Skip to content

Call the API with a bearer token.

The token belongs to one workspace. API access is on paid plans. The OpenAPI document describes these routes and nothing else.

How do you authenticate?

Create a token in the workspace and send it as Authorization: Bearer. A token can be limited to these scopes: monitors:read, monitors:write, incidents:read, incidents:write, status-pages:read, status-pages:write. status-pages:write can be granted, and this version of the API has no route that uses it.

curl https://upkira.com/api/v1/monitors \
  -H "Authorization: Bearer YOUR-TOKEN"

One address may make 600 requests a minute before the token is checked. One token may make 120 a minute after that. A refusal uses status 429 and a Retry-After header.

Which calls exist?

API routes
CallScopeWhat it does
GET /api/v1/monitorsmonitors:readList monitors. Deleted ones are left out.
POST /api/v1/monitorsmonitors:writeCreate a monitor. A heartbeat token or server install command is returned once, in this response only.
POST /api/v1/monitors/{id}/pausemonitors:writeStop checks.
POST /api/v1/monitors/{id}/resumemonitors:writeStart checks again. The monitor returns to pending.
GET /api/v1/incidentsincidents:readThe 100 newest incidents.
POST /api/v1/incidents/{id}/acknowledgeincidents:writeAcknowledge an open incident. A resolved incident is refused.
GET /api/v1/status-pagesstatus-pages:readList status pages. A password is not included.

The machine-readable document is at /api/v1/openapi.json. It describes 6 paths. A Terraform provider is not part of this repository.

What comes back once?

Creating a heartbeat monitor returns heartbeatToken in that response. Creating a server monitor returns agentInstallCommand. Later reads do not include them. An HTTP auth header or request body is stored encrypted and is left out of list responses. Do not put a token in a URL, a ticket, or a log.

Getting started covers adding a check in the app.