> ## Documentation Index
> Fetch the complete documentation index at: https://docs.incident.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create

> Share an update against an incident.

An update can carry a message, move the incident to a new status, change its severity,
or any combination of the three. At least one of them must be provided.

Which permissions you need depends on what the update does: changing status requires
permission to update an incident's status, and changing severity permission to update
its severity.


🔑 Requires the `incident_updates.create` scope.


## OpenAPI

````yaml /openapi/tags/incident-updates-v2.json post /v2/incident_updates
openapi: 3.0.3
info:
  description: "This is the API reference for incident.io.\n\nIt documents available API endpoints, provides examples of how to use it, and\ninstructions around things like authentication and error handling.\n\nThe API is hosted at:\n\n- https://api.incident.io/\n\nAnd you will need to create an API key via your [incident.io\ndashboard](https://app.incident.io/settings/api-keys) to make requests.\n\n# Making requests\n\nHere are the key concepts required to make requests to the incident.io API.\n\n## Authentication\n\nFor all requests made to the incident.io API, you'll need an API key.\n\nTo create an API key, head to the incident dashboard and visit [API\nkeys](https://app.incident.io/settings/api-keys). When you create the key, you'll be able to choose what actions it\ncan take for your account: choose carefully, as those roles can only be set\nwhen you first create the key. We'll only show you the token once, so make sure\nyou store it somewhere safe.\n\nAPI keys are global to your incident.io account, and can be managed by anyone\nwho has the right permissions. We display the user that created the API key,\nand the API key will remain valid if that user becomes deactivated.\n\nOnce you have the key, you should make requests to the API that set the\n`Authorization` request header using a \"Bearer\" authentication scheme:\n\n```\nAuthorization: Bearer <YOUR_API_KEY>\n```\n\n## Rate Limits\n\nThe incident.io API enforces rate limits to ensure consistent performance for all users.\n\nThe default rate limit is 1200 requests/minute per API key. This limit applies to most endpoints across the API.\n\nLimits are token buckets that refill continuously rather than resetting on a fixed window boundary. The default\nbucket holds 1200 requests and refills at 20 per second, so you can burst up to the full bucket and then sustain\n20 requests/second indefinitely. There is no boundary at which your quota resets to full in one step.\n\nSome endpoints have lower rate limits, particularly those that interact with external third-party systems that impose\ntheir own limitations. These specific limits vary by endpoint.\n\n### Rate limit headers\n\nResponses to requests authenticated with an API key carry your current allowance, so you can pace yourself rather\nthan waiting to be throttled:\n\n```\nX-RateLimit-Limit: 60, 1200;window=60, 60;window=60\nX-RateLimit-Remaining: 59\nX-RateLimit-Used: 1\nX-RateLimit-Reset: 1785173199\n```\n\n| Header | Meaning |\n| --- | --- |\n| `X-RateLimit-Limit` | The quota that binds this request, followed by every limit that applied and the window it applies over |\n| `X-RateLimit-Remaining` | Requests you can make right now against the binding limit |\n| `X-RateLimit-Used` | Requests you have spent against it |\n| `X-RateLimit-Reset` | Unix timestamp (seconds) at which that limit will be back to full |\n\nMore than one limit can apply to a request: your API key's overall limit, and for some endpoints a lower limit of\ntheir own. `X-RateLimit-Limit` lists all of them, each with its window, so `1200;window=60` means 1200 requests per\nminute. Because our limits refill continuously rather than resetting on a boundary, that window is what tells you\nthe rate you can sustain: 1200 per 60 seconds is 20 requests/second indefinitely.\n\n`Remaining`, `Used` and `Reset` describe whichever limit has the least allowance left, since that is the one you\nwill hit first.\n\n`X-RateLimit-Remaining` may lag by a small number of requests under high concurrency, and can move by more than the\nrequests you made, because limits scoped to your whole organisation are shared with your other API keys.\n\nHeaders are omitted rather than guessed if we cannot determine your allowance for a request.