> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Start vulnerability triage

> Start one or more Neo triage runs for reports from HackerOne, GitHub Security Advisories, or Security Inbox (Gmail). Neo builds the triage prompt and queues each run on the same durable task-start path as normal tasks — custom free-form task text is not accepted. Up to 20 items per request. Items already being triaged are skipped. Requires Neo AI access and available credits.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json post /api/v1/triage
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/triage:
    post:
      tags:
        - Triage
      summary: Start vulnerability triage
      description: >
        Start one or more Neo triage runs for reports from HackerOne, GitHub
        Security Advisories, or Security Inbox (Gmail). Neo builds the triage
        prompt and queues each run on the same durable task-start path as normal
        tasks — custom free-form task text is not accepted. Up to 20 items per
        request. Items already being triaged are skipped. Requires Neo AI access
        and available credits.
      operationId: post-v1-triage
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TriageCreateRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriageCreateResponse'
          description: >-
            Per-item results. Some items may succeed while others are skipped or
            rejected.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Invalid request, model, or team membership
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '402':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Insufficient credits
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Neo AI access required
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unexpected server error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    TriageCreateRequest:
      properties:
        items:
          items:
            $ref: '#/components/schemas/TriageCreateItem'
          maxItems: 20
          minItems: 1
          type: array
        model:
          description: >
            Optional model to use for triage. An invalid value rejects the
            entire request before any items are started.
          type: string
        source:
          description: Source for every item in this request.
          enum:
            - hackerone
            - github
            - gmail
          type: string
      required:
        - source
        - items
      type: object
    TriageCreateResponse:
      properties:
        results:
          items:
            $ref: '#/components/schemas/TriageCreateResult'
          type: array
        summary:
          $ref: '#/components/schemas/TriageCreateSummary'
      required:
        - results
        - summary
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
    TriageCreateItem:
      properties:
        context:
          description: >
            Optional scope — HackerOne program handle, GitHub owner/repo, or
            Security Inbox mailbox email. Required for Gmail.
          type: string
        external_id:
          description: >
            HackerOne report id, GitHub security advisory id, or Gmail thread
            id.
          minLength: 1
          type: string
      required:
        - external_id
      type: object
    TriageCreateResult:
      properties:
        error:
          $ref: '#/components/schemas/TriageCreateError'
        external_id:
          type: string
        status:
          enum:
            - accepted
            - skipped
            - rejected
          type: string
        task_id:
          description: Present when status is accepted.
          format: uuid
          type: string
      required:
        - external_id
        - status
      type: object
    TriageCreateSummary:
      properties:
        accepted:
          type: integer
        rejected:
          type: integer
        skipped:
          type: integer
      required:
        - accepted
        - skipped
        - rejected
      type: object
    TriageCreateError:
      properties:
        code:
          description: >
            Error code explaining why the item was skipped or rejected (for
            example triage already in progress, duplicate in request, or source
            not connected).
          type: string
        message:
          type: string
      required:
        - code
        - message
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````