> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Start a triage run for a finding

> Start a Neo triage run for one finding of your team. This is the one route that starts triage for every source: HackerOne reports, GitHub security advisories, Security Inbox (Gmail) threads and custom API source findings, each addressed by its opaque finding id. Neo builds the triage prompt (custom free-form task text is not accepted) and queues the task on the same durable task-start path as normal tasks. Each run is appended to the finding's history and pins the finding revision it triages. Only one run per finding can be active: a second request while one is queued or running returns 409 run_in_flight. Built-in sources must still be connected. Custom source findings are triaged from the record Neo stored at synchronization; Neo does not call the source and never sends its credential to the task. Requires Neo AI access and available credits; viewers cannot start runs.




## OpenAPI

````yaml /openapi/neo.public.openapi.json post /api/v1/triage/findings/{id}/runs
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/triage/findings/{id}/runs:
    post:
      tags:
        - Triage
      summary: Start a triage run for a finding
      description: >
        Start a Neo triage run for one finding of your team. This is the one
        route that starts triage for every source: HackerOne reports, GitHub
        security advisories, Security Inbox (Gmail) threads and custom API
        source findings, each addressed by its opaque finding id. Neo builds the
        triage prompt (custom free-form task text is not accepted) and queues
        the task on the same durable task-start path as normal tasks. Each run
        is appended to the finding's history and pins the finding revision it
        triages. Only one run per finding can be active: a second request while
        one is queued or running returns 409 run_in_flight. Built-in sources
        must still be connected. Custom source findings are triaged from the
        record Neo stored at synchronization; Neo does not call the source and
        never sends its credential to the task. Requires Neo AI access and
        available credits; viewers cannot start runs.
      operationId: post-v1-triage-findings-id-runs
      parameters:
        - $ref: '#/components/parameters/TriageFindingId'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TriageFindingRunRequest'
        required: false
      responses:
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageFindingRun'
          description: The run was claimed and its task queued
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Invalid model, invalid finding identity for its source, or you are
            not a member of a team
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '402':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Insufficient credits or usage. Usage-accounted denials use the task
            error codes: `free_usage_exhausted`, `weekly_usage_limit_reached`,
            `billing_period_usage_limit_reached`, `topup_required`,
            `model_not_available_on_free`, and `subscription_required`.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Neo AI access required, viewer role, or the source connection is
            private to another member
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Finding not found in your team
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            A run of this finding is already queued or running (run_in_flight),
            or the built-in source is not connected (source_not_connected)
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
        '502':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: The triage task could not be queued (enqueue_failed)
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Custom sources are turned off (custom_sources_disabled); built-in
            sources are not affected; or this deployment has no custom source
            tables yet (custom_sources_unavailable)
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  parameters:
    TriageFindingId:
      description: Finding id
      in: path
      name: id
      required: true
      schema:
        format: uuid
        type: string
  schemas:
    TriageFindingRunRequest:
      properties:
        model:
          description: >
            Optional model to use for triage. An invalid value rejects the
            request before a run is claimed.
          type: string
      type: object
    TriageFindingRun:
      description: One triage run of a finding. Runs are append-only.
      properties:
        completed_at:
          format: date-time
          nullable: true
          type: string
        created_at:
          format: date-time
          type: string
        error_code:
          description: Stable failure code when status is failed, such as enqueue_failed.
          nullable: true
          type: string
        finding_id:
          format: uuid
          type: string
        finding_revision:
          description: The finding revision this run triages.
          type: integer
        id:
          format: uuid
          type: string
        internal_summary:
          nullable: true
          type: string
        model:
          description: Model requested for the run. Empty means the default.
          type: string
        status:
          enum:
            - queued
            - running
            - completed
            - failed
            - cancelled
          type: string
          x-enum-varnames:
            - TriageFindingRunStatusQueued
            - TriageFindingRunStatusRunning
            - TriageFindingRunStatusCompleted
            - TriageFindingRunStatusFailed
            - TriageFindingRunStatusCancelled
        suggested_response:
          nullable: true
          type: string
        task_id:
          description: Neo task id of this run once dispatched.
          format: uuid
          nullable: true
          type: string
        task_status:
          description: Current Neo task status, when the run has a task.
          enum:
            - pending
            - active
            - completed
            - error
            - aborted
            - suspended
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTaskStatusPending
            - TriageFindingRunTaskStatusActive
            - TriageFindingRunTaskStatusCompleted
            - TriageFindingRunTaskStatusError
            - TriageFindingRunTaskStatusAborted
            - TriageFindingRunTaskStatusSuspended
        triage_severity:
          description: Neo suggested severity. Only set when triage_status is valid.
          enum:
            - none
            - low
            - medium
            - high
            - critical
            - unknown
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTriageSeverityNone
            - TriageFindingRunTriageSeverityLow
            - TriageFindingRunTriageSeverityMedium
            - TriageFindingRunTriageSeverityHigh
            - TriageFindingRunTriageSeverityCritical
            - TriageFindingRunTriageSeverityUnknown
        triage_status:
          description: Neo disposition. Null until the run records a decision.
          enum:
            - valid
            - need_more_info
            - duplicate
            - informative
            - not_applicable
            - spam
            - unknown
          nullable: true
          type: string
          x-enum-varnames:
            - TriageFindingRunTriageStatusValid
            - TriageFindingRunTriageStatusNeedMoreInfo
            - TriageFindingRunTriageStatusDuplicate
            - TriageFindingRunTriageStatusInformative
            - TriageFindingRunTriageStatusNotApplicable
            - TriageFindingRunTriageStatusSpam
            - TriageFindingRunTriageStatusUnknown
      required:
        - id
        - finding_id
        - finding_revision
        - status
        - model
        - created_at
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. `access_restricted`

            (HTTP 403) denies hosted Neo access under the access policy. On team

            invitations, param=email identifies a restricted recipient rather

            than the caller; show the error without redirecting the caller.
            Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        param:
          description: >-
            Field rejected by the policy; email for a restricted invite
            recipient.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.