\n\n### Exceeding a rate limit\n\nWhen you exceed a rate limit the API responds with `429 Too Many Requests` and a `Retry-After` header giving the\nnumber of seconds to wait:\n\n```\nX-RateLimit-Limit: 1200, 1200;window=60\nX-RateLimit-Remaining: 0\nX-RateLimit-Used: 1200\nX-RateLimit-Reset: 1785173199\nRetry-After: 1\n```\n\nPrefer `Retry-After` over `X-RateLimit-Reset` when deciding how long to back off. `Retry-After` is when a single\nrequest will succeed; `X-RateLimit-Reset` is the later point at which your whole allowance has returned. It is a\nduration rather than a timestamp, so it does not depend on your clock agreeing with ours.\n\nThe 429 also carries a JSON body with the same information:\n\n```json\n{\n    \"type\": \"too_many_requests\",\n    \"status\": 429,\n    \"request_id\": \"b839a403-7704-41c1-bf6a-39a2d68caefa\",\n    \"rate_limit\": {\n        \"name\": \"api_key_name\",\n        \"limit\": 1200,\n        \"remaining\": 0,\n        \"retry_after\": \"2025-04-17T11:17:18Z\"\n    },\n    \"errors\": [\n        {\n            \"code\": \"too_many_requests\",\n            \"message\": \"Too many requests hit the API too quickly. We recommend an exponential backoff of your requests.\"\n        }\n    ]\n}\n```\n\nThe response includes:\n* The name of the API key (`name`)\n* The bucket limit (`limit`)\n* The number of requests remaining (`remaining`)\n* When you can retry requests (`retry_after`), as an RFC3339 timestamp\n\n## Errors\n\nWe use standard HTTP response codes to indicate the status or failure of API\nrequests.\n\nThe API response body will be JSON, and contain more detailed information on the\nnature of the error.\n\nAn example error when a request is made without an API key:\n\n```json\n{\n  \"type\": \"authentication_error\",\n  \"status\": 401,\n  \"request_id\": \"8e3cc412-b49d-4957-9073-2c19d2c61804\",\n  \"errors\": [\n    {\n      \"code\": \"missing_authorization_material\",\n      \"message\": \"No authorization material provided in request\"\n    }\n  ]\n}\n```\n\nNote that the error:\n\n- Contains the HTTP status (`401`)\n- References the type of error (`authentication_error`)\n- Includes a `request_id` that can be provided to incident.io support to help\n\tdebug questions with your API request\n- Provides a list of individual errors, which go into detail about why the error\n\toccurred\n\nThe most common error will be a 422 Validation Error, which is returned when the\nrequest was rejected due to failing validations.\n\nThese errors look like this:\n\n```json\n{\n  \"type\": \"validation_error\",\n  \"status\": 422,\n  \"request_id\": \"631766c4-4afd-4803-997c-cd700928fa4b\",\n  \"errors\": [\n    {\n      \"code\": \"is_required\",\n      \"message\": \"A severity is required to open an incident\",\n      \"source\": {\n        \"field\": \"severity_id\"\n      }\n    }\n  ]\n}\n```\n\nThis error is caused by not providing a severity identifier, which should be at\nthe `severity_id` field of the request payload. Errors like these can be mapped to\nforms, should you be integrating with the API from a user-interface.\n\n## Compatibility\n\nWe won't make breaking changes to existing API services or endpoints, but will\nexpect integrators to upgrade themselves to the latest API endpoints within 3\nmonths of us deprecating the old service.\n\nWe will make changes that are considered backwards compatible, which include:\n\n- Adding new API endpoints and services\n- Adding new properties to responses from existing API endpoints\n- Reordering properties returned from existing API endpoints\n- Adding optional request parameters to existing API endpoints\n- Altering the format or length of IDs\n- Adding new values to enums\n\nIt is important that clients are robust to these changes, to ensure reliable\nintegrations.\n\nAs an example, if you are generating a client using an openapi-generator, ensure\nthe generated client is configured to support unknown enum values, often\nconfigured via the `enumUnknownDefaultCase` parameter.\n\nWhen breaking changes are unavoidable, we'll create a new service version on a\nseparate path, and run them in parallel.\n\nFor example:\n\n- https://api.incident.io/v1/incidents\n- https://api.incident.io/v2/incidents\n\nFor any questions, email support@incident.io.\n"
  title: incident.io
  version: 1.0.0
servers:
  - url: https://api.incident.io
security:
  - BearerAuth: []
tags:
  - description: >
      List and create incident updates.


