- Use an alert source when the tool reports a signal that might be an incident: a monitor firing, an error rate climbing, a check failing. incident.io deduplicates repeated events, groups related alerts into one incident, pages the right people, and can decline the incident when the signal clears.
- Use the API when someone or something has already decided it’s an incident: a support agent clicking Escalate in your ticketing tool, a form in an internal portal, or a script that runs your own logic. You get an incident straight away, with the fields you set.
Send alerts to an alert source
Create an HTTP alert source. It gives you a URL and a secret token to send events to:How events become alerts
Thededuplication_key identifies the thing you’re alerting on:
- Repeat events update the alert. Sending
firingagain with the same key updates the existing alert rather than creating a new one, so a monitor that re-sends every minute produces one alert. resolvedresolves it. Send the same key with"status": "resolved"when the signal clears.- Firing again after that starts a new alert, because the previous one is resolved.
metadata to set alert attributes, like the affected service or team, so you can route and filter on them. Each alert source has its own rate limit.
How alerts become incidents
An alert route connects the alert source to incidents and paging. For each route, you choose:- Which alerts count, by filtering on alert attributes and priority.
- Whether related alerts share an incident, by grouping alerts that fire close together, or that share attributes like the service.
- Whether incidents start in triage. Triage incidents let a responder accept or decline before the incident process starts. Tick Decline triage incidents if the linked alerts are resolved to decline them automatically when the signal clears.
- Who gets paged, through escalation paths. Paging and incident creation are independent, so a route can page without creating incidents, or the reverse.
- How the incident looks: its name, summary, severity, and custom fields, set from the alert. See Incident templates.
Call the create incident API
Create an API key with the Create incidents permission, and call the create incident endpoint:- Use an ID from your tool as the
idempotency_key, like the ticket number. Sending the same key again returns the incident you already created, so retries never make duplicates. - The incident starts in an active status and opens its own Slack or Microsoft Teams channel, unless its incident type is set to start in triage or to skip creating a channel. A
severity_idis required for an active incident. List yours with the severities endpoint. - Set anything a responder would: the incident type, custom fields, role assignments, and timestamps. See Creating your first incident using the API for a walkthrough.
- Run workflows on API-created incidents by adding a condition on the API Key creator, so you can, for example, invite the support agent who escalated the ticket.