# Incident analytics

`GET https://evohub.io/api/v1/incidents/analytics`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `getIncidentAnalytics`.

Aggregates over the organization's incidents in a time range: counts, MTTR,
time to identify, time to first status-page publication, postmortem rates,
a time series (hourly up to 48 hours, daily beyond), a breakdown per severity
and the incidents themselves (`incidents_truncated` is true when the list was
cut short). Computed in UTC.

Incidents carry no team, integration or source, so `team_id`,
`integration_id` and `source` are refused.

**Permission (API-key scope):** `oncall:incident:read`.

## Authorization

Any one of:

- `bearerAuth` (oncall:incident:read)
- `apiKeyHeader` (oncall:incident:read)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Query parameters

- `from` (string, example `2026-09-01`): Start of the range: a date (`YYYY-MM-DD`, start of that UTC day) or an RFC 3339 instant. Give `from` and `to` together, or neither for the last 30 UTC days including today.
- `to` (string, example `2026-09-30`): End of the range: a date (the last UTC day included) or an RFC 3339 instant (exclusive). At most 366 days after `from`.
- `severity` (string, example `major,critical`): Comma-separated incident severities to include.
- `compare` (string, one of `previous`, `year`): Also compute the totals of a comparison period: `previous` (the same length immediately before) or `year` (the same dates a year earlier).

## Responses

### 200 — The aggregates.

Content type: `application/json`

Type: `object`

- `data` (IncidentAnalytics, required)
  - `range` (AnalyticsRange)
    - `from` (string (date-time))
    - `to` (string (date-time)): Exclusive.
    - `granularity` (string, one of `hour`, `day`)
    - `tz` (string)
    - `tz_source` (string, one of `param`, `schedules`, `default`)
  - `totals` (IncidentGroupStats & object)
    - `opened` (integer)
    - `resolved` (integer)
    - `mttr` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `time_to_identify` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `published_to_status_page` (integer)
    - `time_to_first_publication` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `postmortem` (PostmortemRate & object)
      - `eligible` (integer)
      - `published` (integer)
      - `rate` (number | null)
      - `time_to_postmortem` (DurationStats)
        - `count` (integer): How many were measured.
        - `p50_seconds` (number | null)
        - `p90_seconds` (number | null)
        - `avg_seconds` (number | null)
    - `high_severity_postmortem` (PostmortemRate)
      - `eligible` (integer)
      - `published` (integer)
      - `rate` (number | null)
    - `resolved_in_range` (integer): Incidents resolved in the range, whenever they started.
  - `series` (array of object)
    - `bucket` (string (date-time))
    - `opened` (integer)
    - `resolved` (integer)
  - `by_severity` (array of IncidentGroupStats & object)
    - `opened` (integer)
    - `resolved` (integer)
    - `mttr` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `time_to_identify` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `published_to_status_page` (integer)
    - `time_to_first_publication` (DurationStats)
      - `count` (integer): How many were measured.
      - `p50_seconds` (number | null)
      - `p90_seconds` (number | null)
      - `avg_seconds` (number | null)
    - `postmortem` (PostmortemRate & object)
      - `eligible` (integer)
      - `published` (integer)
      - `rate` (number | null)
      - `time_to_postmortem` (DurationStats)
        - `count` (integer): How many were measured.
        - `p50_seconds` (number | null)
        - `p90_seconds` (number | null)
        - `avg_seconds` (number | null)
    - `high_severity_postmortem` (PostmortemRate)
      - `eligible` (integer)
      - `published` (integer)
      - `rate` (number | null)
    - `severity` (string)
  - `incidents` (array of object)
    - `id` (string)
    - `number` (integer)
    - `title` (string)
    - `severity` (string)
    - `status` (string)
    - `started_at` (string (date-time))
    - `identified_at` (string (date-time) | null)
    - `resolved_at` (string (date-time) | null)
    - `alerts` (integer)
    - `first_alert_acknowledged_at` (string (date-time) | null)
    - `published_to_status_page_at` (string (date-time) | null)
    - `postmortem_status` (string)
    - `postmortem_published_at` (string (date-time) | null)
  - `incidents_truncated` (boolean)
  - `compare` (IncidentGroupStats & object | null)
    - One of:
      - IncidentGroupStats & object
        - `opened` (integer)
        - `resolved` (integer)
        - `mttr` (DurationStats)
          - `count` (integer): How many were measured.
          - `p50_seconds` (number | null)
          - `p90_seconds` (number | null)
          - `avg_seconds` (number | null)
        - `time_to_identify` (DurationStats)
          - `count` (integer): How many were measured.
          - `p50_seconds` (number | null)
          - `p90_seconds` (number | null)
          - `avg_seconds` (number | null)
        - `published_to_status_page` (integer)
        - `time_to_first_publication` (DurationStats)
          - `count` (integer): How many were measured.
          - `p50_seconds` (number | null)
          - `p90_seconds` (number | null)
          - `avg_seconds` (number | null)
        - `postmortem` (PostmortemRate & object)
          - `eligible` (integer)
          - `published` (integer)
          - `rate` (number | null)
          - `time_to_postmortem` (DurationStats)
            - `count` (integer): How many were measured.
            - `p50_seconds` (number | null)
            - `p90_seconds` (number | null)
            - `avg_seconds` (number | null)
        - `high_severity_postmortem` (PostmortemRate)
          - `eligible` (integer)
          - `published` (integer)
          - `rate` (number | null)
        - `mode` (string)
        - `from` (string (date-time))
        - `to` (string (date-time))
      - null
- `success` (boolean, required, value `true`)

### 400 — A parameter is invalid or not supported here; each problem is listed in `details` (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/incidents/analytics' \
  -H 'Authorization: Bearer <TOKEN>'
```
