{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "incident-io",
    "name": "incident.io API",
    "vendor": "Pineapple Technology Ltd. (incident.io)",
    "vendorUrl": "https://incident.io",
    "kind": "http-api",
    "category": "observability",
    "summary": "incident.io is an incident response, on-call, alerting and status page service. Agents reach it through a REST API at api.incident.io with an OpenAPI description and seven SDKs, a hosted MCP server and the `inc` CLI.",
    "url": "https://www.anchorterminal.com/tools/incident-io",
    "markdownUrl": "https://www.anchorterminal.com/tools/incident-io.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/incident-io.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/incident-io.json",
    "repo": "https://github.com/incident-io/sdk-ts",
    "license": "Proprietary service under incident.io's Terms and Conditions. The SDKs, the `inc` CLI and the skills plugin on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://mcp.incident.io/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@incident-io/sdk"
      },
      {
        "registry": "pypi",
        "name": "incident-io"
      }
    ],
    "auth": "mixed",
    "authNotes": "The REST API takes an API key as a Bearer token. An admin creates an organisation key in Settings and picks its permissions, 13 of which can be limited to named teams. A user key has its owner's current role. Keys are shown once and do not expire. The MCP server takes the same keys, or OAuth with PKCE for a person, which an admin must enable and which lasts 28 days. Access is self-serve on a paid plan, with no app review.",
    "pricing": "paid",
    "pricingNotes": "API, webhooks and MCP are not included in the free Basic plan. Team is $19 per user a month for incident response ($15 with the annual discount) plus $10 for on-call. Pro is $25 plus $20 for on-call, billed yearly through sales. Enterprise is quoted. API calls are not metered. The terms define a 14-day trial, which the docs say sales sets up for Pro and Enterprise. No sandbox below Enterprise (checked 2026-10-09).",
    "priceSummary": "$19 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI description or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 1318,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.incident.io/api-reference/introduction",
    "llmsTxt": "https://docs.incident.io/llms.txt",
    "openapi": "https://api.incident.io/v1/openapiV3.json",
    "capabilities": [
      "observability.incidents",
      "work.oncall"
    ],
    "tags": [
      "hosted",
      "rest",
      "openapi",
      "llms-txt",
      "mcp",
      "api-key",
      "oauth",
      "incidents",
      "on-call",
      "status-pages",
      "cli",
      "typescript",
      "python",
      "go",
      "status-page",
      "sla",
      "soc2"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.9,
      "grade": "B",
      "agentReady": false,
      "rank": 204,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 83,
        "payments": 10,
        "reliability": 90,
        "schema": 88,
        "security": 64,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 90,
          "points": 18,
          "reason": "Scored as a hosted API. status.incident.io lists 43 components, API and MCP among them, with uptime from July to October 2026 (20). The API component shows 100 per cent. The feed lists six incidents since 16 July 2026, one of which broke listing alerts in the public API on 18 August until a rollback, with no duration given, and none marked as an outage of the API (20). Limits are published with numbers, 1,200 requests a minute per key and lower figures for eight endpoints (15). 429 carries `Retry-After`, the body recommends exponential backoff, and seven create calls require an `idempotency_key` (15). The SLA commits to 99.9 per cent a month on Pro and Enterprise (10). The API carries no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "OpenAPI 3.0.3 description, public at api.incident.io/v1/openapiV3.json per the docs and read from docs.incident.io/openapi/latest.json, 284 operations and 777 schemas (25). llms.txt and a Markdown twin of every docs page (10). Every operation has a description, but the median is 65 characters and few say when not to use a call. List incidents is the exception, with worked filter examples (12). 262 enums, required fields marked and two free-form objects in the whole file (13). 4,014 example values and thirteen error statuses on every operation, though the shared error example pairs an unrelated code and message (13). Versions sit in the path per resource and the changelog is generated from the description file (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "Scored for the REST API. `page_size` sets response size, but no field selection was found and incident objects are large. The description file is 5.4 MB, with per-resource files as the smaller route (12). Cursor pagination on 41 list operations and operator filters such as `status_category[one_of]` (18). Errors carry a code, a message, the field at fault and a `request_id` (18). `idempotency_key` is required on seven create calls, and updates by PUT have no key (14). Seven official SDKs and a CLI with JSON output, with `idempotency_key` and `visibility` required to create an incident (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 64,
