# Continue editing a source-backed workspace

Submit a follow-up prompt to the same workspace. An expired sandbox is recreated from its durable source before execution. Failed runs do not replace the last completed result source.

`POST /api/platform/v1/apps/{appId}/threads/{threadId}/messages`

Required permission: `thread:update`.

## Parameters

| Name | In | Type | Required | Description |

| --- | --- | --- | --- | --- |

| `appId` | path | `string` | Yes | — |

| `threadId` | path | `string` | Yes | — |

| `Idempotency-Key` | header | `string` | No | Required for service credentials. Retry the same request with the same key. |

## Request body

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `content` | `string` | Yes | min length 1, max length 100000 | — |
| `clientMessageId` | `string` | No | min length 1, max length 128 | — |

```json
{
  "content": "Add a contact page"
}
```

## Example request

```bash
curl --request POST \
  --url https://api.hoplite.sh/api/platform/v1/apps/appId/threads/threadId/messages \
  --header "X-Api-Key: $HOPLITE_API_KEY" \
  --header "Idempotency-Key: $HOPLITE_OPERATION_ID" \
  --header 'Content-Type: application/json' \
  --data '{
  "content": "Add a contact page"
}'
```

## 201 response

Success

Content type: `application/json`. Response type: `object`.

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `ok` | `boolean` | Yes | true | — |
| `message` | `object` | Yes | — | — |
| `message.id` | `string` | Yes | — | — |
| `message.threadId` | `string` | Yes | — | — |
| `message.role` | `string` | Yes | — | — |
| `message.content` | `string` | Yes | — | — |
| `message.[key]` | `object` | No | — | — |
| `run` | `object` | No | — | — |
| `run.id` | `string` | Yes | — | — |
| `run.status` | `string` | Yes | — | — |
| `run.[key]` | `object` | No | — | — |
| `idempotent` | `boolean` | No | — | — |

```json

```

## Status codes

- `201` — Success

- `400` — Invalid request

- `401` — Authentication required

- `403` — Permission, app scope or entitlement denied

- `404` — App, source or thread not found

- `409` — Idempotency conflict or request in progress

- `413` — Request too large

- `503` — Source storage or execution unavailable