Runs
Stop a run
Snapshots the sandbox and shuts it down. Returns when the snapshot is saved and the run is stopped. Saved vulnerabilities and evidence remain available. Stopping an already stopped run returns that run; completed or failed runs return 409.
POST
/
runs
/
{id}
/
stop
Stop a run
curl --request POST \
--url https://api.antigen.sh/v1/runs/{id}/stop \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/runs/{id}/stop"
headers = {"x-api-key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/runs/{id}/stop', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/runs/{id}/stop",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/runs/{id}/stop"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/runs/{id}/stop")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/runs/{id}/stop")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "run_123",
"status": "stopped",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Path Parameters
Opaque resource identifier.
Minimum string length:
1Response
Successful response.
Minimum string length:
1Available options:
creating, running, stopped, completed, failed Show child attributes
Show child attributes
Example:
{ "base": "tcell", "model": "claude-opus-5-cyber", "skills": [ "Check authorization when one account requests another account’s resources." ], "guardrails": "Do not attempt denial of service.", "tools": ["asset_map", "human_tasks"] }
- Option 1
- Option 2
Show child attributes
Show child attributes
Example:
{ "instructions": "Test the production API for authorization vulnerabilities.", "targets": ["api.example.com"] }
Failure description when status is failed; otherwise null.
Stop a run
curl --request POST \
--url https://api.antigen.sh/v1/runs/{id}/stop \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/runs/{id}/stop"
headers = {"x-api-key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/runs/{id}/stop', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/runs/{id}/stop",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/runs/{id}/stop"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/runs/{id}/stop")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/runs/{id}/stop")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "run_123",
"status": "stopped",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}