> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Review a Triage finding

> Record your team's decision on one finding, its severity override or its fix record. Decisions: `accept`, `mark_duplicate` (with `duplicate_of`), `decline` (with `reason`), `snooze` (with `until`, in the future and at most one year ahead; only without a decision or after a snooze ended) and `return_to_queue`. Severity: `set_severity`, `clear_severity`. Fix record of an accepted finding: `update_fix`, `mark_fixed` (with optional `evidence`) and `reopen_fix`. Links are HTTPS only and carry no credentials. Every change names the review `expected_version` it read (0 when the finding has no review) and appends one event to the finding's history. Repeating the current decision changes nothing and returns `event: null`. A repeated `Idempotency-Key` on the same finding returns the first event without a second change. Neo records what a source write-back would do on the event and never writes to the source. Members and admins only; viewers read.




## OpenAPI

````yaml /openapi/neo.public.openapi.json post /api/v1/triage/findings/{id}/review
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/triage/findings/{id}/review:
    post:
      tags:
        - Triage
      summary: Review a Triage finding
      description: >
        Record your team's decision on one finding, its severity override or its
        fix record. Decisions: `accept`, `mark_duplicate` (with `duplicate_of`),
        `decline` (with `reason`), `snooze` (with `until`, in the future and at
        most one year ahead; only without a decision or after a snooze ended)
        and `return_to_queue`. Severity: `set_severity`, `clear_severity`. Fix
        record of an accepted finding: `update_fix`, `mark_fixed` (with optional
        `evidence`) and `reopen_fix`. Links are HTTPS only and carry no
        credentials. Every change names the review `expected_version` it read (0
        when the finding has no review) and appends one event to the finding's
        history. Repeating the current decision changes nothing and returns
        `event: null`. A repeated `Idempotency-Key` on the same finding returns
        the first event without a second change. Neo records what a source
        write-back would do on the event and never writes to the source. Members
        and admins only; viewers read.
      operationId: post-v1-triage-findings-id-review
      parameters:
        - $ref: '#/components/parameters/TriageFindingId'
        - description: >
            Optional key that makes a repeated request on this finding return
            the first event and review instead of changing it again.
          in: header
          name: Idempotency-Key
          required: false
          schema:
            maxLength: 200
            minLength: 1
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TriageFindingReviewRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageFindingReviewResponse'
          description: >-
            The review after the change, and the event it appended (null when
            nothing changed)
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Invalid request (invalid_request), a duplicate target that is the
            finding itself or that you cannot see (duplicate_target_invalid), a
            snooze end in the past or more than one year ahead (snooze_invalid),
            a fix link that is not HTTPS or carries credentials (invalid_url),
            or you are not a member of a team
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Viewers cannot review findings (forbidden)
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Finding not found in your team, or its source is not visible to you
            (finding_not_found)
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            The review changed since you read it (review_conflict), the action
            does not apply to the current review (invalid_transition), the
            duplicate target is itself a duplicate (duplicate_cycle), or a
            retest of the fix is running (run_in_flight)
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Reviews are turned off (triage_reviews_disabled), or this deployment
            has not finished its database migration (custom_sources_unavailable)
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  parameters:
    TriageFindingId:
      description: Finding id
      in: path
      name: id
      required: true
      schema:
        format: uuid
        type: string
  schemas:
    TriageFindingReviewRequest:
      description: >-
        One change of a finding review, such as a decision, a severity override
        or a fix record change.
      properties:
        action:
          description: >
            The change to make. Decisions are accept, mark_duplicate, decline,
            snooze and return_to_queue; set_severity and clear_severity change
            the severity override; update_fix, mark_fixed and reopen_fix change
            the fix record of an accepted finding.
          enum:
            - accept
            - mark_duplicate
            - decline
            - snooze
            - return_to_queue
            - set_severity
            - clear_severity
            - update_fix
            - mark_fixed
            - reopen_fix
          type: string
          x-enum-varnames:
            - TriageFindingReviewActionAccept
            - TriageFindingReviewActionMarkDuplicate
            - TriageFindingReviewActionDecline
            - TriageFindingReviewActionSnooze
            - TriageFindingReviewActionReturnToQueue
            - TriageFindingReviewActionSetSeverity
            - TriageFindingReviewActionClearSeverity
            - TriageFindingReviewActionUpdateFix
            - TriageFindingReviewActionMarkFixed
            - TriageFindingReviewActionReopenFix
        duplicate_of:
          description: Required for mark_duplicate.
          format: uuid
          type: string
        evidence:
          description: Evidence of mark_fixed.
