Base URL
All endpoints are served from:Authentication
Send an API key as a bearer token:
Endpoints that record who created something (creating monitors, heartbeats, status pages, updates and maintenance) need a user, so organization keys receive
403 there. Use a personal key.
Some endpoints are marked session only. They serve the GetMonitor panel and cannot be called with an API key; keys receive 401.
Choosing the organization
Endpoints that act inside an organization need theX-Organization-Id header. Missing it returns 400. An organization the key cannot access returns 403.
To find your organization IDs, call List organizations with a personal key. It does not need the header.
Scopes and roles
Each key carries scopes. An endpoint lists the scope it needs, and the request must also pass the role check:
Read endpoints accept the viewer, member, admin and owner roles. Write endpoints accept member, admin and owner, so a viewer’s key is always read-only.
Errors
Errors share one shape:400), message is a list with one entry per problem.