Updated 2026-09-29
On Enterprise (the plan with API access), Status exposes a public v1 API so you can manage monitoring from your own scripts, infrastructure-as-code, or internal tools instead of only the dashboard.
Creating a key
From the Security page (Settings → Security), create an API key and choose which scopes it can use. A key must have at least one scope — there's no such thing as a scope-less key. The full secret is shown once at creation time; after that, only a masked version is shown, so store it somewhere safe when you create it.
Who can create keys
Creating and revoking keys needs the Create and revoke API keys
permission (the Owner and Admins always have it). You can only give a key
scopes that your own role covers. For example, checks:write needs
permission to create, edit and delete checks and to view alert channels,
because a key with that scope can attach alert channels to checks.
Keys belong to the account, not to the person who created them, so they keep working after that person leaves. When someone is removed, disabled or moved to a role that no longer covers their keys' scopes, the dashboard lists the keys they created and offers to revoke them. See Invite your team and choose roles.
Available scopes
| Scope | Grants | To grant it, your role needs |
|---|---|---|
checks:read |
Read checks and their configuration | View checks, results and uptime |
checks:write |
Create, update, and delete checks | Create, edit and delete checks, and View, test and verify alert channels and delivery logs |
results:read |
Read check results and uptime data | View checks, results and uptime |
incidents:read |
Read incidents | View incidents |
incidents:write |
Acknowledge incidents | Acknowledge, add notes and post incident updates |
channels:read |
Read alert channels | View, test and verify alert channels and delivery logs |
channels:write |
Create alert channels (email or webhook) | Create, edit and delete alert channels |
maintenance:write |
Create and manage maintenance windows | Schedule, edit and delete maintenance windows |
Give a key only the scopes it actually needs — a read-only integration
should use checks:read/results:read, not a key with write access to
everything.
Posting incident updates and notes, and editing or deleting alert channels, are dashboard-only.
What the API covers
- Checks: list, create, get, update, delete, results, and uptime over 24 hours, 7 days, 30 days or 365 days.
- Incidents: list, get (with the timeline), and acknowledge.
- Alert channels: list and create.
- Maintenance windows: list, create, update and delete.
The base path is /api/v1. Each key may make 120 requests a minute. Keys can
be given an expiry date. The full reference (OpenAPI) is in the dashboard under
API docs on plans with API access. A heartbeat check's URL token is
returned only to keys with checks:write.
Using a key
Send the key as a bearer token:
Authorization: Bearer status_<prefix>_<secret>
Requests are rate-limited per key, so design integrations to react to events rather than polling aggressively.
Plan limits
Your plan controls whether API access is available at all, and how many API keys you can have at once. See Choosing a plan for specifics.