Skip to main content
Hooks send an HTTP request to a configured URL when a vulnerability’s status or assignment changes. These requests are webhooks. Your service receives the event and decides what to do with it. You can use hooks to send notifications, launch agents, or connect vulnerabilities to your existing workflows.

Status changes

A status-change event includes the vulnerability’s previous status and its new status. When an agent creates a vulnerability, it starts in Open with no previous status. Later, verification might return an unresolved vulnerability from Remediated to Open. Your service can check these values to decide how to respond. For example, it could notify your security team whenever a vulnerability returns to Open.

Assignment changes

An assignment-change event includes the previous assignee and the new assignee. Either can be empty when a vulnerability is first assigned or becomes unassigned. Your service can use this event to notify the assignee, create a task in another system, or start work automatically.

Default hooks

Antigen comes with hooks configured for triage, remediation, and verification:
  • Entering Open starts Antigen’s pre-built triage-agent.
  • Assignment to Antigen’s pre-built remediation-agent starts remediation.
  • Entering Remediated starts a verification run.
You can turn these hooks on or off in the platform or via the API. See the lifecycle overview for how the default setup works.

Add your own webhooks

You can also register webhooks through the SDK or API to receive status and assignment changes at your own URL. Your service decides how to respond, whether that means sending a notification, launching an agent, or starting another workflow. Keep the default hooks enabled to run your automation alongside them, or disable them to handle the work yourself.