incident.io API

by Pineapple Technology Ltd. (incident.io) HTTP API in Observability & incidents

Hosted

Pineapple Technology Ltd. · incident.io · status page · who's behind it

incident.io is an incident response, on-call, alerting and status page service. Agents reach it through a REST API at api.incident.io with an OpenAPI description and seven SDKs, a hosted MCP server and the inc CLI.

Good for Agents that declare and update incidents, page people, read on-call schedules and post status page incidents in an organisation that already pays for incident.io.

Is this your product? Claim this listing or verify it

Assessment. The REST API has a public OpenAPI description with 284 operations, numeric rate limits, Retry-After on 429 and required idempotency keys on seven create calls. API and MCP access need the Team plan or higher, so the free Basic plan cannot be used by an agent, and audit logs are Enterprise only.

Facts

Transport
HTTP
Endpoint
https://mcp.incident.io/mcp
Auth
OAuth or key
Pricing
Paid · $19 / seat-mo
x402
No
Licence
Proprietary service under incident.io's Terms and Conditions. The SDKs, the `inc` CLI and the skills plugin on GitHub are MIT
Packages
npm @incident-io/sdk
pypi incident-io
llms.txt
published
Last release
npm / week
1.3k
API
REST at https://api.incident.io, OpenAPI 3.0.3 with 284 operations on 162 paths (126 GET, 79 POST, 40 PUT, 38 DELETE, 1 PATCH). Versions are per resource in the path, such as /v2/incidents and /v3/catalog_entries
Coverage
Incidents, updates, timeline items, alerts, alert sources and routes, escalations and escalation paths, schedules and overrides, catalogue, status pages, workflows, post-mortem documents, follow-ups, users, teams, API keys and telemetry data sources
MCP server
Hosted at https://mcp.incident.io/mcp with 91 tools in the docs table. OAuth with PKCE for people (the grant lasts 28 days) or an API key for automation. An admin enables it in settings. Team, Pro and Enterprise only
Credentials
Organisation API keys with chosen permissions, 13 of which can be limited to named teams, and user API keys that take the owner's current role. Bearer header. Keys do not expire. A user key pushed to a public GitHub repository is deleted automatically
Rate limits
1,200 requests a minute per key. List incidents 60 a minute, update catalogue entry 300 a minute, bulk catalogue update 60 a minute. Incident creation 10 an hour with a chat channel, 300 an hour without
Errors
JSON with type, status, request_id and an errors list of code, message and source.field. 429 carries Retry-After in seconds and a rate_limit object
Pagination
Cursor, page_size (default 25, maximum set per endpoint, 250 for incidents) and after, on 41 list operations. Configuration lists return everything in one response
Idempotency
idempotency_key is a required body field on create calls for incidents, incident updates, timeline items, escalations, status page incidents, maintenances and retrospective incidents
SDKs
Go, TypeScript (@incident-io/sdk 2.15.0), Python (incident-io 2.14.0, Python 3.11 or later), Rust, Ruby, PHP and .NET, generated from the OpenAPI description, MIT. Terraform and Pulumi providers
CLI
inc, MIT, v0.4.25 on 9 October 2026. JSON output, inc describe for a schema of every command, --dry-run, and inc api for any endpoint
Compatibility
The docs promise no breaking changes to existing endpoints, a new path version when one is needed, and three months for integrators to move off a deprecated endpoint
Audit
Audit logs on Enterprise only, kept one year, by CSV export or log stream to a SIEM. API actions are attributed to the key, or to the person for a user key
Hosting
Google Cloud, europe-west1 (Belgium) with a standby in europe-west4 (Netherlands), per the security FAQ. 20 sub-processors listed on 27 July 2026, 17 in the United States
Certifications
SOC 2 Type I and II and GDPR compliance claimed on incident.io/security, with yearly third-party penetration tests. The trust centre was not read
Status
status.incident.io with 43 components, among them API and MCP, with uptime from July to October 2026 and Atom and RSS feeds

