---
title: "Bulk Update Incidents"
description: "Applies one action (acknowledge, resolve, severity, assign) to up to 200 Incident Management incidents at once, with a per-incident result."
---

`POST /api/im/incidents/bulk`

Applies one action to many incidents, for example to acknowledge or resolve dozens of incidents during a large outage. Every incident runs through exactly the same logic as the single-incident endpoint, with the same side effects (stopping or re-arming escalation, status pages, outbound integrations). Incidents are processed one by one and independently: one failing incident does not undo or block the others, so the request is **not** atomic.

## Authentication

Any IM-eligible role (`admin`, `editor`, `responder`) or an organization-wide API token, see [Authentication](/api/incident-management#authentication). Incident Management must be enabled for the organization.

Every action except `acknowledge` is restricted to the incidents' teams: you must be a member of the team of **every** selected incident, or an organization admin. This is checked for all ids before anything is changed; if any incident is not yours, the whole request is refused with `403` and the offending ids are listed in `data.deniedIncidentIds`. An organization-wide API token passes as an organization admin.

## Request Body

| Field | Type | Required | Description |
|-------|------|----------|--------------|
| `ids` | number[] | Yes | 1 to 200 incident IDs, unique positive integers. |
| `action` | string | Yes | One of `acknowledge`, `resolve`, `severity`, `assign`, `team`. |
| `payload` | object | Depends on `action` | See below. |

| `action` | `payload` | Same as |
|----------|-----------|---------|
| `acknowledge` | none | [Acknowledge](/api/incident-management/acknowledge-incident#acknowledge). An incident that is already acknowledged counts as `ok`. |
| `resolve` | `note` (string, optional, up to 10,000 characters) | [Resolve Incident](/api/incident-management/resolve-incident) |
| `severity` | `severity` (required, `sev1` to `sev4`) | [Change Incident Severity](/api/incident-management/incident-severity) |
| `assign` | `userId` (required: a user ID, or `null` to remove the role holder), `role` (optional, default `assignee`) | [Assign a role](/api/incident-management/incident-assign#assign-a-role) |
| `team` | `teamId` (required) | Not implemented, always answers `501` |

## Example (cURL)

```bash
curl -X POST "$BASE_URL/api/im/incidents/bulk" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "ids": [42, 43, 44],
    "action": "resolve",
    "payload": { "note": "Upstream provider outage resolved." }
  }'
```

## Response

`200 OK`, also when some incidents failed. `ok` lists the IDs that were changed, `failed` the others with a `reason`: the `data.code` the single-incident endpoint would have returned (for example `imIncidentNotFound`, `imIncidentAlreadyClosed`, `imIncidentStatusConflict`, `invalidUserId`), or `unknown`.

```json
{
  "ok": [42, 43],
  "failed": [
    { "id": 44, "reason": "imIncidentAlreadyClosed" }
  ]
}
```

## Common errors

- `401 Unauthorized` when not authenticated
- `403 Forbidden` (`customerScopedTokenForbidden`) when using a customer-scoped token
- `403 Forbidden` (`imAccessDenied`) when the session user has no IM-eligible role
- `403 Forbidden` (`imNotEnabled`) when Incident Management is not enabled for the organization
- `403 Forbidden` (`imTeamMembershipRequired`) when the action is not `acknowledge` and at least one selected incident belongs to a team you are not a member of (and you are not an organization admin); `data.deniedIncidentIds` lists them, nothing was changed
- `400 Bad Request` (`invalidRequestBody`) when `ids` is empty, longer than 200, contains duplicates or non-positive-integers, `action` is unknown, or the payload for the action is invalid (missing or unknown `severity`, missing `userId`, unknown `role`, `note` not a string or too long, missing `teamId`)
- `501 Not Implemented` (`imBulkActionNotImplemented`) for `action: "team"`; moving incidents between teams is not supported
