Runs
Resume a run
Restores a stopped run into a new sandbox and continues with the same ID, agent configuration, files, and conversation context. Target authorization is checked again before testing continues. Returns once the run is running.
This endpoint accepts no configuration overrides. To supply new context, steer the resumed run. To use a different agent configuration, start a new run. A run that is not stopped returns 409.
POST
/
runs
/
{id}
/
resume
Resume a run
curl --request POST \
--url https://api.antigen.sh/v1/runs/{id}/resume \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/runs/{id}/resume"
headers = {"x-api-key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/runs/{id}/resume', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/runs/{id}/resume",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/runs/{id}/resume"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/runs/{id}/resume")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/runs/{id}/resume")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "run_123",
"status": "running",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Path Parameters
Opaque resource identifier.
Minimum string length:
1Response
Successful response.
Minimum string length:
1Available options:
creating, running, stopped, completed, failed Show child attributes
Show child attributes
Example:
{ "base": "tcell", "model": "claude-opus-5-cyber", "skills": [ "Check authorization when one account requests another account’s resources." ], "guardrails": "Do not attempt denial of service.", "tools": ["asset_map", "human_tasks"] }
- Option 1
- Option 2
Show child attributes
Show child attributes
Example:
{ "instructions": "Test the production API for authorization vulnerabilities.", "targets": ["api.example.com"] }
Failure description when status is failed; otherwise null.
Resume a run
curl --request POST \
--url https://api.antigen.sh/v1/runs/{id}/resume \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/runs/{id}/resume"
headers = {"x-api-key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/runs/{id}/resume', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/runs/{id}/resume",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/runs/{id}/resume"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/runs/{id}/resume")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/runs/{id}/resume")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "run_123",
"status": "running",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}