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OpenAPI 3.0.3 description with 284 operations, per-resource description files, llms.txt and Markdown twins of every docs page
  • API keys carry chosen permissions, 13 of the 36 scopable to named teams, and user keys take the owner's role
  • Default limit of 1,200 requests a minute per key, X-RateLimit-* headers on every response and Retry-After on 429
  • idempotency_key is required on seven create calls, among them incidents, escalations and status page incidents
  • API changelog generated from the description file, with 60 dated entries between 2 July and 8 October 2026

Weaknesses

  • The pricing page marks API, webhooks and MCP as not included in the free Basic plan. Team starts at $19 per user a month
  • Audit logs are Enterprise only and reach the customer by CSV export or log stream, with no API to read them
  • Alert event and heartbeat endpoints accept the alert source token in a token query parameter
  • The changelog records three removals from live endpoints in 2026 with no earlier deprecation entry
  • The security FAQ says no data leaves Europe, while the sub-processor list of 27 July 2026 names 17 processors in the United States

Before you call it notes for agents

  1. Send Authorization: Bearer <key> to https://api.incident.io and call GET /v1/identity first to read the key's roles
  2. Send a fresh idempotency_key with every create call for incidents, incident updates, timeline items, escalations and status page incidents. A repeated key returns the first result
  3. Page with page_size and after until no cursor comes back. Do not stop at a short or empty page
  4. Keep GET /v2/incidents under 60 requests a minute and wait the seconds in Retry-After on 429
  5. Incident creation is limited to 10 an hour per key when a Slack or Teams channel is created, 300 an hour otherwise

Who's behind it provenance 79/100

  • Legal entity namedPineapple Technology Ltd.20/20
  • Domain ageincident.io, no registry record we could read0/15
  • Endpoint on the vendor's domainmcp.incident.io15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagestatus.incident.io10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service dated 2026-08-01, states 6 of 7, 2 to know

TL;DR Dated 2026-08-01. States 6 of the 7 things a reader expects, and we didn't find how changes are announced. To know before relying on it, model training with no opt-out found and limits on benchmarking.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
incident.io may use User Content to train, tune, and improve the AI Services solely for the exclusive benefit of Customer, in order to solely make the AI Services more accurate and tailored for Customer, without requiring Customer’s separate consent.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Restricts benchmarking or competitive usecosts points
(f) access, use or view the Services for the purpose of creating a product or service that is competitive with the Services;

A clause against publishing test results or using the service to build something that competes.

Gives the date it was last updated Last updated 2026-08-01
Effective: August 1, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of England and Wales
These Terms are governed by and construed under the laws of England and Wales.

Says where a dispute would be heard and under whose law.

States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
…INDEMNIFICATION OBLIGATIONS IN SECTION 7, OR CUSTOMER’S BREACH OF THE RESTRICTIONS IN SECTION 2.9: (A) IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES OF ANY KIND WHATSOEVER, WHETHER IN CONTRACT, TORT, OR OTHERWISE, INCLUDING WITHOUT LIMITAT…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
incident.io may apply usage limits to, or suspend, API or MCP access that threatens the security, stability, or integrity of the Services.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
Customer shall not, and shall ensure its Users do not: (a) except to the extent expressly permitted by applicable law reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of the incident.io Platform;

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Go to pageTerms and ConditionsService Level AgreementData Processing AddendumSub-processorsDORA AddendumPrivacy PolicySMS TermsVulnerability Disclosure PolicyCookie Policy

Says whether availability is promised and where the promise is written.

Customers may connect agents and MCP clients through the API, and the vendor's obligations over user content stop once data is sent to such a connected system.
incident.io gives no warranty or indemnity in respect of Connected Systems, and incident.io’s obligations regarding User Content (including under the Data Processing Addendum) do not extend to data once transmitted to a Connected System at Customer’s direction.

Noted by a second reader on 2026-10-08.

The subscription renews automatically for the same length, and fees for a renewal term may rise on at least 60 days' written notice.
The Subscription Fees to be charged for any Renewal Subscription Term may be increased upon at least sixty (60) days prior written notice to Customer and will only take effect at the start of such Renewal Subscription Term.

Noted by a second reader on 2026-10-08.

