Skip to main content
The Antigen SDK gives you access to the Antigen API from TypeScript. Use it to:
  • Query your organization’s Asset Map.
  • Create and manage team workflows.
  • Assemble agents and control their runs.
  • Work with targets, vulnerabilities, and evidence.
Your code works with the same resources your team sees in the platform.

Install the SDK

Set ANTIGEN_API_KEY in your environment. See Authentication for creating and using API keys. Python support is planned. Python applications can use the Antigen API directly.

Run an agent

To start a run, retrieve an agent or construct one locally. This example uses tCell to test your approved targets and collect the vulnerabilities it discovers.
antigen.agents.get(tCell) retrieves tCell’s configuration. Calling agent.run() with a task starts testing in a sandbox and returns a Run object. run.wait() waits for completion, and run.vulnerabilities.list() retrieves the vulnerabilities discovered during the run. You can run the same agent again against different approved targets. Each invocation creates a separate run with its own progress and results. See Targets for submitting targets, updating them, and checking their approval status.

Customize an agent

tCell, triage-agent, and remediation-agent are pre-built agents developed with the same SDK. You can retrieve them using the exported tCell, triageAgent, and remediationAgent constants. An agent’s configuration determines its model, skills, guardrails, and tools. You can customize an existing agent by replacing configuration fields or adding to them. This example keeps tCell’s configuration and appends a skill describing your application’s authentication:
Constructing an agent locally creates a configuration you can use to start runs. Registering it saves that configuration in Antigen under a name, so your team can retrieve and reuse it without defining it again. Registered agents also appear in the platform’s assignment dropdown. Your team can assign a vulnerability to an agent, and your webhook handler can launch it to investigate or prepare a fix. See Assigning to your own agents for setting up this workflow. See Agents for composition and registration, Models for model selection, and Skills and Guardrails for configuring instructions and constraints.

Control a run

A run continues in its sandbox if your script exits or disconnects. While it runs, you can stream progress events or send messages to adjust the agent’s focus. You can also stop a run and resume it later. Runs can test targets, investigate vulnerabilities, or prepare fixes, depending on the agent you launch. See Runs, Steering, and Stopping and resuming.

Work with results

Use the SDK to read vulnerabilities, update their status and assignment, and retrieve their supporting evidence. These updates appear in the platform, where your team can review and act on them. Status and assignment changes can trigger hooks. For example, when a vulnerability is assigned to your registered agent, your handler can retrieve the agent and start a run with that vulnerability. See Pentest after a deployment for a complete example that runs tCell from CI after a production deployment.