> ## Documentation Index
> Fetch the complete documentation index at: https://docs.antigen.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Query the graph

> Executes read-only Cypher within your organization’s Asset Map and returns an array of rows. Each row uses the aliases selected by RETURN. No matches returns []. Graph nodes, edges, and paths use the same representation as GET /asset-map.

The HTTP request carries query text and parameters. The SDK accepts a @neo4j/cypher-builder query object and serializes the built query into this body. Parameter values cannot change the query’s organization scope. Writes, administrative operations, and operations that access external resources are rejected.



## OpenAPI

````yaml /reference/openapi.yaml post /asset-map/query
openapi: 3.1.0
info:
  title: Antigen API
  version: v1
  description: >-
    Work with the same agents, runs, and resources your team uses in Antigen.
    Requests and responses use camelCase fields. List endpoints return arrays.
    See the [overview](/reference) for authentication, updates, and errors.
servers:
  - url: https://api.antigen.sh/v1
security:
  - ApiKeyAuth: []
tags:
  - name: Agents
    description: Retrieve, compose, and register agent configurations.
  - name: Models
    description: Models available to agents in your organization.
  - name: Targets
    description: Submit testing scope for human approval.
  - name: Runs
    description: Execute agents and control their work.
  - name: Vulnerabilities
    description: Track weaknesses, remediation, status, and assignment.
  - name: Evidence
    description: Read supporting file metadata and retrieve file contents.
  - name: Reports
    description: Read and export captured engagement results.
  - name: Human tasks
    description: Ask people for help and follow their responses.
  - name: Hooks
    description: Connect status and assignment changes to your own service.
  - name: Asset Map
    description: Read your organization’s infrastructure graph.
  - name: Integrations
    description: Inspect and disconnect provider connections.
  - name: API keys
    description: Create and revoke credentials for automation.
paths:
  /asset-map/query:
    post:
      tags:
        - Asset Map
      summary: Query the graph
      description: >-
        Executes read-only Cypher within your organization’s Asset Map and
        returns an array of rows. Each row uses the aliases selected by RETURN.
        No matches returns []. Graph nodes, edges, and paths use the same
        representation as GET /asset-map.


        The HTTP request carries query text and parameters. The SDK accepts a
        @neo4j/cypher-builder query object and serializes the built query into
        this body. Parameter values cannot change the query’s organization
        scope. Writes, administrative operations, and operations that access
        external resources are rejected.
      operationId: queryAssetMap
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GraphQuery'
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/QueryRows'
        '400':
          $ref: '#/components/responses/Error400'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '429':
          $ref: '#/components/responses/Error429'
components:
  schemas:
    GraphQuery:
      type: object
      properties:
        query:
          type: string
          description: Read-only Cypher statement.
          minLength: 1
        parameters:
          type: object
          additionalProperties: true
          default: {}
          description: Named query parameters. Keep values separate from the query text.
      required:
        - query
      additionalProperties: false
      example:
        query: >-
          MATCH (p:SupabaseProject) WHERE p.region = $region RETURN p.id AS id,
          p.name AS name
        parameters:
          region: us-east-1
    QueryRows:
      type: array
      items:
        type: object
        additionalProperties: true
        description: >-
          Fields selected by RETURN. Nodes use GraphNode, relationships use
          GraphEdge, and paths use nodes and edges arrays. Scalar values and
          lists are JSON values.
      example:
        - id: project_123
          name: production
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable error code.
            message:
              type: string
              description: Description of the problem.
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      example:
        error:
          code: invalid_request
          message: The target value is required.
  responses:
    Error400:
      description: Invalid request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: invalid_request
              message: Check the request fields and values.
    Error401:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: unauthorized
              message: Supply a valid API key.
    Error403:
      description: Permission denied
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: forbidden
              message: The API key does not permit this operation or requested scope.
    Error429:
      description: Too many requests
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: rate_limited
              message: Retry after the interval in Retry-After.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 1
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        API key from your organization. Supply the value directly, without a
        Bearer prefix.

````