Create a human task
Creates an open request assigned to a person. Connected messaging tools deliver a direct message; connected issue trackers create an assigned issue. Both refer to the same task when both are configured.
An optional completion condition lets the GitHub integration confirm a pull request merge. Otherwise the assigned person confirms the work through a connected tool. See Human tasks.
curl --request POST \
--url https://api.antigen.sh/v1/human-tasks \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
}
}
'import requests
url = "https://api.antigen.sh/v1/human-tasks"
payload = {
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
}
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
vulnerabilityId: 'vuln_123',
assignee: 'alex@example.com',
title: 'Review and merge the invoice fix',
description: 'Review the ownership check and merge the pull request once approved.',
completion: {type: 'pull_request_merged', url: 'https://github.com/acme/payments/pull/42'}
})
};
fetch('https://api.antigen.sh/v1/human-tasks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/human-tasks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'vulnerabilityId' => 'vuln_123',
'assignee' => 'alex@example.com',
'title' => 'Review and merge the invoice fix',
'description' => 'Review the ownership check and merge the pull request once approved.',
'completion' => [
'type' => 'pull_request_merged',
'url' => 'https://github.com/acme/payments/pull/42'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/human-tasks"
payload := strings.NewReader("{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/human-tasks")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/human-tasks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "task_123",
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
},
"status": "open",
"response": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Body
Vulnerability this request relates to.
1Email of the responsible person in your organization.
Action the person needs to take.
1What is needed, why, and how to confirm completion.
1Optional condition confirmed through a connected integration.
Show child attributes
Show child attributes
Response
Created.
1Vulnerability this request relates to.
1Email of the responsible person in your organization.
Action the person needs to take.
1What is needed, why, and how to confirm completion.
1Optional condition confirmed through a connected integration.
Show child attributes
Show child attributes
open, completed, cancelled Person’s response, when supplied. Automatic completion may have no written response.
curl --request POST \
--url https://api.antigen.sh/v1/human-tasks \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
}
}
'import requests
url = "https://api.antigen.sh/v1/human-tasks"
payload = {
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
}
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
vulnerabilityId: 'vuln_123',
assignee: 'alex@example.com',
title: 'Review and merge the invoice fix',
description: 'Review the ownership check and merge the pull request once approved.',
completion: {type: 'pull_request_merged', url: 'https://github.com/acme/payments/pull/42'}
})
};
fetch('https://api.antigen.sh/v1/human-tasks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/human-tasks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'vulnerabilityId' => 'vuln_123',
'assignee' => 'alex@example.com',
'title' => 'Review and merge the invoice fix',
'description' => 'Review the ownership check and merge the pull request once approved.',
'completion' => [
'type' => 'pull_request_merged',
'url' => 'https://github.com/acme/payments/pull/42'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/human-tasks"
payload := strings.NewReader("{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/human-tasks")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/human-tasks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"vulnerabilityId\": \"vuln_123\",\n \"assignee\": \"alex@example.com\",\n \"title\": \"Review and merge the invoice fix\",\n \"description\": \"Review the ownership check and merge the pull request once approved.\",\n \"completion\": {\n \"type\": \"pull_request_merged\",\n \"url\": \"https://github.com/acme/payments/pull/42\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "task_123",
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
},
"status": "open",
"response": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}