Unless the order form says otherwise, incident.io may name the customer and use its logo on its websites, customer lists and marketing materials.
Customer agrees that incident.io is permitted to identify Customer as an incident.io customer, and to use Customer’s name and/or logo on incident.io’s websites, and in its customer lists and marketing materials

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 8,105 words

Privacy policy dated 2024-02-15, states 6 of 8

TL;DR Dated 2024-02-15. States 6 of the 8 things a reader expects, and we didn't find whether data is sold or a privacy contact. The rules found no clause to flag.

Gives the date it was last updated Last updated 2024-02-15
Last updated: February 15, 2024

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
Among the types of Personal Data that incident.io collects, by itself or through third parties, there are: email address;

The basic statement a privacy policy exists to make.

Says how long data is kept For as long as needed, with no period named
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.

Says when data sent to the service is deleted.

Says who else receives the data
Go to pageTerms and ConditionsService Level AgreementData Processing AddendumSub-processorsDORA AddendumPrivacy PolicySMS TermsVulnerability Disclosure PolicyCookie Policy

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact

Not found in the text.

An address or officer to send a request to.

Says where data is transferred or stored
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.If an…

The countries data goes to and the safeguard used.

The document · read 2026-10-09 · 2,293 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The site footer and the legal pages carry the copyright of Pineapple Technology Ltd. The terms are governed by the laws of England and Wales. No company number was found on the pages read.

The Terms and Conditions are effective 1 August 2026 and are served at incident.io/legal and incident.io/legal/terms. Orders before that date fall under legacy terms.

The API answers at api.incident.io and the MCP server at mcp.incident.io.

incident.io/.well-known/security.txt names security@incident.io and the vulnerability disclosure policy, and expires on 15 July 2027.

rdap.org answered 404 for incident.io, so the registration date is not recorded.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 401 · 36 ms · 2 minutes ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h42 msget
p95 24h133 msanswers, asks for auth

Probed every five minutes at https://mcp.incident.io/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 3 minutes ago
  • github incident-io/sdk-ts v2.16.0, released 2026-10-09
  • npm @incident-io/sdk 2.16.0
  • pypi incident-io 2.15.0, released 2026-10-09
  • GitHub stars 30
  • npm downloads a week 1.3k
  • PyPI downloads a week 1k

Pages we watch

PageKindLast checkedLast changed
docs.incident.io/api-reference/changelogchangelog6 hours ago · 200no change seen
incident.io/legal/privacyprivacy6 hours ago · 200no change seen
incident.io/legal/termsterms6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/incident-io.json