      Incident Updates allows you to see all the updates that have been shared
      against a

      particular incident. This will include any time that the Severity or
      Status of

      an incident changed, alongside any additional updates that were provided.
    name: Incident Updates V2
paths:
  /v2/incident_updates:
    post:
      tags:
        - Incident Updates V2
      summary: Create
      description: >
        Share an update against an incident.


        An update can carry a message, move the incident to a new status, change
        its severity,

        or any combination of the three. At least one of them must be provided.


        Which permissions you need depends on what the update does: changing
        status requires

        permission to update an incident's status, and changing severity
        permission to update

        its severity.
      operationId: Incident Updates V2_Create
      requestBody:
        content:
          application/json:
            example:
              idempotency_key: alert-uuid
              incident_id: 01G0J1EXE7AXZ2C93K61WBPYEH
              message: We're working on a fix, hoping to ship in the next 30 minutes
              to_incident_status_id: 01G0J1EXE7AXZ2C93K61WBPYEH
              to_severity_id: 01FH5TZRWMNAFB0DZ23FD1TV96
            schema:
              $ref: '#/components/schemas/IncidentUpdatesCreatePayloadV2'
        required: true
      responses:
        '201':
          content:
            application/json:
              example:
                incident_update:
                  created_at: '2021-08-17T13:28:57.801578Z'
                  id: 01FCNDV6P870EA6S7TK1DSYDG0
                  incident_id: 01FCNDV6P870EA6S7TK1DSYDG0
                  merged_into_incident_id: 01FCNDV6P870EA6S7TK1DSYDG0
                  message: >-
                    We're working on a fix, hoping to ship in the next 30
                    minutes
                  new_incident_status:
                    category: triage
                    created_at: '2021-08-17T13:28:57.801578Z'
                    description: >-
                      Impact has been **fully mitigated**, and we're ready to
                      learn from this incident.
                    id: 01FCNDV6P870EA6S7TK1DSYD5H
                    name: Closed
                    rank: 4
                    updated_at: '2021-08-17T13:28:57.801578Z'
                  new_severity:
                    created_at: '2021-08-17T13:28:57.801578Z'
                    description: Issues with **low impact**.
                    id: 01FCNDV6P870EA6S7TK1DSYDG0
                    name: Minor
                    rank: 1
                    updated_at: '2021-08-17T13:28:57.801578Z'
                  updater:
                    alert:
                      id: 01GW2G3V0S59R238FAHPDS1R66
                      title: '*errors.withMessage: PG::Error failed to connect'
                    api_key:
                      id: 01FCNDV6P870EA6S7TK1DSYDG0
                      name: My test API key
                    user:
                      email: lisa@incident.io
                      id: 01FCNDV6P870EA6S7TK1DSYDG0
                      name: Lisa Karlin Curtis
                      role: owner
                      slack_user_id: U02AYNF2XJM
                    workflow:
                      id: 01FCNDV6P870EA6S7TK1DSYDG0
                      name: My little workflow
              schema:
                $ref: '#/components/schemas/IncidentUpdatesCreateResultV2'
          description: Created response.
components:
  schemas:
    IncidentUpdatesCreatePayloadV2:
      example:
        idempotency_key: alert-uuid
        incident_id: 01G0J1EXE7AXZ2C93K61WBPYEH
        message: We're working on a fix, hoping to ship in the next 30 minutes
        to_incident_status_id: 01G0J1EXE7AXZ2C93K61WBPYEH
        to_severity_id: 01FH5TZRWMNAFB0DZ23FD1TV96
      properties:
        idempotency_key:
          description: >-
            Unique string used to de-duplicate incident update requests.
