> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://respan.ai/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://respan.ai/docs/_mcp/server.

# Get an incident

POST https://api.respan.ai/api/pulses/incidents/{incident_id}/
Content-Type: application/json

Returns one incident with exact counts, the error groups behind it, the providers, models, endpoints and customers it hit, and its latest failed requests. Send an empty body.

Reference: https://respan.ai/docs/apis/errors/get-incident

## Authentication

- `Authorization` header (bearer token, required) — Use your Respan API key for Respan API authentication. Enter only the Respan API key value; clients send Authorization: Bearer \<RESPAN\_API\_KEY>. For /api/responses, provider credentials such as Perplexity, OpenAI, or Azure OpenAI go in Settings -> Providers or respan\_params.credential\_override in the request body, not in this authentication field.

## Request

### Path parameters

- `incident_id` (string, required) — Incident ID, from List incidents.

## Response

### 200

The incident.

- `incident` (ErrorIncident, required) — The incident, with exact `impact`, `error_count` and `request_count`, and `dominant_fingerprint` set from the top error group.
- `affected` (ErrorIncidentAffected, required)
- `contributors` (ErrorIncidentContributors, required)
- `occurrence_preview` (list of ErrorIncidentOccurrence, required) — The 20 most recent failed requests.
- `data_status` (ErrorIncidentDetailDataStatus, required)
- `links` (ErrorIncidentDetailLinks, required)

## Errors

### 403 Forbidden Error

Forbidden: the API key is missing, invalid or expired; the key doesn't grant `logs:read` (Read access does).

- `detail` (string, required)

### 404 Not Found Error

No incident with this ID in your organization.

- `error` (string, required)

### 429 Too Many Requests Error

Rate limited. This endpoint allows 60 requests per minute per organization.

- `detail` (string, required)

## Types

### ErrorIncident

A window where one environment's error rate for one fault domain rose well above its usual level.

- `id` (string, required) — Incident ID.
- `title` (string, required) — Main error class and environment, in words.
- `environment` (string, required)
- `fault_domain` (enum, required) — Whose fault the failure is, derived from `error_class`: `user` (your requests or your own provider keys), `provider` (the upstream provider), `respan` (Respan's gateway or managed capacity), or `none` (client cancellations).
  - Allowed values: `user`, `respan`, `provider`, `none`
- `started_at` (datetime, required)
- `ended_at` (datetime, required, nullable) — End of the last elevated minute, or `null` while ongoing.
- `duration_seconds` (integer, required) — From `started_at` to `data_through_at`.
- `data_through_at` (datetime, required) — How far the evidence goes: `ended_at` once past; for an ongoing incident, the latest minute that is fully ingested.
- `state` (enum, required)
  - Allowed values: `ongoing`, `past`
- `resolution_reason` (enum, required, nullable) — Why it ended: the rate recovered, requests stopped, or the scope went silent. `null` while ongoing.
  - Allowed values: `recovered`, `no_traffic`, `stale`
- `severity` (enum, required)
  - Allowed values: `low`, `medium`, `high`, `critical`
- `trigger` (enum, required) — `spike` for a sudden jump, `drift` for a sustained smaller rise.
  - Allowed values: `spike`, `drift`
- `peak_error_rate` (double, required) — A fraction from 0 to 1.
- `baseline_error_rate` (double, required) — A fraction from 0 to 1.
- `error_count` (integer, required)
- `request_count` (integer, required)
- `hot_bucket_count` (integer, required) — Minutes that tripped the detector.
- `error_class_breakdown` (map from string to integer, required) — Failed requests per error class.
- `dominant_error_class` (string, required) — Most common error class.
- `dominant_fingerprint` (string, required, nullable) — Error group with the most failures. Usually `null` in List incidents; Get an incident fills it.
- `impact` (ErrorIncidentImpact, required)
- `primary_error` (ErrorIncidentPrimaryError, required)
- `acknowledged_at` (datetime, required, nullable)
- `is_acknowledged` (boolean, required)
- `notes` (string, required) — Team notes. Visible to everyone in the organization.
- `created_at` (datetime, required)
- `updated_at` (datetime, required) — When the detector last evaluated the incident. Acknowledging or editing notes doesn't change it.