Notable

  • The API reference lists 284 operations on 162 paths in OpenAPI 3.0.3, with 82 smaller files by resource and version, plus files for webhooks, audit log events and deprecated endpoints source
  • A hosted MCP server at https://mcp.incident.io/mcp lists 91 tools, takes OAuth with PKCE or an API key, and is included in Team, Pro and Enterprise plans but not Basic source
  • The MCP tool status_page_update only drafts. The docs say a person publishes every status page update source
  • Deprecated /v2/actions and /v2/follow_ups endpoints carry a removal date of 31 December 2026 in their descriptions source
  • Section 2.10 of the terms of 1 August 2026 permits connecting agents and MCP clients through the APIs and makes the customer responsible for what they do source
  • The SLA commits to 99.9 per cent platform availability a month on Pro and Enterprise, and 99.99 per cent for notification triggering on Enterprise source
  • status.incident.io shows the API component at 100 per cent from July to October 2026, and the feed lists six incidents since 16 July source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence high. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 18.0
Scored as a hosted API. status.incident.io lists 43 components, API and MCP among them, with uptime from July to October 2026 (20). The API component shows 100 per cent. The feed lists six incidents since 16 July 2026, one of which broke listing alerts in the public API on 18 August until a rollback, with no duration given, and none marked as an outage of the API (20). Limits are published with numbers, 1,200 requests a minute per key and lower figures for eight endpoints (15). 429 carries Retry-After, the body recommends exponential backoff, and seven create calls require an idempotency_key (15). The SLA commits to 99.9 per cent a month on Pro and Enterprise (10). The API carries no beta label (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 14.3
OpenAPI 3.0.3 description, public at api.incident.io/v1/openapiV3.json per the docs and read from docs.incident.io/openapi/latest.json, 284 operations and 777 schemas (25). llms.txt and a Markdown twin of every docs page (10). Every operation has a description, but the median is 65 characters and few say when not to use a call. List incidents is the exception, with worked filter examples (12). 262 enums, required fields marked and two free-form objects in the whole file (13). 4,014 example values and thirteen error statuses on every operation, though the shared error example pairs an unrelated code and message (13). Versions sit in the path per resource and the changelog is generated from the description file (15).
Agent ergonomics 13%16.2 12.2
Scored for the REST API. page_size sets response size, but no field selection was found and incident objects are large. The description file is 5.4 MB, with per-resource files as the smaller route (12). Cursor pagination on 41 list operations and operator filters such as status_category[one_of] (18). Errors carry a code, a message, the field at fault and a request_id (18). idempotency_key is required on seven create calls, and updates by PUT have no key (14). Seven official SDKs and a CLI with JSON output, with idempotency_key and visibility required to create an incident (13).
Security & auth 14%17.5 11.2
Organisation keys carry chosen permissions, 13 of 36 scopable to teams, can be rotated and are shown once. User keys take the owner's role and die with the account. 30 for that, less the checklist's 10 because alert event and heartbeat endpoints accept the alert source token in a token query parameter. The API key itself travels only in the header (20). A viewer permission gives read-only keys and the MCP status page tool only drafts, but no confirmation step guards destructive API calls (15). Alert payloads and incident text are untrusted content. The docs cover redaction of sensitive data, and no injection guidance for API consumers was found (4). Audit logs are Enterprise only, kept one year, exported or streamed, and API actions are attributed to the key (10). security.txt valid to July 2027, a disclosure policy with a five-working-day reply, SOC 2 Type I and II claimed, yearly penetration tests, no paid bounty (15).
Payments & pricing 10%12.5 1.2
No x402, MPP or L402 (0). Plan prices per seat are public, Team at $19 and Pro at $25 a user a month, with no per-call price (10). The Basic plan is free, but the pricing page marks API, webhooks and MCP as not included, and the docs route trials through sales (0). A person signs up, pays and creates a key in the dashboard (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
The API changelog's newest entry is 8 October 2026 (30). 60 dated entries between 2 July and 8 October 2026 (20). A public changelog, support by email and a Slack community, with reply times not checked (10). Seven official SDKs generated from the description file, TypeScript 2.15.0 and Python 2.14.0 both tagged 8 October 2026 (15). The SDK and CLI repositories have test workflows, and the two SDKs read were first tagged in September 2026 and reached a second major version within two weeks (8).
Transparency & trusteditorial 72, provenance 79 7%8.8 6.7
Closed service under published Terms and Conditions effective 1 August 2026, with the SDKs, CLI and skills plugin under MIT (17). Privacy policy, DPA, sub-processor list and an AI data handling page are public. The terms limit training on customer content to the customer's own benefit. The security FAQ's statement that no data leaves Europe disagrees with a sub-processor list naming 17 processors in the United States, and retention is stated in general terms (20). Deprecated endpoints carry a removal date in their descriptions and the docs give integrators three months, but the changelog shows removals with no earlier entry (17). 20 sub-processors with locations and purposes, hosting regions named, 15 days' notice of changes in the DPA (18).
Negative events≤15
  • 2026-04-09, 2026-06-26 and 2026-09-30: the API changelog records the request property time_to_ack_seconds removed from POST /v2/escalation_paths, the request property version removed from POST /v2/alert_routes, and the response property layer_id removed from GET /v2/schedules, each with no earlier deprecation entry in a changelog that starts on 5 January 2026. The docs say existing endpoints get no breaking changes. Whether customers were told another way was not established, so the deduction is 2 (https://docs.incident.io/api-reference/changelog).
-2
Total68.9 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on incident.io API, or have the agent fetch /fixes/incident-io.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: incident.io API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/incident-io, the October 2026 research run, assessed 9 October 2026. Grade B, 68.9 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on incident.io API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 10 out of 100, up to 11.3 more on the total