          "points": 11.2,
          "reason": "Organisation keys carry chosen permissions, 13 of 36 scopable to teams, can be rotated and are shown once. User keys take the owner's role and die with the account. 30 for that, less the checklist's 10 because alert event and heartbeat endpoints accept the alert source token in a `token` query parameter. The API key itself travels only in the header (20). A `viewer` permission gives read-only keys and the MCP status page tool only drafts, but no confirmation step guards destructive API calls (15). Alert payloads and incident text are untrusted content. The docs cover redaction of sensitive data, and no injection guidance for API consumers was found (4). Audit logs are Enterprise only, kept one year, exported or streamed, and API actions are attributed to the key (10). security.txt valid to July 2027, a disclosure policy with a five-working-day reply, SOC 2 Type I and II claimed, yearly penetration tests, no paid bounty (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). Plan prices per seat are public, Team at $19 and Pro at $25 a user a month, with no per-call price (10). The Basic plan is free, but the pricing page marks API, webhooks and MCP as not included, and the docs route trials through sales (0). A person signs up, pays and creates a key in the dashboard (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "The API changelog's newest entry is 8 October 2026 (30). 60 dated entries between 2 July and 8 October 2026 (20). A public changelog, support by email and a Slack community, with reply times not checked (10). Seven official SDKs generated from the description file, TypeScript 2.15.0 and Python 2.14.0 both tagged 8 October 2026 (15). The SDK and CLI repositories have test workflows, and the two SDKs read were first tagged in September 2026 and reached a second major version within two weeks (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 72, provenance 79",
          "reason": "Closed service under published Terms and Conditions effective 1 August 2026, with the SDKs, CLI and skills plugin under MIT (17). Privacy policy, DPA, sub-processor list and an AI data handling page are public. The terms limit training on customer content to the customer's own benefit. The security FAQ's statement that no data leaves Europe disagrees with a sub-processor list naming 17 processors in the United States, and retention is stated in general terms (20). Deprecated endpoints carry a removal date in their descriptions and the docs give integrators three months, but the changelog shows removals with no earlier entry (17). 20 sub-processors with locations and purposes, hosting regions named, 15 days' notice of changes in the DPA (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "high",
        "notes": {
          "ergonomics": "Scored for the REST API. `page_size` sets response size, but no field selection was found and incident objects are large. The description file is 5.4 MB, with per-resource files as the smaller route (12). Cursor pagination on 41 list operations and operator filters such as `status_category[one_of]` (18). Errors carry a code, a message, the field at fault and a `request_id` (18). `idempotency_key` is required on seven create calls, and updates by PUT have no key (14). Seven official SDKs and a CLI with JSON output, with `idempotency_key` and `visibility` required to create an incident (13).",
          "maintenance": "The API changelog's newest entry is 8 October 2026 (30). 60 dated entries between 2 July and 8 October 2026 (20). A public changelog, support by email and a Slack community, with reply times not checked (10). Seven official SDKs generated from the description file, TypeScript 2.15.0 and Python 2.14.0 both tagged 8 October 2026 (15). The SDK and CLI repositories have test workflows, and the two SDKs read were first tagged in September 2026 and reached a second major version within two weeks (8).",
          "payments": "No x402, MPP or L402 (0). Plan prices per seat are public, Team at $19 and Pro at $25 a user a month, with no per-call price (10). The Basic plan is free, but the pricing page marks API, webhooks and MCP as not included, and the docs route trials through sales (0). A person signs up, pays and creates a key in the dashboard (0).",
