# List alerts

`GET https://evohub.io/api/v1/alerts`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `listAlerts`.

Lists the organization's alerts, newest first unless `sort` says otherwise.
The list is paged: `limit` (default 50) and `offset`, with the number of
matching alerts in `meta.total`. Every filter is optional and they combine.

`team_id` narrows the list, it never hides anything you could otherwise see:
a team id returns that team's alerts together with the organization-wide ones
(alerts with no team), and `none` returns only the organization-wide ones.

**Permission (API-key scope):** `oncall:alert:read`.

## Authorization

Any one of:

- `bearerAuth` (oncall:alert:read)
- `apiKeyHeader` (oncall:alert:read)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Query parameters

- `status` (string, one of `triggered`, `acknowledged`, `resolved`, `suppressed`, `open`, example `open`): `triggered`, `acknowledged`, `resolved`, `suppressed`, or `open` for triggered and acknowledged together.
- `severity` (AlertSeverity, one of `critical`, `high`, `medium`, `low`, `info`): One severity.
- `source` (string, example `prometheus`): The kind of integration or origin, for example `prometheus` or `manual`.
- `q` (string): Free-text search over the title, source and label values (case-insensitive, partial match).
- `assignee` (string, example `me`): A user id, `me` for the caller, or `unassigned`.
- `escalation_policy_id` (string): Only alerts routed to this escalation policy.
- `integration_id` (string): Only alerts opened by this integration.
- `team_id` (string): A team id (that team's alerts plus organization-wide ones) or `none` (organization-wide alerts only).
- `created_from` (string, example `2026-10-01`): Earliest creation time, inclusive: RFC 3339, or a date (`YYYY-MM-DD`, start of the UTC day). An unreadable value is ignored.
- `created_to` (string, example `2026-10-09`): Latest creation time, inclusive: RFC 3339, or a date (`YYYY-MM-DD`, the whole UTC day). An unreadable value is ignored.
- `sort` (string, one of `created_at`, `updated_at`, `severity`, `status`, `source`, `assigned_to`, `title`, default `created_at`): Column to sort by.
- `dir` (string, one of `asc`, `desc`, default `desc`): Sort direction. Empty values sort last either way.
- `limit` (integer, default `50`, min 0): Page size. 0 or omitted means 50.
- `offset` (integer, default `0`, min 0): How many items to skip.

## Responses

### 200 — A page of alerts.

Content type: `application/json`

Type: `object`

- `data` (array of Alert, required)
  - `id` (string, required)
  - `org_id` (string, required)
  - `team_id` (string): Owning team; empty for an organization-wide alert.
  - `escalation_policy_id` (string): Empty when no policy pages for it.
  - `incident_id` (string)
  - `integration_id` (string): The integration that opened it; empty for alerts raised by hand or by another EvoHub product.
  - `fingerprint` (string): Deduplication key: while an alert with it is open, the same fingerprint retriggers it instead of opening another.
  - `title` (string, required)
  - `description` (string)
  - `severity` (AlertSeverity, required, one of `critical`, `high`, `medium`, `low`, `info`)
  - `status` (AlertStatus, required, one of `triggered`, `acknowledged`, `resolved`, `suppressed`)
  - `source` (string, required): Where it came from: an integration kind such as `prometheus`, `api`, `webhook`, or `manual`.
  - `labels` (object)
    - Other keys: string
  - `annotations` (object)
    - Other keys: string
  - `current_escalation_step` (integer): The escalation step reached so far.
  - `acknowledged_by` (string)
  - `acknowledged_at` (string (date-time))
  - `resolved_by` (string)
  - `resolved_at` (string (date-time))
  - `snoozed_until` (string (date-time))
  - `snoozed_by` (string)
  - `assigned_to` (string): User id of the assignee; empty when unassigned.
  - `notification_count` (integer)
  - `retrigger_count` (integer): How many times the same fingerprint arrived again while it was open.
  - `created_at` (string (date-time), required)
  - `updated_at` (string (date-time), required)
- `success` (boolean, required, value `true`)
- `meta` (object, required)
  - `total` (integer): Alerts matching the filters, ignoring the page.

### 400 — `sort` names a column that cannot be sorted on, or `dir` is not `asc` or `desc` (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/alerts' \
  -H 'Authorization: Bearer <TOKEN>'
```
