Docs
Get an incident
GET /api/v1/incidents/{id}
One confirmed incident, by the id from List incidents. An incident of another team, or a suspicion that was never confirmed, returns 404.
Example
cURL
curl http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58 \
-H "Authorization: Bearer $PULSEKEEPER_TOKEN"
PHP
<?php
// composer require guzzlehttp/guzzle
$client = new GuzzleHttp\Client([
'base_uri' => 'http://pulsekeeper.io/api/v1/',
'headers' => ['Authorization' => 'Bearer '.getenv('PULSEKEEPER_TOKEN')],
]);
$incident = json_decode($client->get('incidents/3f9a1c0e7b2d4a58')->getBody(), true)['data'];
JavaScript
const response = await fetch('http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58', {
headers: { Authorization: `Bearer ${process.env.PULSEKEEPER_TOKEN}` },
});
const { data: incident } = await response.json();
Go
req, _ := http.NewRequest("GET", "http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58", nil)
req.Header.Set("Authorization", "Bearer "+os.Getenv("PULSEKEEPER_TOKEN"))
res, err := http.DefaultClient.Do(req)
if err != nil {
log.Fatal(err)
}
defer res.Body.Close()
var body struct {
Data map[string]any `json:"data"`
}
json.NewDecoder(res.Body).Decode(&body)
Response
{
"data": {
"id": "3f9a1c0e7b2d4a58",
"type": "downtime",
"title": "Site unreachable",
"severity": "critical",
"state": "resolved",
"monitor": { "id": "a81c27e05f3d9b64", "type": "http", "name": "HTTP", "target": "shop.example.com" },
"client": { "id": "c4e0b9a17d2f6385", "name": "Example Shop" },
"started_at": "2026-09-30T21:14:05Z",
"confirmed_at": "2026-09-30T21:14:41Z",
"acknowledged_at": null,
"resolved_at": "2026-09-30T21:42:10Z",
"duration_seconds": 1685,
"excluded_from_sla": false,
"affected_locations": ["fra", "lon"],
"error": { "code": "http_5xx", "detail": "HTTP 502" },
"cause": { "text": "Outage at the hosting provider", "in_report": true }
}
}
Fields
| Field | Meaning |
|---|---|
type |
What happened: downtime, timeout, blocked (a firewall blocks our checks), auth (the site asks for a password), ssl_expiring, ssl_invalid, domain_expiring, heartbeat_missed and others. title says the same in words. |
severity |
critical (an outage), warning or info. |
state |
confirmed, acknowledged (someone on your team took it), resolved or suppressed. Suppressed means it happened during a maintenance window: it is real, but it does not count against availability. |
monitor |
The monitor it happened on. target is the hostname; null for heartbeats. |
client |
The client the target belongs to; null for heartbeats. |
started_at |
The first failed check. |
confirmed_at |
When a second location confirmed it. Downtime counts from here. |
resolved_at |
The first successful check after it; null while it lasts. |
duration_seconds |
Set once resolved. For an open incident it is null: count from started_at to the moment you need. |
excluded_from_sla |
true when it does not count against availability, for example during maintenance. |
affected_locations |
The locations that saw the failure. |
error |
The first error: a code such as http_5xx, timeout or dns_fail, and its detail. |
cause |
What your team wrote under Add cause. With in_report: false it was marked as internal: leave it out of anything your client sees. |