Change Incident Severity
Sets the severity of an Incident Management incident by hand. The value then sticks and is no longer derived from its alerts.
POST /api/im/incidents/:id/severity
Sets an incident's severity. The incident is marked severityManual: true, so new alerts no longer raise or lower it automatically. If the incident is still triggered, its pending escalation is cancelled and re-armed at the incident's current tier under the new severity. Status pages driven by a status page rule and outbound integrations are notified of the change.
Authentication
Any IM-eligible role (admin, editor, responder) or an organization-wide API token, see Authentication. Incident Management must be enabled for the organization. Unlike resolve or status changes, this single-incident endpoint has no team restriction. (The severity action of Bulk Update Incidents does.)
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
severity | string | Yes | One of sev1, sev2, sev3, sev4. |
Example (cURL)
curl -X POST "$BASE_URL/api/im/incidents/42/severity" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{ "severity": "sev2" }'Response
200 OK: the updated incident row (same shape as the items of List Incidents, without the enrichment fields), with severity set and severityManual: true.
{
"id": 42,
"teamId": 3,
"title": "Database connection pool exhausted",
"severity": "sev2",
"severityManual": true,
"status": "triggered",
"currentTier": 1,
"escalationEpoch": 1
}(Shortened; the full row is returned.)
Common errors
401 Unauthorizedwhen not authenticated403 Forbidden(customerScopedTokenForbidden) when using a customer-scoped token403 Forbidden(imAccessDenied) when the session user has no IM-eligible role403 Forbidden(imNotEnabled) when Incident Management is not enabled for the organization400 Bad Request(invalidRequestBody) when:idis not a positive integer, orseverityis missing or not one ofsev1tosev4404 Not Found(imIncidentNotFound) when the incident does not exist, or belongs to another organization
Resolve Incident
Resolves an Incident Management incident from any non-closed status. This is the only endpoint that can move an incident to resolved.
Snooze Incident
Pauses escalation and reminders of an open Incident Management incident until a given time (at most 7 days ahead), or ends a snooze early.