# Add a note to an alert

`POST https://evohub.io/api/v1/alerts/{id}/events`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `addAlertNote`.

Adds a note to the alert's timeline. It does not change the alert's status.

**Permission (API-key scope):** `oncall:alert:respond`.

## Authorization

Any one of:

- `bearerAuth` (oncall:alert:respond)
- `apiKeyHeader` (oncall:alert:respond)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required, example `9d4e2f1a-6b3c-4d8e-a7f9-0c1b2a3d4e5f`): The alert's id.

## Request body (required)

Content type: `application/json`

Type: `object`

- `message` (string, required): The note.

## Responses

### 201 — The note as stored.

Content type: `application/json`

Type: `object`

- `data` (AlertEvent, required)
  - `id` (string)
  - `alert_id` (string)
  - `event_type` (string, one of `created`, `acknowledged`, `resolved`, `reopened`, `note_added`, `snoozed`, `assigned`, `taken_over`, `suppressed`, `voice_call_sent`, `sms_sent`, `email_sent`, `push_sent`, `call_not_answered`, `manual_escalation`, `retriggered`, `redirected`, `not_routed`, `notification_blocked`, `notification_suppressed`, `ack_timed_out`)
  - `actor_id` (string): Who did it; empty for EvoHub itself.
  - `note` (string)
  - `metadata` (object | null): Details that depend on the event type.
    - Other keys: any
  - `created_at` (string (date-time))
- `success` (boolean, required, value `true`)

### 400 — The body is not JSON (`INVALID_BODY`) or `message` is empty (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — No alert with this id in your organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/alerts/9d4e2f1a-6b3c-4d8e-a7f9-0c1b2a3d4e5f/events' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "message": "Restarting the payments pods."
}'
```
