# Take over an alert

`POST https://evohub.io/api/v1/alerts/{id}/takeover`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `takeOverAlert`.

"I've got this": assigns the alert to the caller and, when it is still
triggered, acknowledges it. The escalation stops. The previous assignee is
recorded on the alert's timeline. With an organization API key the key itself
becomes the assignee. No request body.

**Permission (API-key scope):** `oncall:alert:respond`.

## Authorization

Any one of:

- `bearerAuth` (oncall:alert:respond)
- `apiKeyHeader` (oncall:alert:respond)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required, example `9d4e2f1a-6b3c-4d8e-a7f9-0c1b2a3d4e5f`): The alert's id.

## Responses

### 200 — The alert after the change.

Content type: `application/json`

Type: `object`

- `data` (Alert, required)
  - `id` (string, required)
  - `org_id` (string, required)
  - `team_id` (string): Owning team; empty for an organization-wide alert.
  - `escalation_policy_id` (string): Empty when no policy pages for it.
  - `incident_id` (string)
  - `integration_id` (string): The integration that opened it; empty for alerts raised by hand or by another EvoHub product.
  - `fingerprint` (string): Deduplication key: while an alert with it is open, the same fingerprint retriggers it instead of opening another.
  - `title` (string, required)
  - `description` (string)
  - `severity` (AlertSeverity, required, one of `critical`, `high`, `medium`, `low`, `info`)
  - `status` (AlertStatus, required, one of `triggered`, `acknowledged`, `resolved`, `suppressed`)
  - `source` (string, required): Where it came from: an integration kind such as `prometheus`, `api`, `webhook`, or `manual`.
  - `labels` (object)
    - Other keys: string
  - `annotations` (object)
    - Other keys: string
  - `current_escalation_step` (integer): The escalation step reached so far.
  - `acknowledged_by` (string)
  - `acknowledged_at` (string (date-time))
  - `resolved_by` (string)
  - `resolved_at` (string (date-time))
  - `snoozed_until` (string (date-time))
  - `snoozed_by` (string)
  - `assigned_to` (string): User id of the assignee; empty when unassigned.
  - `notification_count` (integer)
  - `retrigger_count` (integer): How many times the same fingerprint arrived again while it was open.
  - `created_at` (string (date-time), required)
  - `updated_at` (string (date-time), required)
- `success` (boolean, required, value `true`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — No alert with this id in your organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 409 — A resolved alert cannot be taken over (`ALERT_RESOLVED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/alerts/9d4e2f1a-6b3c-4d8e-a7f9-0c1b2a3d4e5f/takeover' \
  -H 'Authorization: Bearer <TOKEN>'
```