          maxLength: 2000
          type: string
        expected_version:
          description: The review version you read; 0 when the finding has no review.
          minimum: 0
          type: integer
        fix:
          $ref: '#/components/schemas/TriageFindingFixPatch'
        note:
          description: >-
            Note of the change, kept on the event (and on the decision for a
            decision).
          maxLength: 2000
          type: string
        reason:
          description: Required for decline.
          enum:
            - false_positive
            - accepted_risk
            - wont_fix
          type: string
          x-enum-varnames:
            - TriageFindingReviewRequestReasonFalsePositive
            - TriageFindingReviewRequestReasonAcceptedRisk
            - TriageFindingReviewRequestReasonWontFix
        severity:
          description: Required for set_severity.
          enum:
            - none
            - low
            - medium
            - high
            - critical
          type: string
          x-enum-varnames:
            - TriageFindingReviewRequestSeverityNone
            - TriageFindingReviewRequestSeverityLow
            - TriageFindingReviewRequestSeverityMedium
            - TriageFindingReviewRequestSeverityHigh
            - TriageFindingReviewRequestSeverityCritical
        until:
          description: Required for snooze. In the future and at most one year ahead.
          format: date-time
          type: string
      required:
        - action
        - expected_version
      type: object
    TriageFindingReviewResponse:
      description: The review after a change, and the event the change appended.
      properties:
        event:
          allOf:
            - $ref: '#/components/schemas/TriageFindingEvent'
          description: The appended event. Null when the request changed nothing.
          nullable: true
        review:
          $ref: '#/components/schemas/TriageFindingReview'
      required:
        - review
        - event
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. `access_restricted`

            (HTTP 403) denies hosted Neo access under the access policy. On team

            invitations, param=email identifies a restricted recipient rather

            than the caller; show the error without redirecting the caller.
            Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        param:
          description: >-
            Field rejected by the policy; email for a restricted invite
            recipient.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
    TriageFindingFixPatch:
      description: >
        Changes to the fix record. An omitted field stays as it is; an empty
        string clears a link or the note. Links are HTTPS only and carry no
        credentials.
      properties:
        note:
          description: Note on the fix.
          maxLength: 2000
          type: string
        pr_url:
          description: Pull request of the fix (HTTPS, no credentials).
          maxLength: 2048
          type: string
        repository_url:
          description: Repository of the fix (HTTPS, no credentials).
          maxLength: 2048
          type: string
        status:
          description: >-
            New fix status. retesting and fixed are set by a retest and by
            mark_fixed.
          enum:
            - in_progress
            - waiting_for_pr
            - pr_linked
          type: string
          x-enum-varnames:
            - TriageFindingFixPatchStatusInProgress
            - TriageFindingFixPatchStatusWaitingForPr
            - TriageFindingFixPatchStatusPrLinked
        target_url:
          description: Staging target a retest checks (HTTPS, no credentials).
          maxLength: 2048
          type: string
      type: object
    TriageFindingEvent:
      description: One change of a finding's review. Events are append-only.
      properties:
        action:
          description: What changed.
          enum:
            - accepted
            - marked_duplicate
            - declined
            - snoozed
            - returned_to_queue
            - severity_set
            - severity_cleared
            - fix_updated
            - fix_marked_fixed
            - fix_reopened
            - retest_requested
            - retest_completed
            - retest_failed
            - undo
          type: string
          x-enum-varnames:
            - TriageFindingEventActionAccepted
            - TriageFindingEventActionMarkedDuplicate
            - TriageFindingEventActionDeclined
            - TriageFindingEventActionSnoozed
            - TriageFindingEventActionReturnedToQueue
            - TriageFindingEventActionSeveritySet
            - TriageFindingEventActionSeverityCleared
            - TriageFindingEventActionFixUpdated
            - TriageFindingEventActionFixMarkedFixed
            - TriageFindingEventActionFixReopened
            - TriageFindingEventActionRetestRequested
            - TriageFindingEventActionRetestCompleted
            - TriageFindingEventActionRetestFailed
            - TriageFindingEventActionUndo
        actor_kind:
          description: >-
            Who made the change, a member (user), the auto triage rule, or Neo
            (system).
          enum:
            - user
            - auto_triage
            - system
          type: string
          x-enum-varnames:
            - TriageFindingEventActorKindUser
            - TriageFindingEventActorKindAutoTriage
            - TriageFindingEventActorKindSystem
        after:
          additionalProperties: true
          description: >-
            The review after the change (review fields only, without who
            decided).
