Update a human task
Updates supplied fields and reflects the change in connected tools. Reassign a task by email, revise its instructions, or update status. Supply response when confirming work through your service. Set cancelled when the request is no longer needed.
External agents use the task’s status and response to decide when to continue. A completed access request tells the agent to retry the operation that required access.
curl --request PATCH \
--url https://api.antigen.sh/v1/human-tasks/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"status": "completed",
"response": "The repository is connected with access to the source code."
}
'import requests
url = "https://api.antigen.sh/v1/human-tasks/{id}"
payload = {
"status": "completed",
"response": "The repository is connected with access to the source code."
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
status: 'completed',
response: 'The repository is connected with access to the source code.'
})
};
fetch('https://api.antigen.sh/v1/human-tasks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/human-tasks/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'status' => 'completed',
'response' => 'The repository is connected with access to the source code.'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/human-tasks/{id}"
payload := strings.NewReader("{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.antigen.sh/v1/human-tasks/{id}")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/human-tasks/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}"
response = http.request(request)
puts response.read_body{
"id": "task_123",
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
},
"status": "open",
"response": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Path Parameters
Opaque resource identifier.
1Body
Email of the responsible person in your organization.
Action the person needs to take.
1What is needed, why, and how to confirm completion.
1Optional condition confirmed through a connected integration.
Show child attributes
Show child attributes
open, completed, cancelled Response or confirmation to retain with the task.
Response
Successful response.
1Vulnerability this request relates to.
1Email of the responsible person in your organization.
Action the person needs to take.
1What is needed, why, and how to confirm completion.
1Optional condition confirmed through a connected integration.
Show child attributes
Show child attributes
open, completed, cancelled Person’s response, when supplied. Automatic completion may have no written response.
curl --request PATCH \
--url https://api.antigen.sh/v1/human-tasks/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"status": "completed",
"response": "The repository is connected with access to the source code."
}
'import requests
url = "https://api.antigen.sh/v1/human-tasks/{id}"
payload = {
"status": "completed",
"response": "The repository is connected with access to the source code."
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
status: 'completed',
response: 'The repository is connected with access to the source code.'
})
};
fetch('https://api.antigen.sh/v1/human-tasks/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/human-tasks/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'status' => 'completed',
'response' => 'The repository is connected with access to the source code.'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/human-tasks/{id}"
payload := strings.NewReader("{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.antigen.sh/v1/human-tasks/{id}")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/human-tasks/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"status\": \"completed\",\n \"response\": \"The repository is connected with access to the source code.\"\n}"
response = http.request(request)
puts response.read_body{
"id": "task_123",
"vulnerabilityId": "vuln_123",
"assignee": "alex@example.com",
"title": "Review and merge the invoice fix",
"description": "Review the ownership check and merge the pull request once approved.",
"completion": {
"type": "pull_request_merged",
"url": "https://github.com/acme/payments/pull/42"
},
"status": "open",
"response": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "conflict",
"message": "The resource’s current state does not allow this operation."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}