSourceStatusDisabled
        - TriageSourceStatusRemoved
    TriageSourceAuth:
      description: >
        Where the credential goes in each request. It names the location; it
        never contains the credential itself.
      properties:
        header_name:
          description: Header that carries the API key (header_api_key).
          maxLength: 256
          type: string
        query_name:
          description: Query parameter that carries the API key (query_api_key).
          maxLength: 256
          type: string
        scopes:
          description: Space-separated OAuth scopes (oauth2_client_credentials).
          maxLength: 256
          type: string
        token_url:
          description: Public https token endpoint (oauth2_client_credentials).
          maxLength: 2048
          type: string
        type:
          enum:
            - none
            - header_api_key
            - query_api_key
            - bearer
            - basic
            - oauth2_client_credentials
          type: string
          x-enum-varnames:
            - TriageSourceAuthTypeNone
            - TriageSourceAuthTypeHeaderApiKey
            - TriageSourceAuthTypeQueryApiKey
            - TriageSourceAuthTypeBearer
            - TriageSourceAuthTypeBasic
            - TriageSourceAuthTypeOauth2ClientCredentials
      required:
        - type
      type: object
  responses:
    TriageSourcesUnavailable:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
      description: >-
        This deployment has no custom source tables yet: its database migration
        has not run (custom_sources_unavailable). Retry later.
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.