Skip to main content
Use the Antigen API from your own service, an external agent, or any language that can make HTTP requests. It works with the same resources as the platform and the Antigen SDK. The base URL is https://api.antigen.sh/v1.

Make a request

Create an API key in the platform and send it in the x-api-key header:
The key determines your organization and permissions. Keep it in your backend or secret store. See Authentication for creating and replacing keys.

Start a run

Send an agent configuration and a task to POST /runs. This example uses tCell’s configuration and an approved target:
Replace the hostname with a target approved for your organization. The response contains the run’s ID and status. Work continues in the background; retrieve GET /runs/{id} to check progress or connect to GET /runs/{id}/events to stream activity. You can supply configuration fields alongside base to customize the agent, or supply a model and configuration without a pre-built base. To work on existing vulnerabilities, include vulnerabilityIds in the task.

Resources

Skills, guardrails, and tools are fields on an agent configuration. Steering, stopping, and resuming operate on a run. Status and assignment are fields on a vulnerability. Authorized agent runs create vulnerabilities and evidence through their tools. The public API lets your applications read those results and coordinate the work that follows.

Requests and responses

JSON fields use camelCase, including vulnerabilityId and createdAt. IDs are opaque strings. Timestamps use ISO 8601 in UTC. List endpoints return an array containing all matching resources. An empty result is []. Filters apply together. There are no pagination parameters or result envelopes. PATCH changes only the fields you supply. Arrays replace their previous values. To append to an array, retrieve the resource, combine the values in your code, and send the resulting array. Fields accept null only where the reference allows it. Creation returns 201. Reads and completed updates return 200. Steering returns 202 when the message is accepted. Deletion returns 204 with no response body. Starting a run returns before the agent finishes its work. Status and assignment changes trigger the same hooks as changes made in the platform. See Webhook events for payloads and delivery verification.

Errors

Errors use the same JSON shape across endpoints:
Each endpoint documents its request, response, and applicable errors.