Skip to main content
POST
Run a gamebook

Path Parameters

workspaceId
string<uuid>
required

Body

application/json

Public v2 inputs for a new gamebook submission, without portal approval or executor state.

incidentId
string
required

Incident identifier in the authorized route workspace.

incidentTitle
string
required

Required non-empty incident display title.

source
enum<string>
required

Detection source of the incident.

Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne,
SumoLogic
playbooks
object[]
required

Actions with unique, contiguous sequence values from 1 through the number of actions.

incidentNumber

Optional incident display number.

isQueued
boolean

Requests human approval. False never overrides server-side approval requirements.

Response

OK

Standard v2 API response envelope for single-item responses.

data
object

Public result of submitting a gamebook, without workspace or incident target details.

meta
object
Last modified on October 8, 2026