Why it scored 10: No x402, MPP or L402 (0). Plan prices per seat are public, Team at $19 and Pro at $25 a user a month, with no per-call price (10). The Basic plan is free, but the pricing page marks API, webhooks and MCP as not included, and the docs route trials through sales (0). A person signs up, pays and creates a key in the dashboard (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 64 out of 100, up to 6.3 more on the total

Why it scored 64: Organisation keys carry chosen permissions, 13 of 36 scopable to teams, can be rotated and are shown once. User keys take the owner's role and die with the account. 30 for that, less the checklist's 10 because alert event and heartbeat endpoints accept the alert source token in a `token` query parameter. The API key itself travels only in the header (20). A `viewer` permission gives read-only keys and the MCP status page tool only drafts, but no confirmation step guards destructive API calls (15). Alert payloads and incident text are untrusted content. The docs cover redaction of sensitive data, and no injection guidance for API consumers was found (4). Audit logs are Enterprise only, kept one year, exported or streamed, and API actions are attributed to the key (10). security.txt valid to July 2027, a disclosure policy with a five-working-day reply, SOC 2 Type I and II claimed, yearly penetration tests, no paid bounty (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 75 out of 100, up to 4.1 more on the total

Why it scored 75: Scored for the REST API. `page_size` sets response size, but no field selection was found and incident objects are large. The description file is 5.4 MB, with per-resource files as the smaller route (12). Cursor pagination on 41 list operations and operator filters such as `status_category[one_of]` (18). Errors carry a code, a message, the field at fault and a `request_id` (18). `idempotency_key` is required on seven create calls, and updates by PUT have no key (14). Seven official SDKs and a CLI with JSON output, with `idempotency_key` and `visibility` required to create an incident (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Transparency & trust, 76 out of 100, up to 2.1 more on the total

Made of editorial 72, provenance 79.

Why it scored 76: Closed service under published Terms and Conditions effective 1 August 2026, with the SDKs, CLI and skills plugin under MIT (17). Privacy policy, DPA, sub-processor list and an AI data handling page are public. The terms limit training on customer content to the customer's own benefit. The security FAQ's statement that no data leaves Europe disagrees with a sub-processor list naming 17 processors in the United States, and retention is stated in general terms (20). Deprecated endpoints carry a removal date in their descriptions and the docs give integrators three months, but the changelog shows removals with no earlier entry (17). 20 sub-processors with locations and purposes, hosting regions named, 15 days' notice of changes in the DPA (18).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: incident.io, no registry record we could read (0 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)

## 5. Reliability, 90 out of 100, up to 2 more on the total

Why it scored 90: Scored as a hosted API. status.incident.io lists 43 components, API and MCP among them, with uptime from July to October 2026 (20). The API component shows 100 per cent. The feed lists six incidents since 16 July 2026, one of which broke listing alerts in the public API on 18 August until a rollback, with no duration given, and none marked as an outage of the API (20). Limits are published with numbers, 1,200 requests a minute per key and lower figures for eight endpoints (15). 429 carries `Retry-After`, the body recommends exponential backoff, and seven create calls require an `idempotency_key` (15). The SLA commits to 99.9 per cent a month on Pro and Enterprise (10). The API carries no beta label (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Schema & documentation, 88 out of 100, up to 2 more on the total

Why it scored 88: OpenAPI 3.0.3 description, public at api.incident.io/v1/openapiV3.json per the docs and read from docs.incident.io/openapi/latest.json, 284 operations and 777 schemas (25). llms.txt and a Markdown twin of every docs page (10). Every operation has a description, but the median is 65 characters and few say when not to use a call. List incidents is the exception, with worked filter examples (12). 262 enums, required fields marked and two free-form objects in the whole file (13). 4,014 example values and thirteen error statuses on every operation, though the shared error example pairs an unrelated code and message (13). Versions sit in the path per resource and the changelog is generated from the description file (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 7. Maintenance & community, 83 out of 100, up to 1.5 more on the total

