API keys and scopes

Manage checks, alert channels, and incidents from your own tooling with a scoped v1 API key.

Updated 2026-09-29

On Enterprise (the plan with API access), Status exposes a public v1 API so you can manage monitoring from your own scripts, infrastructure-as-code, or internal tools instead of only the dashboard.

Creating a key

From the Security page (Settings → Security), create an API key and choose which scopes it can use. A key must have at least one scope — there's no such thing as a scope-less key. The full secret is shown once at creation time; after that, only a masked version is shown, so store it somewhere safe when you create it.

Who can create keys

Creating and revoking keys needs the Create and revoke API keys permission (the Owner and Admins always have it). You can only give a key scopes that your own role covers. For example, checks:write needs permission to create, edit and delete checks and to view alert channels, because a key with that scope can attach alert channels to checks.

Keys belong to the account, not to the person who created them, so they keep working after that person leaves. When someone is removed, disabled or moved to a role that no longer covers their keys' scopes, the dashboard lists the keys they created and offers to revoke them. See Invite your team and choose roles.

Available scopes

Scope Grants To grant it, your role needs
checks:read Read checks and their configuration View checks, results and uptime
checks:write Create, update, and delete checks Create, edit and delete checks, and View, test and verify alert channels and delivery logs
results:read Read check results and uptime data View checks, results and uptime
incidents:read Read incidents View incidents
incidents:write Acknowledge incidents Acknowledge, add notes and post incident updates
channels:read Read alert channels View, test and verify alert channels and delivery logs
channels:write Create alert channels (email or webhook) Create, edit and delete alert channels
maintenance:write Create and manage maintenance windows Schedule, edit and delete maintenance windows

Give a key only the scopes it actually needs — a read-only integration should use checks:read/results:read, not a key with write access to everything.

Posting incident updates and notes, and editing or deleting alert channels, are dashboard-only.

What the API covers

  • Checks: list, create, get, update, delete, results, and uptime over 24 hours, 7 days, 30 days or 365 days.
  • Incidents: list, get (with the timeline), and acknowledge.
  • Alert channels: list and create.
  • Maintenance windows: list, create, update and delete.

The base path is /api/v1. Each key may make 120 requests a minute. Keys can be given an expiry date. The full reference (OpenAPI) is in the dashboard under API docs on plans with API access. A heartbeat check's URL token is returned only to keys with checks:write.

Using a key

Send the key as a bearer token:

Authorization: Bearer status_<prefix>_<secret>

Requests are rate-limited per key, so design integrations to react to events rather than polling aggressively.

Plan limits

Your plan controls whether API access is available at all, and how many API keys you can have at once. See Choosing a plan for specifics.

Ready to know the moment something breaks?

We're launching soon. Optional multi-region confirmation keeps one flaky vantage point from sending you an alert.

Coming Soon