            Retrying with the same key returns the update the first request
            created, rather than sharing a second one.
          example: alert-uuid
          type: string
        incident_id:
          description: The incident you want to update
          example: 01G0J1EXE7AXZ2C93K61WBPYEH
          type: string
        message:
          description: Message that explains the context behind the update, in markdown
          example: We're working on a fix, hoping to ship in the next 30 minutes
          type: string
        to_incident_status_id:
          description: Move the incident to this status
          example: 01G0J1EXE7AXZ2C93K61WBPYEH
          type: string
        to_severity_id:
          description: Move the incident to this severity
          example: 01FH5TZRWMNAFB0DZ23FD1TV96
          type: string
      required:
        - incident_id
        - idempotency_key
      type: object
    IncidentUpdatesCreateResultV2:
      example:
        incident_update:
          created_at: '2021-08-17T13:28:57.801578Z'
          id: 01FCNDV6P870EA6S7TK1DSYDG0
          incident_id: 01FCNDV6P870EA6S7TK1DSYDG0
          merged_into_incident_id: 01FCNDV6P870EA6S7TK1DSYDG0
          message: We're working on a fix, hoping to ship in the next 30 minutes
          new_incident_status:
            category: triage
            created_at: '2021-08-17T13:28:57.801578Z'
            description: >-
              Impact has been **fully mitigated**, and we're ready to learn from
              this incident.
            id: 01FCNDV6P870EA6S7TK1DSYD5H
            name: Closed
            rank: 4
            updated_at: '2021-08-17T13:28:57.801578Z'
          new_severity:
            created_at: '2021-08-17T13:28:57.801578Z'
            description: Issues with **low impact**.
            id: 01FCNDV6P870EA6S7TK1DSYDG0
            name: Minor
            rank: 1
            updated_at: '2021-08-17T13:28:57.801578Z'
          updater:
            alert:
              id: 01GW2G3V0S59R238FAHPDS1R66
              title: '*errors.withMessage: PG::Error failed to connect'
            api_key:
              id: 01FCNDV6P870EA6S7TK1DSYDG0
              name: My test API key
            user:
              email: lisa@incident.io
              id: 01FCNDV6P870EA6S7TK1DSYDG0
              name: Lisa Karlin Curtis
              role: owner
              slack_user_id: U02AYNF2XJM
            workflow:
              id: 01FCNDV6P870EA6S7TK1DSYDG0
              name: My little workflow
      properties:
        incident_update:
          $ref: '#/components/schemas/IncidentUpdateV2'
      required:
        - incident_update
      type: object
    IncidentUpdateV2:
      properties:
        created_at:
          description: When the update was created
          example: '2021-08-17T13:28:57.801578Z'
          format: date-time
          type: string
        id:
          description: Unique identifier for this incident update
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        incident_id:
          description: The incident this update relates to
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        merged_into_incident_id:
          description: >-
            The ID of the incident this incident was merged into, if the to
            state of this update is 'merged'.
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        message:
          description: Message that explains the context behind the update
          example: We're working on a fix, hoping to ship in the next 30 minutes
          type: string
        new_incident_status:
          $ref: '#/components/schemas/IncidentStatusV2'
        new_severity:
          $ref: '#/components/schemas/SeverityV2'
        updater:
          $ref: '#/components/schemas/ActorV2'
      required:
        - id
        - incident_id
        - new_incident_status
        - updater
        - created_at
      type: object
    IncidentStatusV2:
      example:
        category: triage
        created_at: '2021-08-17T13:28:57.801578Z'
        description: >-
          Impact has been **fully mitigated**, and we're ready to learn from
          this incident.
        id: 01FCNDV6P870EA6S7TK1DSYD5H
        name: Closed
        rank: 4
        updated_at: '2021-08-17T13:28:57.801578Z'
      properties:
        category:
          description: >-
            What category of status it is. All statuses apart from live (renamed
            in the app to Active) and learning (renamed in the app to
            Post-incident) are managed by incident.io and cannot be configured
          enum:
            - triage
            - declined
            - merged
            - canceled
            - live
            - learning
            - closed
            - paused
          example: triage
          type: string
        created_at:
          example: '2021-08-17T13:28:57.801578Z'
          format: date-time
          type: string
        description:
          description: Rich text description of the incident status
          example: >-
            Impact has been **fully mitigated**, and we're ready to learn from
            this incident.
          type: string
        id:
          description: Unique ID of this incident status
          example: 01FCNDV6P870EA6S7TK1DSYD5H
          type: string
        name:
          description: Unique name of this status
          example: Closed
          type: string
        rank:
          description: Order of this incident status
          example: 4
          format: int64
          type: integer
        updated_at:
          example: '2021-08-17T13:28:57.801578Z'
          format: date-time
          type: string
      required:
        - id
        - name
        - description
        - rank
        - category
        - created_at
        - updated_at
      type: object
    SeverityV2:
      example:
        created_at: '2021-08-17T13:28:57.801578Z'
        description: Issues with **low impact**.
