Get Incident Details
Returns detailed incident data, including a timeline of failed/recovery checks and alert events.
GET /api/incidents/:incidentPublicId
Authentication
Requires a valid session.
- Header:
Authorization: Bearer <token>
Parameters
incidentPublicId(Path, required): Incident public UUID.
Example (cURL)
BASE_URL="https://uptimeify.io"
TOKEN="<your-api-token>"
curl -X GET "$BASE_URL/api/incidents/6bfec6f6-245a-47ce-843b-157d97d56f88" \
-H "Authorization: Bearer $TOKEN" \
-H "Accept: application/json"Note: evidenceCheck can be null. screenshotUrl is only set when hasScreenshot is true.
Timeline resolution
Every entry in outageStartedCheck, failedChecks and recoveryChecks carries a resolution:
raw: a single check at a single location.location,statusCodeanderrorMessageare the ones that location reported.1min: one minute of the monitoring aggregate, used once an incident is older than the raw check retention window (48 hours).location,statusCodeanderrorMessagearenull,responseTimeMsis the average over the minute, and two extra fields say how many locations were behind it:totalLocationsandfailedLocations. Theidof such an entry is synthetic (1min-<timestamp>) and cannot be looked up as a check.
The three lists are resolved independently, so an incident that spans the boundary can return raw entries for its recent part and 1min entries for the older one.
Example Response (excerpt)
{
"incident": {
"id": 123,
"websiteId": 101,
"type": "downtime",
"status": "open",
"startedAt": "2026-02-26T12:10:00.000Z",
"resolvedAt": null,
"statusCode": null,
"errorMessage": "Timeout",
"responseTimeMs": null,
"falseAlarmAt": null,
"falseAlarmReason": null
},
"timeline": {
"outageStartedAt": "2026-02-26T12:08:00.000Z",
"outageStartedCheck": {
"id": "chk_01H...",
"checkedAt": "2026-02-26T12:08:00.000Z",
"status": "failure",
"statusCode": 503,
"errorMessage": "Timeout",
"responseTimeMs": null,
"location": { "id": 7, "code": "de-nbg", "name": "Nuremberg (DE)" },
"resolution": "raw"
},
"confirmationAt": "2026-02-26T12:10:00.000Z",
"failedChecks": [
{
"id": "1min-2026-02-26T12:09:00.000Z",
"checkedAt": "2026-02-26T12:09:00.000Z",
"status": "failure",
"statusCode": null,
"errorMessage": null,
"responseTimeMs": 246,
"location": null,
"resolution": "1min",
"totalLocations": 3,
"failedLocations": 2
}
],
"failedChecksTotal": 2,
"alertEvents": [
{
"id": 987,
"sentAt": "2026-02-26T12:11:00.000Z",
"type": "email",
"status": "sent",
"channelName": "Ops Email",
"errorMessage": null
}
],
"recoveryChecks": [],
"recoveryChecksTotal": 0
},
"evidenceCheck": {
"id": "chk_01H...",
"checkedAt": "2026-02-26T12:08:00.000Z",
"diagnostics": null,
"hasScreenshot": false,
"screenshotUrl": null
}
}False-alarm mark
An incident can be marked as a false alarm (POST /api/incidents/{id}/false-alarm). Two read-only
fields on incident report that mark:
| Field | Type | Meaning |
|---|---|---|
falseAlarmAt | string | null | When the mark was set, ISO 8601. null means the incident is not marked. |
falseAlarmReason | string | null | The free-text reason given when marking, or null. |
The mark is reversible, so falseAlarmAt can return to null. It does not change status: an
incident marked as a false alarm still went out as an alert, which is the point the mark records.
The user who set the mark is not part of the response.
Common Errors
400 Incident public ID (UUID) requiredif:incidentPublicIdis invalid401 Unauthorizedif you are not authenticated403 Forbiddenif the incident exists but you do not have access404 Incident not foundif the incident does not exist