          "reliability": "Scored as a hosted API. status.incident.io lists 43 components, API and MCP among them, with uptime from July to October 2026 (20). The API component shows 100 per cent. The feed lists six incidents since 16 July 2026, one of which broke listing alerts in the public API on 18 August until a rollback, with no duration given, and none marked as an outage of the API (20). Limits are published with numbers, 1,200 requests a minute per key and lower figures for eight endpoints (15). 429 carries `Retry-After`, the body recommends exponential backoff, and seven create calls require an `idempotency_key` (15). The SLA commits to 99.9 per cent a month on Pro and Enterprise (10). The API carries no beta label (10).",
          "schema": "OpenAPI 3.0.3 description, public at api.incident.io/v1/openapiV3.json per the docs and read from docs.incident.io/openapi/latest.json, 284 operations and 777 schemas (25). llms.txt and a Markdown twin of every docs page (10). Every operation has a description, but the median is 65 characters and few say when not to use a call. List incidents is the exception, with worked filter examples (12). 262 enums, required fields marked and two free-form objects in the whole file (13). 4,014 example values and thirteen error statuses on every operation, though the shared error example pairs an unrelated code and message (13). Versions sit in the path per resource and the changelog is generated from the description file (15).",
          "security": "Organisation keys carry chosen permissions, 13 of 36 scopable to teams, can be rotated and are shown once. User keys take the owner's role and die with the account. 30 for that, less the checklist's 10 because alert event and heartbeat endpoints accept the alert source token in a `token` query parameter. The API key itself travels only in the header (20). A `viewer` permission gives read-only keys and the MCP status page tool only drafts, but no confirmation step guards destructive API calls (15). Alert payloads and incident text are untrusted content. The docs cover redaction of sensitive data, and no injection guidance for API consumers was found (4). Audit logs are Enterprise only, kept one year, exported or streamed, and API actions are attributed to the key (10). security.txt valid to July 2027, a disclosure policy with a five-working-day reply, SOC 2 Type I and II claimed, yearly penetration tests, no paid bounty (15).",
          "transparency": "Closed service under published Terms and Conditions effective 1 August 2026, with the SDKs, CLI and skills plugin under MIT (17). Privacy policy, DPA, sub-processor list and an AI data handling page are public. The terms limit training on customer content to the customer's own benefit. The security FAQ's statement that no data leaves Europe disagrees with a sub-processor list naming 17 processors in the United States, and retention is stated in general terms (20). Deprecated endpoints carry a removal date in their descriptions and the docs give integrators three months, but the changelog shows removals with no earlier entry (17). 20 sub-processors with locations and purposes, hosting regions named, 15 days' notice of changes in the DPA (18)."
        },
        "sources": [
          {
            "what": "API introduction with authentication, rate limits, pagination, errors and compatibility",
            "url": "https://docs.incident.io/api-reference/introduction.md",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI description file, read in place of the rendered reference pages",
            "url": "https://docs.incident.io/openapi/latest.json",
            "seen": "2026-10-09"
          },
          {
            "what": "deprecated endpoints description file",
            "url": "https://docs.incident.io/openapi/deprecated-endpoints.json",
            "seen": "2026-10-09"
          },
          {
            "what": "API changelog",
            "url": "https://docs.incident.io/api-reference/changelog.md",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.incident.io/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API key permissions",
            "url": "https://docs.incident.io/admin/api-keys.md",
            "seen": "2026-10-09"
          },
          {
            "what": "user API keys",
            "url": "https://docs.incident.io/admin/user-api-keys.md",
            "seen": "2026-10-09"
          },
          {
            "what": "remote MCP server, tool table and plans",
            "url": "https://docs.incident.io/ai/remote-mcp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "SDK overview and versioning",
