> ## Documentation Index
> Fetch the complete documentation index at: https://docs.antigen.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Stop a run

> Snapshots the sandbox and shuts it down. Returns when the snapshot is saved and the run is stopped. Saved vulnerabilities and evidence remain available. Stopping an already stopped run returns that run; completed or failed runs return 409.



## OpenAPI

````yaml /reference/openapi.yaml post /runs/{id}/stop
openapi: 3.1.0
info:
  title: Antigen API
  version: v1
  description: >-
    Work with the same agents, runs, and resources your team uses in Antigen.
    Requests and responses use camelCase fields. List endpoints return arrays.
    See the [overview](/reference) for authentication, updates, and errors.
servers:
  - url: https://api.antigen.sh/v1
security:
  - ApiKeyAuth: []
tags:
  - name: Agents
    description: Retrieve, compose, and register agent configurations.
  - name: Models
    description: Models available to agents in your organization.
  - name: Targets
    description: Submit testing scope for human approval.
  - name: Runs
    description: Execute agents and control their work.
  - name: Vulnerabilities
    description: Track weaknesses, remediation, status, and assignment.
  - name: Evidence
    description: Read supporting file metadata and retrieve file contents.
  - name: Reports
    description: Read and export captured engagement results.
  - name: Human tasks
    description: Ask people for help and follow their responses.
  - name: Hooks
    description: Connect status and assignment changes to your own service.
  - name: Asset Map
    description: Read your organization’s infrastructure graph.
  - name: Integrations
    description: Inspect and disconnect provider connections.
  - name: API keys
    description: Create and revoke credentials for automation.
paths:
  /runs/{id}/stop:
    post:
      tags:
        - Runs
      summary: Stop a run
      description: >-
        Snapshots the sandbox and shuts it down. Returns when the snapshot is
        saved and the run is stopped. Saved vulnerabilities and evidence remain
        available. Stopping an already stopped run returns that run; completed
        or failed runs return 409.
      operationId: stopRun
      parameters:
        - name: id
          in: path
          required: true
          description: Opaque resource identifier.
          schema:
            type: string
            minLength: 1
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Run'
              example:
                id: run_123
                status: stopped
                agent:
                  base: tcell
                  model: claude-opus-5-cyber
                  skills:
                    - >-
                      Check authorization when one account requests another
                      account’s resources.
                  guardrails: Do not attempt denial of service.
                  tools:
                    - asset_map
                    - human_tasks
                task:
                  instructions: Test the production API for authorization vulnerabilities.
                  targets:
                    - api.example.com
                createdAt: '2026-09-13T10:00:00.000Z'
                updatedAt: '2026-09-13T10:00:00.000Z'
                error: null
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '409':
          $ref: '#/components/responses/Error409'
        '429':
          $ref: '#/components/responses/Error429'
components:
  schemas:
    Run:
      type: object
      properties:
        id:
          type: string
          minLength: 1
        status:
          type: string
          enum:
            - creating
            - running
            - stopped
            - completed
            - failed
        agent:
          $ref: '#/components/schemas/AgentConfiguration'
        task:
          $ref: '#/components/schemas/Task'
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
        error:
          type:
            - string
            - 'null'
          description: Failure description when status is failed; otherwise null.
      required:
        - id
        - status
        - agent
        - task
        - createdAt
        - updatedAt
        - error
      additionalProperties: false
      example:
        id: run_123
        status: running
        agent:
          base: tcell
          model: claude-opus-5-cyber
          skills:
            - >-
              Check authorization when one account requests another account’s
              resources.
          guardrails: Do not attempt denial of service.
          tools:
            - asset_map
            - human_tasks
        task:
          instructions: Test the production API for authorization vulnerabilities.
          targets:
            - api.example.com
        createdAt: '2026-09-13T10:00:00.000Z'
        updatedAt: '2026-09-13T10:00:00.000Z'
        error: null
    AgentConfiguration:
      type: object
      properties:
        base:
          type:
            - string
            - 'null'
          enum:
            - tcell
            - triage-agent
            - remediation-agent
            - null
          description: >-
            Underlying pre-built agent. Its private instructions remain managed
            by Antigen. Use null to assemble an agent without a pre-built base.
        model:
          type: string
          description: Model ID from GET /models.
          minLength: 1
        skills:
          type: array
          items:
            type: string
          description: Instruction strings. Send file contents, not file paths.
        guardrails:
          type: string
          description: Natural-language constraints on agent behavior.
        tools:
          type: array
          items:
            type: string
          description: >-
            Names of tools available to the agent, such as asset_map and
            human_tasks.
      required:
        - base
        - model
        - skills
        - guardrails
        - tools
      additionalProperties: false
      example:
        base: tcell
        model: claude-opus-5-cyber
        skills:
          - >-
            Check authorization when one account requests another account’s
            resources.
        guardrails: Do not attempt denial of service.
        tools:
          - asset_map
          - human_tasks
    Task:
      type: object
      properties:
        instructions:
          type: string
          description: Work the agent should perform during this run.
          minLength: 1
        targets:
          type: array
          items:
            type: string
          description: Target values within your organization’s approved scope.
        vulnerabilityIds:
          type: array
          items:
            type: string
            minLength: 1
          description: >-
            Existing vulnerabilities in your organization. The API retrieves
            their current context.
      required:
        - instructions
      additionalProperties: false
      anyOf:
        - required:
            - targets
          properties:
            targets:
              minItems: 1
        - required:
            - vulnerabilityIds
          properties:
            vulnerabilityIds:
              minItems: 1
      example:
        instructions: Test the production API for authorization vulnerabilities.
        targets:
          - api.example.com
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable error code.
            message:
              type: string
              description: Description of the problem.
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      example:
        error:
          code: invalid_request
          message: The target value is required.
  responses:
    Error401:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: unauthorized
              message: Supply a valid API key.
    Error403:
      description: Permission denied
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: forbidden
              message: The API key does not permit this operation or requested scope.
    Error404:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: not_found
              message: The resource does not exist in this organization.
    Error409:
      description: Conflict
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: conflict
              message: The resource’s current state does not allow this operation.
    Error429:
      description: Too many requests
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: rate_limited
              message: Retry after the interval in Retry-After.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 1
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        API key from your organization. Supply the value directly, without a
        Bearer prefix.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.