Docs

Get an incident

GET /api/v1/incidents/{id}

One confirmed incident, by the id from List incidents. An incident of another team, or a suspicion that was never confirmed, returns 404.

Example

cURL

curl http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58 \
  -H "Authorization: Bearer $PULSEKEEPER_TOKEN"

PHP

<?php

// composer require guzzlehttp/guzzle
$client = new GuzzleHttp\Client([
    'base_uri' => 'http://pulsekeeper.io/api/v1/',
    'headers' => ['Authorization' => 'Bearer '.getenv('PULSEKEEPER_TOKEN')],
]);

$incident = json_decode($client->get('incidents/3f9a1c0e7b2d4a58')->getBody(), true)['data'];

JavaScript

const response = await fetch('http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58', {
  headers: { Authorization: `Bearer ${process.env.PULSEKEEPER_TOKEN}` },
});

const { data: incident } = await response.json();

Go

req, _ := http.NewRequest("GET", "http://pulsekeeper.io/api/v1/incidents/3f9a1c0e7b2d4a58", nil)
req.Header.Set("Authorization", "Bearer "+os.Getenv("PULSEKEEPER_TOKEN"))

res, err := http.DefaultClient.Do(req)
if err != nil {
	log.Fatal(err)
}
defer res.Body.Close()

var body struct {
	Data map[string]any `json:"data"`
}
json.NewDecoder(res.Body).Decode(&body)

Response

{
  "data": {
    "id": "3f9a1c0e7b2d4a58",
    "type": "downtime",
    "title": "Site unreachable",
    "severity": "critical",
    "state": "resolved",
    "monitor": { "id": "a81c27e05f3d9b64", "type": "http", "name": "HTTP", "target": "shop.example.com" },
    "client": { "id": "c4e0b9a17d2f6385", "name": "Example Shop" },
    "started_at": "2026-09-30T21:14:05Z",
    "confirmed_at": "2026-09-30T21:14:41Z",
    "acknowledged_at": null,
    "resolved_at": "2026-09-30T21:42:10Z",
    "duration_seconds": 1685,
    "excluded_from_sla": false,
    "affected_locations": ["fra", "lon"],
    "error": { "code": "http_5xx", "detail": "HTTP 502" },
    "cause": { "text": "Outage at the hosting provider", "in_report": true }
  }
}

Fields

Field Meaning
type What happened: downtime, timeout, blocked (a firewall blocks our checks), auth (the site asks for a password), ssl_expiring, ssl_invalid, domain_expiring, heartbeat_missed and others. title says the same in words.
severity critical (an outage), warning or info.
state confirmed, acknowledged (someone on your team took it), resolved or suppressed. Suppressed means it happened during a maintenance window: it is real, but it does not count against availability.
monitor The monitor it happened on. target is the hostname; null for heartbeats.
client The client the target belongs to; null for heartbeats.
started_at The first failed check.
confirmed_at When a second location confirmed it. Downtime counts from here.
resolved_at The first successful check after it; null while it lasts.
duration_seconds Set once resolved. For an open incident it is null: count from started_at to the moment you need.
excluded_from_sla true when it does not count against availability, for example during maintenance.
affected_locations The locations that saw the failure.
error The first error: a code such as http_5xx, timeout or dns_fail, and its detail.
cause What your team wrote under Add cause. With in_report: false it was marked as internal: leave it out of anything your client sees.