            "url": "https://docs.incident.io/integrations/sdks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI docs",
            "url": "https://docs.incident.io/integrations/cli.md",
            "seen": "2026-10-09"
          },
          {
            "what": "audit logs",
            "url": "https://docs.incident.io/admin/audit-logs.md",
            "seen": "2026-10-09"
          },
          {
            "what": "security FAQ with hosting regions",
            "url": "https://docs.incident.io/admin/security-faqs.md",
            "seen": "2026-10-09"
          },
          {
            "what": "AI data handling",
            "url": "https://docs.incident.io/admin/ai-usage.md",
            "seen": "2026-10-09"
          },
          {
            "what": "billing and plan changes",
            "url": "https://docs.incident.io/admin/change-plan.md",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing and plan comparison",
            "url": "https://incident.io/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms and Conditions, effective 1 August 2026",
            "url": "https://incident.io/legal/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "Service Level Agreement",
            "url": "https://incident.io/legal/sla",
            "seen": "2026-10-09"
          },
          {
            "what": "sub-processors, effective 27 July 2026",
            "url": "https://incident.io/legal/sub-processors",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://incident.io/legal/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://incident.io/legal/data-processing-addendum",
            "seen": "2026-10-09"
          },
          {
            "what": "vulnerability disclosure policy",
            "url": "https://incident.io/legal/vulnerability-disclosure",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://incident.io/security",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://incident.io/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "status page components and uptime",
            "url": "https://status.incident.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "status incident feed",
            "url": "https://status.incident.io/feed.rss",
            "seen": "2026-10-09"
          },
          {
            "what": "TypeScript SDK repository, tags and README (shallow clone)",
            "url": "https://github.com/incident-io/sdk-ts",
            "seen": "2026-10-09"
          },
          {
            "what": "Python SDK repository, tags (shallow clone)",
            "url": "https://github.com/incident-io/sdk-python",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI repository, tags (shallow clone)",
            "url": "https://github.com/incident-io/inc",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads for @incident-io/sdk",
            "url": "https://api.npmjs.org/downloads/point/last-week/@incident-io/sdk",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "The lead said incident.io has no MCP server. The docs describe a hosted one at https://mcp.incident.io/mcp with 91 tools. This listing grades the REST API and records the MCP server as a second surface.",
          "unchecked: the MCP tool schemas and annotations, which are only available through tools/list with an account",
          "unchecked: trust.incident.io, which is drawn by script, so the SOC 2 claim rests on the security page and the security FAQ",
          "unchecked: the domain registration date, because rdap.org answered 404 for incident.io",
          "unchecked: PyPI download figures, because PyPI's robots.txt disallows `/pypi/`",
          "unchecked: whether a Team trial exists without a card. The terms define a 14-day trial and the docs mention trials only for Pro and Enterprise through sales",
          "The Team price shows as $19 with a second figure of $15 beside an annual discount switch. We read $15 as the yearly-billed price",
          "Whether the three removals in the changelog were announced to customers by another route was not established",
          "The Go, Rust, Ruby, PHP and .NET SDK repositories were not read"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "2026-04-09, 2026-06-26 and 2026-09-30: the API changelog records the request property `time_to_ack_seconds` removed from `POST /v2/escalation_paths`, the request property `version` removed from `POST /v2/alert_routes`, and the response property `layer_id` removed from `GET /v2/schedules`, each with no earlier deprecation entry in a changelog that starts on 5 January 2026. The docs say existing endpoints get no breaking changes. Whether customers were told another way was not established, so the deduction is 2 (https://docs.incident.io/api-reference/changelog)."
