The token belongs to one workspace. API access is on paid plans. The OpenAPI document describes these routes and nothing else.
How do you authenticate?
Create a token in the workspace and send it as Authorization: Bearer. A token can be limited to these scopes: monitors:read, monitors:write, incidents:read, incidents:write, status-pages:read, status-pages:write. status-pages:write can be granted, and this version of the API has no route that uses it.
One address may make 600 requests a minute before the token is checked. One token may make 120 a minute after that. A refusal uses status 429 and a Retry-After header.
Which calls exist?
API routes
Call
Scope
What it does
GET /api/v1/monitors
monitors:read
List monitors. Deleted ones are left out.
POST /api/v1/monitors
monitors:write
Create a monitor. A heartbeat token or server install command is returned once, in this response only.
POST /api/v1/monitors/{id}/pause
monitors:write
Stop checks.
POST /api/v1/monitors/{id}/resume
monitors:write
Start checks again. The monitor returns to pending.
GET /api/v1/incidents
incidents:read
The 100 newest incidents.
POST /api/v1/incidents/{id}/acknowledge
incidents:write
Acknowledge an open incident. A resolved incident is refused.
GET /api/v1/status-pages
status-pages:read
List status pages. A password is not included.
The machine-readable document is at /api/v1/openapi.json. It describes 6 paths. A Terraform provider is not part of this repository.
What comes back once?
Creating a heartbeat monitor returns heartbeatToken in that response. Creating a server monitor returns agentInstallCommand. Later reads do not include them. An HTTP auth header or request body is stored encrypted and is left out of list responses. Do not put a token in a URL, a ticket, or a log.