API documentation
The API is available on plans with API access. Create a key in Settings > API. The OpenAPI 3.1 document is at /api/v1/openapi.json.
Authentication
Bearer API keys. A key has a public prefix and a secret that is shown once and stored only as a hash. Keys are read-only or read-write, can be revoked, and show their last use.
Authorization: Bearer <key>Limits by plan
Limits apply per account, not only per key. Exceeding them returns 429 with Retry-After and X-RateLimit-* headers.
| Plan | Requests / min | Requests / day | API keys | Webhooks / min |
|---|---|---|---|---|
| pro | 45 | 9,000 | 2 | 35 |
| business | 75 | 27,000 | 5 | 75 |
| scale | 350 | 200,000 | 20 | 325 |
Endpoints
| Method | Path | Key access | What it does |
|---|---|---|---|
| GET | /api/v1/account | read | Plan, limits and API quota of the account behind the key |
| GET | /api/v1/sites | read | List sites (cursor pagination) |
| GET | /api/v1/sites/status | read | The status of all sites in one call (cheap; supports ETag) |
| POST | /api/v1/sites | write | Add a site (it must be verified before monitoring starts) |
| POST | /api/v1/sites/batch | write | Add up to 20 sites at once; every item succeeds or fails on its own |
| GET | /api/v1/sites/{id} | read | One site |
| DELETE | /api/v1/sites/{id} | write | Delete a site and its history |
| POST | /api/v1/sites/{id}/pause | write | Pause monitoring of a site |
| POST | /api/v1/sites/{id}/resume | write | Resume monitoring of a paused site |
| POST | /api/v1/sites/{id}/verify | write | Queue an ownership verification attempt |
| POST | /api/v1/sites/{id}/check | write | Queue an immediate check |
| POST | /api/v1/sites/{id}/crawl | write | Queue a full crawl (counts against the monthly crawl quota) |
| GET | /api/v1/sites/{id}/checks | read | Check history of a site, newest first (cursor pagination) |
| GET | /api/v1/incidents | read | Incidents, newest first (cursor pagination) |
| POST | /api/v1/incidents/{id}/acknowledge | write | Acknowledge an open incident (stops escalation rules) |
| GET | /api/v1/feeds | read | Product feeds |
| GET | /api/v1/servers | read | Servers |
| GET | /api/v1/maintenance | read | Planned maintenance windows |
| POST | /api/v1/maintenance | write | Plan a maintenance window (no alerts during it) |
| DELETE | /api/v1/maintenance/{id} | write | Cancel a maintenance window |
| GET | /api/v1/webhooks | read | Webhook subscriptions |
| POST | /api/v1/webhooks | write | Subscribe an HTTPS endpoint to events. The signing secret is returned once. |
| DELETE | /api/v1/webhooks/{id} | write | Delete a webhook subscription |
| POST | /api/v1/webhooks/{id}/test | write | Send a test event to one subscription |
| GET | /api/v1/webhooks/{id}/deliveries | read | Recent deliveries of a subscription |
| POST | /api/v1/webhooks/deliveries/{id}/retry | write | Retry a failed or abandoned delivery |
Webhooks
Events: site.down, site.up, ssl.expiring, domain.expiring, feed.broken, page.broken, crawl.finished, maintenance.started, maintenance.ended, server.down, server.up. Each delivery carries an event id, a timestamp and an HMAC-SHA256 signature made with your subscription secret. Retries after 1 min, 5 min, 30 min, 2 h and 12 h; after 3 days of failures the subscription is switched off. Only https URLs are accepted, redirects are not followed, and your endpoint must answer within 5 seconds.
Verifying a signature
Illustrative pseudocode — final header names will be published with the API.
expected = HMAC_SHA256(secret, timestamp + "." + rawBody)
reject if |now - timestamp| > 5 minutes
accept if constant_time_equals(expected, signature)