# Run a Teams action link

`POST https://evohub.io/api/v1/chat/actions/{token}`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `runChatAction`.

Takes the link's action on the alert as the caller and notes it on the
alert's timeline. Each link works once. `result` is `done`, or `already` when
the alert was already in that state. No request body.

**Permission (API-key scope):** `oncall:alert:respond`.

## Authorization

Any one of:

- `bearerAuth` (oncall:alert:respond)
- `apiKeyHeader` (oncall:alert:respond)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `token` (string, required): The signed token from the action link on a Microsoft Teams card.

## Responses

### 200 — The outcome.

Content type: `application/json`

Type: `object`

- `data` (ChatActionResult, required)
  - `action` (string, one of `ack`, `resolve`, `takeover`)
  - `result` (string, one of `done`, `already`)
  - `alert` (ActionAlert)
    - `id` (string)
    - `title` (string)
    - `status` (AlertStatus, one of `triggered`, `acknowledged`, `resolved`, `suppressed`)
    - `severity` (AlertSeverity, one of `critical`, `high`, `medium`, `low`, `info`)
- `success` (boolean, required, value `true`)

### 400 — The link is invalid or has expired (`INVALID_ACTION_LINK`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The caller lacks the permission (`FORBIDDEN`), the link belongs to another organization (`WRONG_ORG`), or the alert belongs to a team the caller is not in and is not assigned to them (`NOT_IN_TEAM`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — No alert with this id in your organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 409 — The link was already used (`ACTION_LINK_USED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/chat/actions/string' \
  -H 'Authorization: Bearer <TOKEN>'
```