Why it scored 83: The API changelog's newest entry is 8 October 2026 (30). 60 dated entries between 2 July and 8 October 2026 (20). A public changelog, support by email and a Slack community, with reply times not checked (10). Seven official SDKs generated from the description file, TypeScript 2.15.0 and Python 2.14.0 both tagged 8 October 2026 (15). The SDK and CLI repositories have test workflows, and the two SDKs read were first tagged in September 2026 and reached a second major version within two weeks (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 2026-04-09, 2026-06-26 and 2026-09-30: the API changelog records the request property `time_to_ack_seconds` removed from `POST /v2/escalation_paths`, the request property `version` removed from `POST /v2/alert_routes`, and the response property `layer_id` removed from `GET /v2/schedules`, each with no earlier deprecation entry in a changelog that starts on 5 January 2026. The docs say existing endpoints get no breaking changes. Whether customers were told another way was not established, so the deduction is 2 (https://docs.incident.io/api-reference/changelog).

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- The lead said incident.io has no MCP server. The docs describe a hosted one at https://mcp.incident.io/mcp with 91 tools. This listing grades the REST API and records the MCP server as a second surface.
- unchecked: the MCP tool schemas and annotations, which are only available through tools/list with an account
- unchecked: trust.incident.io, which is drawn by script, so the SOC 2 claim rests on the security page and the security FAQ
- unchecked: the domain registration date, because rdap.org answered 404 for incident.io
- unchecked: PyPI download figures, because PyPI's robots.txt disallows `/pypi/`
- unchecked: whether a Team trial exists without a card. The terms define a 14-day trial and the docs mention trials only for Pro and Enterprise through sales
- The Team price shows as $19 with a second figure of $15 beside an annual discount switch. We read $15 as the yearly-billed price
- Whether the three removals in the changelog were announced to customers by another route was not established
- The Go, Rust, Ruby, PHP and .NET SDK repositories were not read

## Weaknesses

- The pricing page marks API, webhooks and MCP as not included in the free Basic plan. Team starts at $19 per user a month
- Audit logs are Enterprise only and reach the customer by CSV export or log stream, with no API to read them
- Alert event and heartbeat endpoints accept the alert source token in a `token` query parameter
- The changelog records three removals from live endpoints in 2026 with no earlier deprecation entry
- The security FAQ says no data leaves Europe, while the sub-processor list of 27 July 2026 names 17 processors in the United States

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send `Authorization: Bearer <key>` to https://api.incident.io and call `GET /v1/identity` first to read the key's roles
- Send a fresh `idempotency_key` with every create call for incidents, incident updates, timeline items, escalations and status page incidents. A repeated key returns the first result
- Page with `page_size` and `after` until no cursor comes back. Do not stop at a short or empty page
- Keep `GET /v2/incidents` under 60 requests a minute and wait the seconds in `Retry-After` on 429
- Incident creation is limited to 10 an hour per key when a Slack or Teams channel is created, 300 an hour otherwise

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • The lead said incident.io has no MCP server. The docs describe a hosted one at https://mcp.incident.io/mcp with 91 tools. This listing grades the REST API and records the MCP server as a second surface.
  • unchecked: the MCP tool schemas and annotations, which are only available through tools/list with an account
  • unchecked: trust.incident.io, which is drawn by script, so the SOC 2 claim rests on the security page and the security FAQ
  • unchecked: the domain registration date, because rdap.org answered 404 for incident.io
  • unchecked: PyPI download figures, because PyPI's robots.txt disallows /pypi/
  • unchecked: whether a Team trial exists without a card. The terms define a 14-day trial and the docs mention trials only for Pro and Enterprise through sales
  • The Team price shows as $19 with a second figure of $15 beside an annual discount switch. We read $15 as the yearly-billed price
  • Whether the three removals in the changelog were announced to customers by another route was not established
  • The Go, Rust, Ruby, PHP and .NET SDK repositories were not read

