---
title: "Comment on Incident"
description: "Adds a comment to the timeline of an Incident Management incident."
---

`POST /api/im/incidents/:id/comment`

Adds a free-text comment to the incident's timeline (an event of kind `comment`, visible in `events` of [Get Incident](/api/incident-management/get-incident)). Outbound integrations are notified of the comment, and subscribers of a status page driven by a [status page rule](/api/incident-management/statuspage-rules) may receive it as an update. Comments are accepted on closed incidents too.

## Authentication

Any IM-eligible role (`admin`, `editor`, `responder`) or an organization-wide API token, see [Authentication](/api/incident-management#authentication). Incident Management must be enabled for the organization. There is no team restriction.

## Request Body

| Field | Type | Required | Description |
|-------|------|----------|--------------|
| `text` | string | Yes | Comment text, not blank, up to 10,000 characters. |

## Example (cURL)

```bash
curl -X POST "$BASE_URL/api/im/incidents/42/comment" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "text": "Failover to the replica is running, ETA 10 minutes." }'
```

## Response

`200 OK`

```json
{
  "ok": true
}
```

## Common errors

- `401 Unauthorized` when not authenticated
- `403 Forbidden` (`customerScopedTokenForbidden`) when using a customer-scoped token
- `403 Forbidden` (`imAccessDenied`) when the session user has no IM-eligible role
- `403 Forbidden` (`imNotEnabled`) when Incident Management is not enabled for the organization
- `400 Bad Request` (`invalidRequestBody`) when `:id` is not a positive integer, or `text` is missing, blank or longer than 10,000 characters
- `404 Not Found` (`imIncidentNotFound`) when the incident does not exist, or belongs to another organization
