# incident.io API (slim) > incident.io is an incident response, on-call, alerting and status page service. Agents reach it through a REST API at api.incident.io with an OpenAPI description and seven SDKs, a hosted MCP server and the inc CLI. - Full: https://www.anchorterminal.com/tools/incident-io.md (~7,600 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/incident-io.json · canonical https://www.anchorterminal.com/tools/incident-io - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **B · 68.9/100 · rank #204 of 950 · #3 in Observability & incidents · not agent-ready · confidence high** Assessment: The REST API has a public OpenAPI description with 284 operations, numeric rate limits, `Retry-After` on 429 and required idempotency keys on seven create calls. API and MCP access need the Team plan or higher, so the free Basic plan cannot be used by an agent, and audit logs are Enterprise only. ## Facts - Kind: HTTP API · vendor: Pineapple Technology Ltd. (incident.io) · category: Observability & incidents · legal entity: Pineapple Technology Ltd. · provenance 79/100 - Endpoint: `https://mcp.incident.io/mcp` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under incident.io's Terms and Conditions. The SDKs, the `inc` CLI and the skills plugin on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.incident.io, OpenAPI 3.0.3 with 284 operations on 162 paths (126 GET, 79 POST, 40 PUT, 38 DELETE, 1 PATCH). Versions are per resource in the path, such as `/v2/incidents` and `/v3/catalog_entries` - Coverage: Incidents, updates, timeline items, alerts, alert sources and routes, escalations and escalation paths, schedules and overrides, catalogue, status pages, workflows, post-mortem documents, follow-ups, users, teams, API keys and telemetry data sources - MCP server: Hosted at https://mcp.incident.io/mcp with 91 tools in the docs table. OAuth with PKCE for people (the grant lasts 28 days) or an API key for automation. An admin enables it in settings. Team, Pro and Enterprise only - Credentials: Organisation API keys with chosen permissions, 13 of which can be limited to named teams, and user API keys that take the owner's current role. Bearer header. Keys do not expire. A user key pushed to a public GitHub repository is deleted automatically - Rate limits: 1,200 requests a minute per key. List incidents 60 a minute, update catalogue entry 300 a minute, bulk catalogue update 60 a minute. Incident creation 10 an hour with a chat channel, 300 an hour without - Errors: JSON with `type`, `status`, `request_id` and an `errors` list of `code`, `message` and `source.field`. 429 carries `Retry-After` in seconds and a `rate_limit` object - Pagination: Cursor, `page_size` (default 25, maximum set per endpoint, 250 for incidents) and `after`, on 41 list operations. Configuration lists return everything in one response - Idempotency: `idempotency_key` is a required body field on create calls for incidents, incident updates, timeline items, escalations, status page incidents, maintenances and retrospective incidents - SDKs: Go, TypeScript (`@incident-io/sdk` 2.15.0), Python (`incident-io` 2.14.0, Python 3.11 or later), Rust, Ruby, PHP and .NET, generated from the OpenAPI description, MIT. Terraform and Pulumi providers - CLI: `inc`, MIT, v0.4.25 on 9 October 2026. JSON output, `inc describe` for a schema of every command, `--dry-run`, and `inc api` for any endpoint - Compatibility: The docs promise no breaking changes to existing endpoints, a new path version when one is needed, and three months for integrators to move off a deprecated endpoint - Audit: Audit logs on Enterprise only, kept one year, by CSV export or log stream to a SIEM. API actions are attributed to the key, or to the person for a user key - Hosting: Google Cloud, europe-west1 (Belgium) with a standby in europe-west4 (Netherlands), per the security FAQ. 20 sub-processors listed on 27 July 2026, 17 in the United States - Certifications: SOC 2 Type I and II and GDPR compliance claimed on incident.io/security, with yearly third-party penetration tests. The trust centre was not read - Status: status.incident.io with 43 components, among them API and MCP, with uptime from July to October 2026 and Atom and RSS feeds - Prices: Team plan, incident response $19 per seat per month; Pro plan, incident response $25 per seat per month; On-call only $20 per seat per month - Scores: Reliability 90, Performance pending, Schema & documentation 88, Agent ergonomics 75, Security & auth 64, Payments & pricing 10, Task success pending, Maintenance & community 83, Transparency & trust 76 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Scored as a hosted API. · Schema & documentation, OpenAPI 3.0.3 description, public at api.incident.io/v1/openapiV3.json per the docs and read from docs.incident.io/openapi/latest.json, 284… · Agent ergonomics, Scored for the REST API. · Security & auth, Organisation keys carry chosen permissions, 13 of 36 scopable to teams, can be rotated and are shown once. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The API changelog's newest entry is 8 October 2026 (30). · Transparency & trust, Closed service under published Terms and Conditions effective 1 August 2026, with the SDKs, CLI and skills plugin under MIT (17). - Sources: 29, open questions: 9, both in the full twin - Capabilities: observability.incidents, work.oncall - JSON: https://www.anchorterminal.com/api/v1/tools/incident-io.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/incident-io.svg` or a link to https://www.anchorterminal.com/tools/incident-io from a page on incident.io or one of its subdomains, or the README of github.com/incident-io/sdk-ts, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Authorization: Bearer ` to https://api.incident.io and call `GET /v1/identity` first to read the key's roles 2. Send a fresh `idempotency_key` with every create call for incidents, incident updates, timeline items, escalations and status page incidents. A repeated key returns the first result 3. Page with `page_size` and `after` until no cursor comes back. Do not stop at a short or empty page 4. Keep `GET /v2/incidents` under 60 requests a minute and wait the seconds in `Retry-After` on 429 5. Incident creation is limited to 10 an hour per key when a Slack or Teams channel is created, 300 an hour otherwise ## Connect ```bash npm install @incident-io/sdk ``` ```bash curl --request GET https://api.incident.io/v1/identity --header 'Authorization: Bearer ' ``` ```bash claude mcp add incident-io --transport http https://mcp.incident.io/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/incident-io ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Grafana MCP Server | BB | 74.5 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/grafana-mcp-server.min.md | | Rootly MCP Server | C | 59.7 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/rootly-mcp.min.md | | PagerDuty MCP Server | D | 48.4 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/pagerduty-mcp.min.md | | Datadog MCP Server | C | 56.6 | observability.incidents | https://www.anchorterminal.com/tools/datadog-mcp.min.md | | Sentry MCP | BB | 70.2 | same category | https://www.anchorterminal.com/tools/sentry-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)