Sources 29

  1. API introduction with authentication, rate limits, pagination, errors and compatibility docs.incident.io · seen 2026-10-09
  2. OpenAPI description file, read in place of the rendered reference pages docs.incident.io · seen 2026-10-09
  3. deprecated endpoints description file docs.incident.io · seen 2026-10-09
  4. API changelog docs.incident.io · seen 2026-10-09
  5. docs index for agents docs.incident.io · seen 2026-10-09
  6. API key permissions docs.incident.io · seen 2026-10-09
  7. user API keys docs.incident.io · seen 2026-10-09
  8. remote MCP server, tool table and plans docs.incident.io · seen 2026-10-09
  9. SDK overview and versioning docs.incident.io · seen 2026-10-09
  10. CLI docs docs.incident.io · seen 2026-10-09
  11. audit logs docs.incident.io · seen 2026-10-09
  12. security FAQ with hosting regions docs.incident.io · seen 2026-10-09
  13. AI data handling docs.incident.io · seen 2026-10-09
  14. billing and plan changes docs.incident.io · seen 2026-10-09
  15. pricing and plan comparison incident.io · seen 2026-10-09
  16. Terms and Conditions, effective 1 August 2026 incident.io · seen 2026-10-09
  17. Service Level Agreement incident.io · seen 2026-10-09
  18. sub-processors, effective 27 July 2026 incident.io · seen 2026-10-09
  19. privacy policy incident.io · seen 2026-10-09
  20. Data Processing Addendum incident.io · seen 2026-10-09
  21. vulnerability disclosure policy incident.io · seen 2026-10-09
  22. security page incident.io · seen 2026-10-09
  23. security.txt incident.io · seen 2026-10-09
  24. status page components and uptime status.incident.io · seen 2026-10-09
  25. status incident feed status.incident.io · seen 2026-10-09
  26. TypeScript SDK repository, tags and README (shallow clone) github.com · seen 2026-10-09
  27. Python SDK repository, tags (shallow clone) github.com · seen 2026-10-09
  28. CLI repository, tags (shallow clone) github.com · seen 2026-10-09
  29. npm weekly downloads for @incident-io/sdk api.npmjs.org · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid $19 / seat-mo API, webhooks and MCP are not included in the free Basic plan. Team is $19 per user a month for incident response ($15 with the annual discount) plus $10 for on-call. Pro is $25 plus $20 for on-call, billed yearly through sales. Enterprise is quoted. API calls are not metered. The terms define a 14-day trial, which the docs say sales sets up for Pro and Enterprise. No sandbox below Enterprise (checked 2026-10-09).

Prices

ItemPriceUnitNote
Team plan, incident response$19per seat per month$15 with the annual discount. On-call adds $10
Pro plan, incident response$25per seat per monthbilled yearly through sales. On-call adds $20
On-call only$20per seat per monthsold through sales

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/incident-io.xml, or this listing's score history at history.json.

Connect

Install

npm install @incident-io/sdk

First request

curl --request GET https://api.incident.io/v1/identity --header 'Authorization: Bearer <YOUR_API_KEY>'

Claude Code

claude mcp add incident-io --transport http https://mcp.incident.io/mcp

Through letme picks today, calling later

GET https://letme.dev/incident-io

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Grafana MCP Server Grafana LabsBB74.5observability.incidents work.oncallno
Rootly MCP Server Rootly Inc.C59.7observability.incidents work.oncallno
PagerDuty MCP Server PagerDutyD48.4observability.incidents work.oncallno
Datadog MCP Server DatadogC56.6observability.incidentsno
Sentry MCP SentryBB70.2same categoryno
Honeycomb MCP HoneycombC58.3same categoryno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    incident.io API on Anchor Terminal, B, 68.9/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/incident-io"><img src="https://www.anchorterminal.com/badges/incident-io.svg" alt="incident.io API on Anchor Terminal" height="20"></a>
    [![incident.io API on Anchor Terminal](https://www.anchorterminal.com/badges/incident-io.svg)](https://www.anchorterminal.com/tools/incident-io)

    It counts on a page on incident.io or one of its subdomains, or the README of github.com/incident-io/sdk-ts.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "incident-io", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.