      ],
      "verdict": "The REST API has a public OpenAPI description with 284 operations, numeric rate limits, `Retry-After` on 429 and required idempotency keys on seven create calls. API and MCP access need the Team plan or higher, so the free Basic plan cannot be used by an agent, and audit logs are Enterprise only.",
      "bestFor": "Agents that declare and update incidents, page people, read on-call schedules and post status page incidents in an organisation that already pays for incident.io.",
      "strengths": [
        "OpenAPI 3.0.3 description with 284 operations, per-resource description files, llms.txt and Markdown twins of every docs page",
        "API keys carry chosen permissions, 13 of the 36 scopable to named teams, and user keys take the owner's role",
        "Default limit of 1,200 requests a minute per key, `X-RateLimit-*` headers on every response and `Retry-After` on 429",
        "`idempotency_key` is required on seven create calls, among them incidents, escalations and status page incidents",
        "API changelog generated from the description file, with 60 dated entries between 2 July and 8 October 2026"
      ],
      "weaknesses": [
        "The pricing page marks API, webhooks and MCP as not included in the free Basic plan. Team starts at $19 per user a month",
        "Audit logs are Enterprise only and reach the customer by CSV export or log stream, with no API to read them",
        "Alert event and heartbeat endpoints accept the alert source token in a `token` query parameter",
        "The changelog records three removals from live endpoints in 2026 with no earlier deprecation entry",
        "The security FAQ says no data leaves Europe, while the sub-processor list of 27 July 2026 names 17 processors in the United States"
      ],
      "agentNotes": [
        "Send `Authorization: Bearer \u003ckey\u003e` to https://api.incident.io and call `GET /v1/identity` first to read the key's roles",
        "Send a fresh `idempotency_key` with every create call for incidents, incident updates, timeline items, escalations and status page incidents. A repeated key returns the first result",
        "Page with `page_size` and `after` until no cursor comes back. Do not stop at a short or empty page",
        "Keep `GET /v2/incidents` under 60 requests a minute and wait the seconds in `Retry-After` on 429",
        "Incident creation is limited to 10 an hour per key when a Slack or Teams channel is created, 300 an hour otherwise"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "high",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.9
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 83,
        "payments": 10,
        "reliability": 90,
        "schema": 88,
        "security": 64,
        "transparency": 72
      },
      "provenanceScore": 79
    },
    "connect": {
      "install": "npm install @incident-io/sdk",
      "http": "curl --request GET https://api.incident.io/v1/identity --header 'Authorization: Bearer \u003cYOUR_API_KEY\u003e'",
      "claudeCode": "claude mcp add incident-io --transport http https://mcp.incident.io/mcp"
    },
    "letme": {
      "capability": "https://letme.dev/observability.incidents",
      "tool": "https://letme.dev/incident-io"
    },
    "notable": [
      "The API reference lists 284 operations on 162 paths in OpenAPI 3.0.3, with 82 smaller files by resource and version, plus files for webhooks, audit log events and deprecated endpoints (https://docs.incident.io/llms.txt)",
      "A hosted MCP server at https://mcp.incident.io/mcp lists 91 tools, takes OAuth with PKCE or an API key, and is included in Team, Pro and Enterprise plans but not Basic (https://docs.incident.io/ai/remote-mcp)",
      "The MCP tool `status_page_update` only drafts. The docs say a person publishes every status page update (https://docs.incident.io/ai/remote-mcp)",
      "Deprecated `/v2/actions` and `/v2/follow_ups` endpoints carry a removal date of 31 December 2026 in their descriptions (https://docs.incident.io/openapi/deprecated-endpoints.json)",
      "Section 2.10 of the terms of 1 August 2026 permits connecting agents and MCP clients through the APIs and makes the customer responsible for what they do (https://incident.io/legal/terms)",
      "The SLA commits to 99.9 per cent platform availability a month on Pro and Enterprise, and 99.99 per cent for notification triggering on Enterprise (https://incident.io/legal/sla)",
      "status.incident.io shows the API component at 100 per cent from July to October 2026, and the feed lists six incidents since 16 July (https://status.incident.io/feed.rss)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.incident.io, OpenAPI 3.0.3 with 284 operations on 162 paths (126 GET, 79 POST, 40 PUT, 38 DELETE, 1 PATCH). Versions are per resource in the path, such as `/v2/incidents` and `/v3/catalog_entries`"
      },
      {
        "label": "Coverage",
