# Freeze an agent (machine)

Source: https://immiscible.fly.dev/docs/api/post-v1-admin-agents-aid-freeze

`POST /v1/admin/agents/:aid/freeze`

`agents:freeze`. Always at least a security hold. Past a freeze ceiling the answer is `202` with a pending freeze for a person.

## Authentication

Service token. A scoped machine token (`ims_...`) made by an owner or admin under Settings, sent as `Authorization: Bearer`. Each route needs one scope; tokens expire within 90 days and can be pinned to address ranges. A token can stop agents but never start them, and never decides an approval.

## Path parameters

- `aid` (string, required): Agent id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/v1/admin/agents/agt_4f2c91a7/freeze" \
  -H "authorization: Bearer $IMMISCIBLE_SERVICE_TOKEN" \
  -H "content-type: application/json" \
  -d '{
    "reason": "Splunk SOAR: exfiltration rule 12",
    "hold": "incident"
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/v1/admin/agents/agt_4f2c91a7/freeze', {
  method: 'POST',
  headers: {
    authorization: `Bearer ${process.env.IMMISCIBLE_SERVICE_TOKEN}`,
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    reason: 'Splunk SOAR: exfiltration rule 12',
    hold: 'incident',
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.post(
    "https://immiscible.fly.dev/v1/admin/agents/agt_4f2c91a7/freeze",
    headers={
        "authorization": f"Bearer {os.environ['IMMISCIBLE_SERVICE_TOKEN']}",
        "content-type": "application/json",
    },
    json={
        "reason": "Splunk SOAR: exfiltration rule 12",
        "hold": "incident",
    },
)
print(res.status_code, res.json())
```