        id: 01FCNDV6P870EA6S7TK1DSYDG0
        name: Minor
        rank: 1
        updated_at: '2021-08-17T13:28:57.801578Z'
      properties:
        created_at:
          description: When the action was created
          example: '2021-08-17T13:28:57.801578Z'
          format: date-time
          type: string
        description:
          description: Description of the severity
          example: Issues with **low impact**.
          type: string
        id:
          description: Unique identifier of the severity
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        name:
          description: Human readable name of the severity
          example: Minor
          maxLength: 50
          type: string
        rank:
          description: Rank to help sort severities (lower numbers are less severe)
          example: 1
          format: int64
          type: integer
        updated_at:
          description: When the action was last updated
          example: '2021-08-17T13:28:57.801578Z'
          format: date-time
          type: string
      required:
        - id
        - name
        - description
        - rank
        - created_at
        - updated_at
      type: object
    ActorV2:
      example:
        alert:
          id: 01GW2G3V0S59R238FAHPDS1R66
          title: '*errors.withMessage: PG::Error failed to connect'
        api_key:
          id: 01FCNDV6P870EA6S7TK1DSYDG0
          name: My test API key
        user:
          email: lisa@incident.io
          id: 01FCNDV6P870EA6S7TK1DSYDG0
          name: Lisa Karlin Curtis
          role: owner
          slack_user_id: U02AYNF2XJM
        workflow:
          id: 01FCNDV6P870EA6S7TK1DSYDG0
          name: My little workflow
      properties:
        alert:
          $ref: '#/components/schemas/AlertActorV2'
        api_key:
          $ref: '#/components/schemas/APIKeyActorV2'
        user:
          $ref: '#/components/schemas/UserV2'
        workflow:
          $ref: '#/components/schemas/WorkflowActorV2'
      type: object
    AlertActorV2:
      example:
        id: 01GW2G3V0S59R238FAHPDS1R66
        title: '*errors.withMessage: PG::Error failed to connect'
      properties:
        id:
          description: The ID of this alert
          example: 01GW2G3V0S59R238FAHPDS1R66
          type: string
        title:
          description: >-
            The title of the alert, parsed from the alert payload according to
            the alert source configuration
          example: '*errors.withMessage: PG::Error failed to connect'
          type: string
      required:
        - id
        - title
      type: object
    APIKeyActorV2:
      example:
        id: 01FCNDV6P870EA6S7TK1DSYDG0
        name: My test API key
      properties:
        id:
          description: Unique identifier for this API key
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        name:
          description: The name of the API key, for the user's reference
          example: My test API key
          type: string
      required:
        - id
        - name
      type: object
    UserV2:
      example:
        email: lisa@incident.io
        id: 01FCNDV6P870EA6S7TK1DSYDG0
        name: Lisa Karlin Curtis
        role: owner
        slack_user_id: U02AYNF2XJM
      properties:
        email:
          description: Email address of the user.
          example: lisa@incident.io
          type: string
        id:
          description: Unique identifier of the user
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        name:
          description: Name of the user
          example: Lisa Karlin Curtis
          type: string
        role:
          description: >-
            DEPRECATED: Role of the user as of March 9th 2023, this value is no
            longer updated.
          enum:
            - viewer
            - responder
            - administrator
            - owner
            - unset
          example: owner
          type: string
        slack_user_id:
          description: Slack ID of the user
          example: U02AYNF2XJM
          type: string
      required:
        - role
        - id
        - name
      type: object
    WorkflowActorV2:
      example:
        id: 01FCNDV6P870EA6S7TK1DSYDG0
        name: My little workflow
      properties:
        id:
          description: Unique identifier for the workflow
          example: 01FCNDV6P870EA6S7TK1DSYDG0
          type: string
        name:
          description: Name provided by the user when creating the workflow
          example: My little workflow
          type: string
      required:
        - id
        - name
      type: object
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: API key from your incident.io dashboard (Settings → API keys)

````