        "value": "Incidents, updates, timeline items, alerts, alert sources and routes, escalations and escalation paths, schedules and overrides, catalogue, status pages, workflows, post-mortem documents, follow-ups, users, teams, API keys and telemetry data sources"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.incident.io/mcp with 91 tools in the docs table. OAuth with PKCE for people (the grant lasts 28 days) or an API key for automation. An admin enables it in settings. Team, Pro and Enterprise only"
      },
      {
        "label": "Credentials",
        "value": "Organisation API keys with chosen permissions, 13 of which can be limited to named teams, and user API keys that take the owner's current role. Bearer header. Keys do not expire. A user key pushed to a public GitHub repository is deleted automatically"
      },
      {
        "label": "Rate limits",
        "value": "1,200 requests a minute per key. List incidents 60 a minute, update catalogue entry 300 a minute, bulk catalogue update 60 a minute. Incident creation 10 an hour with a chat channel, 300 an hour without"
      },
      {
        "label": "Errors",
        "value": "JSON with `type`, `status`, `request_id` and an `errors` list of `code`, `message` and `source.field`. 429 carries `Retry-After` in seconds and a `rate_limit` object"
      },
      {
        "label": "Pagination",
        "value": "Cursor, `page_size` (default 25, maximum set per endpoint, 250 for incidents) and `after`, on 41 list operations. Configuration lists return everything in one response"
      },
      {
        "label": "Idempotency",
        "value": "`idempotency_key` is a required body field on create calls for incidents, incident updates, timeline items, escalations, status page incidents, maintenances and retrospective incidents"
      },
      {
        "label": "SDKs",
        "value": "Go, TypeScript (`@incident-io/sdk` 2.15.0), Python (`incident-io` 2.14.0, Python 3.11 or later), Rust, Ruby, PHP and .NET, generated from the OpenAPI description, MIT. Terraform and Pulumi providers"
      },
      {
        "label": "CLI",
        "value": "`inc`, MIT, v0.4.25 on 9 October 2026. JSON output, `inc describe` for a schema of every command, `--dry-run`, and `inc api` for any endpoint"
      },
      {
        "label": "Compatibility",
        "value": "The docs promise no breaking changes to existing endpoints, a new path version when one is needed, and three months for integrators to move off a deprecated endpoint"
      },
      {
        "label": "Audit",
        "value": "Audit logs on Enterprise only, kept one year, by CSV export or log stream to a SIEM. API actions are attributed to the key, or to the person for a user key"
      },
      {
        "label": "Hosting",
        "value": "Google Cloud, europe-west1 (Belgium) with a standby in europe-west4 (Netherlands), per the security FAQ. 20 sub-processors listed on 27 July 2026, 17 in the United States"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type I and II and GDPR compliance claimed on incident.io/security, with yearly third-party penetration tests. The trust centre was not read"
      },
      {
        "label": "Status",
        "value": "status.incident.io with 43 components, among them API and MCP, with uptime from July to October 2026 and Atom and RSS feeds"
      }
    ],
    "unitPrices": [
      {
        "item": "Team plan, incident response",
        "unit": "seat-month",
        "usd": 19,
        "note": "$15 with the annual discount. On-call adds $10"
      },
      {
        "item": "Pro plan, incident response",
        "unit": "seat-month",
        "usd": 25,
        "note": "billed yearly through sales. On-call adds $20"
      },
      {
        "item": "On-call only",
        "unit": "seat-month",
        "usd": 20,
        "note": "sold through sales"
      }
    ],
    "provenance": {
      "legalEntity": "Pineapple Technology Ltd.",
      "domain": "incident.io",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://incident.io/legal/terms",
      "privacy": "https://incident.io/legal/privacy",
      "statusPage": "https://status.incident.io",
      "changelog": "https://docs.incident.io/api-reference/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The site footer and the legal pages carry the copyright of Pineapple Technology Ltd. The terms are governed by the laws of England and Wales. No company number was found on the pages read.",
        "The Terms and Conditions are effective 1 August 2026 and are served at incident.io/legal and incident.io/legal/terms. Orders before that date fall under legacy terms.",
        "The API answers at api.incident.io and the MCP server at mcp.incident.io.",
        "incident.io/.well-known/security.txt names security@incident.io and the vulnerability disclosure policy, and expires on 15 July 2027.",
        "rdap.org answered 404 for incident.io, so the registration date is not recorded."
