Skip to main content

Base URL

All endpoints are served from:
Requests and responses use JSON unless an endpoint says otherwise.

Authentication

Send an API key as a bearer token:
There are two kinds of key: Endpoints that record who created something (creating monitors, heartbeats, status pages, updates and maintenance) need a user, so organization keys receive 403 there. Use a personal key. Some endpoints are marked session only. They serve the GetMonitor panel and cannot be called with an API key; keys receive 401.

Choosing the organization

Endpoints that act inside an organization need the X-Organization-Id header. Missing it returns 400. An organization the key cannot access returns 403. To find your organization IDs, call List organizations with a personal key. It does not need the header.

Scopes and roles

Each key carries scopes. An endpoint lists the scope it needs, and the request must also pass the role check: Read endpoints accept the viewer, member, admin and owner roles. Write endpoints accept member, admin and owner, so a viewer’s key is always read-only.

Errors

Errors share one shape:
For validation errors (400), message is a list with one entry per problem.

Billing headers

Organization-scoped responses include the organization’s billing state: