Targets
Submit a target
Submits one domain, wildcard domain, or IP address for review. attested must be true to confirm your organization is authorized to test it. The Antigen team reviews every new target; a new submission has pending status. Duplicate values return 409.
POST
/
targets
Submit a target
curl --request POST \
--url https://api.antigen.sh/v1/targets \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"value": "api.example.com",
"attested": true
}
'import requests
url = "https://api.antigen.sh/v1/targets"
payload = {
"value": "api.example.com",
"attested": True
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({value: 'api.example.com', attested: true})
};
fetch('https://api.antigen.sh/v1/targets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/targets",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'value' => 'api.example.com',
'attested' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/targets"
payload := strings.NewReader("{\n \"value\": \"api.example.com\",\n \"attested\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/targets")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"value\": \"api.example.com\",\n \"attested\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/targets")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"value\": \"api.example.com\",\n \"attested\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "target_123",
"value": "api.example.com",
"status": "pending",
"reviewNote": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Body
application/json
Submit a target
curl --request POST \
--url https://api.antigen.sh/v1/targets \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"value": "api.example.com",
"attested": true
}
'import requests
url = "https://api.antigen.sh/v1/targets"
payload = {
"value": "api.example.com",
"attested": True
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({value: 'api.example.com', attested: true})
};
fetch('https://api.antigen.sh/v1/targets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/targets",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'value' => 'api.example.com',
'attested' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/targets"
payload := strings.NewReader("{\n \"value\": \"api.example.com\",\n \"attested\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.antigen.sh/v1/targets")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"value\": \"api.example.com\",\n \"attested\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/targets")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"value\": \"api.example.com\",\n \"attested\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "target_123",
"value": "api.example.com",
"status": "pending",
"reviewNote": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}