      ],
      "score": 79,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Pineapple Technology Ltd.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "incident.io, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.incident.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.incident.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://incident.io/legal/terms",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-08-01",
          "words": 8105,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective: August 1, 2026",
              "says": "Last updated 2026-08-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by and construed under the laws of England and Wales.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…INDEMNIFICATION OBLIGATIONS IN SECTION 7, OR CUSTOMER’S BREACH OF THE RESTRICTIONS IN SECTION 2.9: (A) IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES OF ANY KIND WHATSOEVER, WHETHER IN CONTRACT, TORT, OR OTHERWISE, INCLUDING WITHOUT LIMITAT…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "incident.io may apply usage limits to, or suspend, API or MCP access that threatens the security, stability, or integrity of the Services."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer shall not, and shall ensure its Users do not: (a) except to the extent expressly permitted by applicable law reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of the incident.io Platform;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Go to pageTerms and ConditionsService Level AgreementData Processing AddendumSub-processorsDORA AddendumPrivacy PolicySMS TermsVulnerability Disclosure PolicyCookie Policy"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "incident.io may use User Content to train, tune, and improve the AI Services solely for the exclusive benefit of Customer, in order to solely make the AI Services more accurate and tailored for Customer, without requiring Customer’s separate consent.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(f) access, use or view the Services for the purpose of creating a product or service that is competitive with the Services;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers may connect agents and MCP clients through the API, and the vendor's obligations over user content stop once data is sent to such a connected system.",
              "quote": "incident.io gives no warranty or indemnity in respect of Connected Systems, and incident.io’s obligations regarding User Content (including under the Data Processing Addendum) do not extend to data once transmitted to a Connected System at Customer’s direction."
            },
            {
              "date": "2026-10-08",
              "text": "The subscription renews automatically for the same length, and fees for a renewal term may rise on at least 60 days' written notice.",
              "quote": "The Subscription Fees to be charged for any Renewal Subscription Term may be increased upon at least sixty (60) days prior written notice to Customer and will only take effect at the start of such Renewal Subscription Term."
            },
            {
              "date": "2026-10-08",
              "text": "Unless the order form says otherwise, incident.io may name the customer and use its logo on its websites, customer lists and marketing materials.",
              "quote": "Customer agrees that incident.io is permitted to identify Customer as an incident.io customer, and to use Customer’s name and/or logo on incident.io’s websites, and in its customer lists and marketing materials"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://incident.io/legal/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2024-02-15",
          "words": 2293,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: February 15, 2024",
              "says": "Last updated 2024-02-15"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Among the types of Personal Data that incident.io collects, by itself or through third parties, there are: email address;"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Go to pageTerms and ConditionsService Level AgreementData Processing AddendumSub-processorsDORA AddendumPrivacy PolicySMS TermsVulnerability Disclosure PolicyCookie Policy"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.If an…"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/incident-io.json",
    "live": {
      "slug": "incident-io",
      "probe": {
        "target": "https://mcp.incident.io/mcp",
        "method": "get",
        "lastAt": "2026-10-10T01:37:54.710722358Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 39,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 41,
        "p95ms24h": 127,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.incident.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-10T01:33:46.844963315Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "incident-io/sdk-ts",
          "version": "v2.16.0",
          "released": "2026-10-09",
          "seenAt": "2026-10-09T16:58:49.132589223Z"
        },
        {
          "registry": "npm",
          "name": "@incident-io/sdk",
          "version": "2.16.0",
          "seenAt": "2026-10-09T16:58:48.142655813Z"
        },
        {
          "registry": "pypi",
          "name": "incident-io",
          "version": "2.15.0",
          "released": "2026-10-09",
          "seenAt": "2026-10-09T16:58:49.00565692Z"
        }
      ],
      "githubStars": 30,
      "npmWeekly": 1318,
      "pypiWeekly": 1041,
      "pages": [
        {
          "url": "https://docs.incident.io/api-reference/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:37:30.70893084Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "3d8a9febed2d"
        },
        {
          "url": "https://incident.io/legal/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:40:28.282721977Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "6540eebcda32"
        },
        {
          "url": "https://incident.io/legal/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:40:30.320495457Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "9efbb6623280"
        }
      ],
      "updatedAt": "2026-10-10T01:37:54.710722358Z"
    }
  }
}
