# Create an incident

`POST https://evohub.io/api/v1/pages/{pageID}/incidents`

Part of the [Status API](https://docs-dev.evohub.io/status.md) reference · operationId `createIncident`.

Opens an incident on the page. With `body` it gets a first timeline entry, and
confirmed subscribers who follow an affected component (or the whole page) are
mailed.

To record one that is already over, send `started_at` and `resolved_at` (and
`resolution_body`): it is marked `backfilled`, lands on the days it happened
and mails nobody.

**Permission (API-key scope):** `status:incident:write`.

## Authorization

Any one of:

- `bearerAuth` (status:incident:write)
- `apiKeyHeader` (status:incident:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `pageID` (string (uuid), required, example `3f6c2a1e-8b4d-4f7a-9c21-5d0e7a9b1c42`): The status page's id (a UUID).

## Request body (required)

Content type: `application/json`

Type: `IncidentCreate`

- `title` (string, required)
- `impact` (IncidentImpact, one of `none`, `minor`, `major`, `critical`)
- `status` (IncidentStatus, one of `investigating`, `identified`, `monitoring`, `resolved`)
- `affected_component_ids` (array of string (uuid)): Components of this page; an id that is not one of the page's components is skipped.
- `body` (string | null): The first timeline entry. Mailed to subscribers unless the incident is backfilled.
- `started_at` (string (date-time) | null): Records an incident that already began (at most two minutes in the future). Makes it `backfilled`.
- `resolved_at` (string (date-time) | null): With `started_at`: when it ended. Sets the status to `resolved`.
- `resolution_body` (string): What the resolved entry of a backfilled incident says.
- `managed_in` (ManagedIn, one of `oncall`, `status_page`)

## Responses

### 201 — The incident.

Content type: `application/json`

Type: `object`

- `data` (Incident, required)
  - `id` (string (uuid), required)
  - `org_id` (string, required)
  - `page_id` (string (uuid), required)
  - `title` (string, required)
  - `impact` (IncidentImpact, required, one of `none`, `minor`, `major`, `critical`)
  - `status` (IncidentStatus, required, one of `investigating`, `identified`, `monitoring`, `resolved`)
  - `started_at` (string (date-time), required)
  - `resolved_at` (string (date-time))
  - `created_at` (string (date-time), required): When the page got it.
  - `updated_at` (string (date-time), required)
  - `postmortem_body` (string): Markdown; absent when none is written.
  - `postmortem_published_at` (string (date-time)): Set while the postmortem shows on the public page.
  - `backfilled` (boolean, required): Written after the fact with its own past times; it mailed no subscriber.
  - `managed_in` (ManagedIn, required, one of `oncall`, `status_page`)
  - `affected_component_ids` (array of string (uuid), required)
  - `updates` (array of IncidentUpdate, required): The timeline.
    - `id` (string (uuid))
    - `incident_id` (string (uuid))
    - `status` (IncidentStatus, one of `investigating`, `identified`, `monitoring`, `resolved`)
    - `body` (string)
    - `created_at` (string (date-time))
- `success` (boolean, required, value `true`)

### 400 — A field is missing or invalid (`VALIDATION_ERROR`); the message names it, or the body is not valid (`INVALID_BODY`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 404 — No such page (`PAGE_NOT_FOUND`, or `NOT_FOUND` for a page the caller cannot see).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): This request's id, also in `X-Request-ID`.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/pages/3f6c2a1e-8b4d-4f7a-9c21-5d0e7a9b1c42/incidents' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "body": "We are looking into elevated error rates on the API.",
  "title": "Elevated API error rates",
  "impact": "major",
  "status": "investigating",
  "managed_in": "status_page",
  "affected_component_ids": [
    "a7c1e3f5-2b4d-4c6e-8f0a-1b3d5f7a9c2e"
  ]
}'
```