          type: object
        before:
          additionalProperties: true
          description: >-
            The review before the change (review fields only, without who
            decided).
          type: object
        created_at:
          description: When the change was made.
          format: date-time
          type: string
        finding_id:
          format: uuid
          type: string
        id:
          format: uuid
          type: string
        note:
          description: Note given with the change.
          nullable: true
          type: string
        run_id:
          description: The retest run of a retest event.
          format: uuid
          nullable: true
          type: string
        seq:
          description: Position in the finding's history, from 1, without gaps.
          type: integer
        undoes_event_id:
          description: For an undo, the event it reverses.
          format: uuid
          nullable: true
          type: string
        user_email:
          description: >
            Email of the member who made the change, or on whose behalf a retest
            ran. Null for auto triage and system changes, and when that member's
            account was deleted.
          nullable: true
          type: string
        writeback:
          additionalProperties: true
          description: >
            What a source write-back would do for this change. Recorded only;
            Neo never writes to the source.
          type: object
      required:
        - id
        - finding_id
        - seq
        - actor_kind
        - action
        - before
        - after
        - writeback
        - created_at
      type: object
    TriageFindingReview:
      description: >
        Your team's review of one finding. `decision` is read at request time: a
        snooze that has ended reads as no decision.
      properties:
        decided_at:
          description: When the current decision was made.
          format: date-time
          nullable: true
          type: string
        decided_by_email:
          description: >-
            Email of the member who made the current decision. Null when that
            member's account was deleted.
          nullable: true
          type: string
        decision:
          description: >-
            The active decision. Null without a decision or after a snooze
            ended.
          enum:
            - accepted
            - duplicate
            - declined
            - snoozed
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingReviewDecisionAccepted
            - TriageFindingReviewDecisionDuplicate
            - TriageFindingReviewDecisionDeclined
            - TriageFindingReviewDecisionSnoozed
        decline_reason:
          description: Why the finding was declined.
          enum:
            - false_positive
            - accepted_risk
            - wont_fix
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingReviewDeclineReasonFalsePositive
            - TriageFindingReviewDeclineReasonAcceptedRisk
            - TriageFindingReviewDeclineReasonWontFix
        duplicate_of:
          description: The finding this one duplicates.
          format: uuid
          nullable: true
          type: string
        duplicate_of_title:
          description: >
            Title of the duplicate target. Null when you cannot see the target's
            source.
          nullable: true
          type: string
        fix:
          allOf:
            - $ref: '#/components/schemas/TriageFindingReviewFix'
          description: Null when the finding has no fix record.
          nullable: true
        note:
          description: Note of the current decision.
          nullable: true
          type: string
        severity_override:
          description: >-
            Severity your team set. It wins over the source and run severity
            until it is cleared.
          enum:
            - none
            - low
            - medium
            - high
            - critical
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingReviewSeverityOverrideNone
            - TriageFindingReviewSeverityOverrideLow
            - TriageFindingReviewSeverityOverrideMedium
            - TriageFindingReviewSeverityOverrideHigh
            - TriageFindingReviewSeverityOverrideCritical
        snoozed_until:
          description: When the snooze ends.
          format: date-time
          nullable: true
          type: string
        updated_at:
          description: When the review last changed.
          format: date-time
          nullable: true
          type: string
        version:
          description: >
            Increases with every change. Send it as expected_version of the next
            change; 0 means the finding has no review yet.
          type: integer
      required:
        - version
      type: object
    TriageFindingReviewFix:
      description: The fix record of an accepted finding.
      properties:
        evidence:
          description: Evidence given when the fix was marked fixed.
          nullable: true
          type: string
        fixed_at:
          description: When the fix was marked fixed.
          format: date-time
          nullable: true
          type: string
        note:
          description: Note on the fix.
          nullable: true
          type: string
        pr_url:
          description: Pull request of the fix (HTTPS).
          nullable: true
          type: string
        repository_url:
          description: Repository of the fix (HTTPS).
          nullable: true
          type: string
        retest_run_id:
          description: The retest run that set the fix to retesting.
          format: uuid
          nullable: true
          type: string
        status:
          description: retesting while a retest run of the fix is active.
          enum:
            - in_progress
            - waiting_for_pr
            - pr_linked
            - retesting
            - fixed
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingReviewFixStatusInProgress
            - TriageFindingReviewFixStatusWaitingForPr
            - TriageFindingReviewFixStatusPrLinked
            - TriageFindingReviewFixStatusRetesting
            - TriageFindingReviewFixStatusFixed
        target_url:
          description: The staging target a retest checks.
          nullable: true
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.