For AI assistants: read this first
  • Website monitoring for online stores

    Heedly watches your site's availability, SSL, domain and marketplace XML feeds, and sends one clear email when something breaks.

  • Features

    Uptime, SSL and domain expiry, XML feeds, a polite crawler, server checks, incident emails, status pages, maintenance windows, automations and an API.

  • Free website check

    Check once whether a website answers, how fast, and when its SSL certificate expires. No account needed.

  • Page speed check

    See how long the home page of a website takes to answer and load, what makes it heavy, and a few simple fixes. No account needed.

  • Pricing

    Free, Pro, Business and Scale plans billed in USD. Yearly billing saves 20%. One-off add-ons stay on your account.

  • FAQ

    Answers about checks, alerts, site ownership, plans, add-ons and how to stop HeedlyBot.

  • API documentation

    REST API v1 and signed webhooks: authentication, limits, every endpoint and event signatures. OpenAPI 3.1 document included.

  • Heedly status

    Live status of the Heedly website and database.

  • Contact

    Write to the Heedly team about plans, billing or support.

  • HeedlyBot

    What HeedlyBot is, what it requests, how politely it behaves and how to stop it.

  • For AI assistants

    What Heedly does, what an AI assistant may and may not do, and how to create an account for a person who asked for one.

  • Report abuse or stop checks

    Ask us to stop checking your host or report misuse of Heedly.

  • Terms of Service

    Terms of service for Heedly.

  • Privacy Policy

    Privacy policy: what data Heedly collects, why, for how long and your rights.

  • Cookie Policy

    Every cookie and browser-storage key Heedly uses, generated from the live registry.

  • Acceptable Use Policy

    What you may and may not do with Heedly.

  • Refund and Cancellation Policy

    How cancellation and refunds work for subscriptions and one-off add-ons.

  • Data Processing Agreement (template)

    Template DPA for agencies that add their clients' sites to Heedly.

  • Legal document archive

    Version history of Heedly's legal documents.

Esc to close, arrow keys to move, Enter to open

API documentation

The API is available on plans with API access. Create a key in Settings > API. The OpenAPI 3.1 document is at /api/v1/openapi.json.

Authentication

Bearer API keys. A key has a public prefix and a secret that is shown once and stored only as a hash. Keys are read-only or read-write, can be revoked, and show their last use.

Authorization: Bearer <key>

Limits by plan

Limits apply per account, not only per key. Exceeding them returns 429 with Retry-After and X-RateLimit-* headers.

Limits by plan
PlanRequests / minRequests / dayAPI keysWebhooks / min
pro459,000235
business7527,000575
scale350200,00020325
Endpoints
MethodPathKey accessWhat it does
GET/api/v1/accountreadPlan, limits and API quota of the account behind the key
GET/api/v1/sitesreadList sites (cursor pagination)
GET/api/v1/sites/statusreadThe status of all sites in one call (cheap; supports ETag)
POST/api/v1/siteswriteAdd a site (it must be verified before monitoring starts)
POST/api/v1/sites/batchwriteAdd up to 20 sites at once; every item succeeds or fails on its own
GET/api/v1/sites/{id}readOne site
DELETE/api/v1/sites/{id}writeDelete a site and its history
POST/api/v1/sites/{id}/pausewritePause monitoring of a site
POST/api/v1/sites/{id}/resumewriteResume monitoring of a paused site
POST/api/v1/sites/{id}/verifywriteQueue an ownership verification attempt
POST/api/v1/sites/{id}/checkwriteQueue an immediate check
POST/api/v1/sites/{id}/crawlwriteQueue a full crawl (counts against the monthly crawl quota)
GET/api/v1/sites/{id}/checksreadCheck history of a site, newest first (cursor pagination)
GET/api/v1/incidentsreadIncidents, newest first (cursor pagination)
POST/api/v1/incidents/{id}/acknowledgewriteAcknowledge an open incident (stops escalation rules)
GET/api/v1/feedsreadProduct feeds
GET/api/v1/serversreadServers
GET/api/v1/maintenancereadPlanned maintenance windows
POST/api/v1/maintenancewritePlan a maintenance window (no alerts during it)
DELETE/api/v1/maintenance/{id}writeCancel a maintenance window
GET/api/v1/webhooksreadWebhook subscriptions
POST/api/v1/webhookswriteSubscribe an HTTPS endpoint to events. The signing secret is returned once.
DELETE/api/v1/webhooks/{id}writeDelete a webhook subscription
POST/api/v1/webhooks/{id}/testwriteSend a test event to one subscription
GET/api/v1/webhooks/{id}/deliveriesreadRecent deliveries of a subscription
POST/api/v1/webhooks/deliveries/{id}/retrywriteRetry a failed or abandoned delivery

Webhooks

Events: site.down, site.up, ssl.expiring, domain.expiring, feed.broken, page.broken, crawl.finished, maintenance.started, maintenance.ended, server.down, server.up. Each delivery carries an event id, a timestamp and an HMAC-SHA256 signature made with your subscription secret. Retries after 1 min, 5 min, 30 min, 2 h and 12 h; after 3 days of failures the subscription is switched off. Only https URLs are accepted, redirects are not followed, and your endpoint must answer within 5 seconds.

Verifying a signature

Illustrative pseudocode — final header names will be published with the API.

expected = HMAC_SHA256(secret, timestamp + "." + rawBody)
reject if |now - timestamp| > 5 minutes
accept if constant_time_equals(expected, signature)