Get Incident
Returns the full detail of a single Incident Management incident: the incident row plus its alerts, timeline events, and role assignments.
GET /api/im/incidents/:id
Returns the full detail of a single incident: the incident row plus its alerts (a safe, redacted view, see below), timeline events in chronological order, and role assignments.
Authentication
Same as List Incidents: any IM-eligible role (admin, editor, responder), or an organization-wide API token. Incident Management must be enabled for the organization.
Example (cURL)
curl -X GET "$BASE_URL/api/im/incidents/42" \
-H "Authorization: Bearer $TOKEN" \
-H "Accept: application/json"Response
{
"id": 42,
"organizationId": 1,
"teamId": 3,
"title": "Database connection pool exhausted",
"customerId": null,
"primarySourceId": 7,
"severity": "sev1",
"severityManual": false,
"status": "triggered",
"mergedIntoId": null,
"escalationPolicyId": 5,
"currentTier": 1,
"escalationEpoch": 0,
"acknowledgedBy": null,
"acknowledgedAt": null,
"snoozedUntil": null,
"autoResolve": true,
"resolvedBy": null,
"resolveNote": null,
"createdBy": null,
"sourceKind": "alert",
"triggeredAt": "2026-07-17T09:12:00.000Z",
"resolvedAt": null,
"alerts": [
{
"id": 101,
"organizationId": 1,
"sourceId": 7,
"dedupKey": "db-primary-01:pool-exhausted",
"status": "open",
"suppressedReason": null,
"title": "Database connection pool exhausted",
"severity": "sev1",
"host": "db-primary-01",
"mappedFields": {},
"duplicateCount": 0,
"firstSeenAt": "2026-07-17T09:12:00.000Z",
"resolvedAt": null,
"incidentId": 42
}
],
"events": [
{
"id": 501,
"incidentId": 42,
"at": "2026-07-17T09:12:00.000Z",
"kind": "alert_received",
"actorUserId": null,
"payload": {}
}
],
"assignments": [
{
"id": 12,
"userId": "u_abc123",
"userName": "Jane Doe",
"role": "commander",
"createdAt": "2026-07-17T09:15:00.000Z"
}
]
}alerts[].rawPayload is never returned by this endpoint: the raw webhook/API payload can carry API keys or other secrets its source's operator put in it. It is also nulled server-side 90 days after ingest by a retention job. alerts[].mappedFields is the already-normalized, safe view of the same alert and survives retention.
Retention, in full: alert payloads (rawPayload) are nulled 90 days after ingest; resolved alerts are deleted 90 days after ingest; outbound-delivery (integration forwarding) records are deleted 90 days after they were sent. The incident itself and its timeline events (events) are kept in full for 12 months after the incident triggered; after that only a daily aggregate survives (incident counts plus acknowledge and resolve times, per team and severity), for 24 months total. Per-source daily aggregates (alert/dedup/incident counts, as shown on a source's Analytics tab) are retained indefinitely. Deleting the underlying alert rows does not erase that history.
Common errors
401 Unauthorizedwhen not authenticated403 Forbidden(imAccessDenied) when using a customer-scoped token, or a session without an IM-eligible role403 Forbidden(imNotEnabled) when Incident Management is not enabled for the organization400 Bad Request(invalidRequestBody) when:idis not a positive integer404 Not Found(imIncidentNotFound) when the incident does not exist, or belongs to another organization