### ErrorIncidentAffected

- `providers` (ErrorIncidentAffectedDimension, required)
- `models` (ErrorIncidentAffectedDimension, required)
- `endpoints` (ErrorIncidentAffectedDimension, required)
- `customers` (ErrorIncidentAffectedDimension, required)

### ErrorIncidentContributors

- `items` (list of ErrorIncidentContributor, required) — Top 20 error groups by failures.
- `total_groups` (integer, required) — Error groups in the incident.
- `total_occurrences` (integer, required) — Failed requests in the incident.
- `other_occurrences` (integer, required) — Failures in groups past the top 20.

### ErrorIncidentOccurrence

- `unique_id` (string, required) — Span ID.
- `timestamp` (string, required) — When the request failed. UTC, ISO 8601 without a timezone suffix.
- `fingerprint` (string, required)
- `error_class` (string, required)
- `provider` (string, required)
- `model` (string, required)
- `endpoint` (string, required)
- `status` (integer, required)
- `customer_identifier` (string, required)
- `error_group_url` (string, required, nullable)
- `log_url` (string, required, nullable) — Path of Get a span for this request.

### ErrorIncidentDetailDataStatus

- `is_partial` (boolean, required) — `true` when the breakdowns couldn't be loaded. `affected`, `contributors` and `occurrence_preview` are then empty.
- `data_through_at` (datetime, required)
- `reason` (string, required, nullable) — `analytics_unavailable` when `is_partial` is `true`, else `null`.

### ErrorIncidentDetailLinks

- `timeseries` (string, required)
- `acknowledgement` (string, required)

### ErrorIncidentImpact

- `error_count` (integer, required) — Failed requests in the incident window.
- `request_count` (integer, required) — All requests in the incident's environment over the window.
- `error_rate` (double, required) — `error_count` / `request_count`. A fraction from 0 to 1.
- `peak_error_rate` (double, required) — Highest one-minute error rate. A fraction from 0 to 1.
- `baseline_error_rate` (double, required) — The scope's usual error rate when the incident was detected. A fraction from 0 to 1.
- `rate_delta` (double, required) — `error_rate` minus `baseline_error_rate`.
- `rate_multiplier` (double, required, nullable) — `error_rate` / `baseline_error_rate`, or `null` when the baseline is 0.
- `is_estimated` (boolean, required) — `true` when the counts are the detector's estimate (incidents longer than 4 hours in List incidents). Get an incident returns exact counts.
- `affected_customers` (integer, optional) — Distinct customers with a failed request. Only in Get an incident.

### ErrorIncidentPrimaryError

- `error_class` (string, required)
- `fingerprint` (string, required, nullable)

### ErrorIncidentAffectedDimension

- `unique_count` (integer, required) — Distinct values hit.
- `total_occurrences` (integer, required)
- `values` (list of ErrorIncidentAffectedValue, required) — Top 10 values by failures.

### ErrorIncidentContributor

- `fingerprint` (string, required) — Error group fingerprint.
- `title` (string, required)
- `error_class` (string, required)
- `provider` (string, required)
- `model` (string, required) — Model of the group's latest failure.
- `endpoint` (string, required)
- `status` (integer, required)
- `occurrence_count` (integer, required)
- `percentage` (double, required) — Share of the incident's failures, 0 to 100.
- `affected_customers` (integer, required) — Distinct customers with a failure in this group.
- `first_seen_at` (string, required) — First failure in the incident. UTC, ISO 8601 without a timezone suffix.
- `last_seen_at` (string, required) — Latest failure in the incident. UTC, ISO 8601 without a timezone suffix.
- `error_group_url` (string, required, nullable) — Path of Get an error group for this fingerprint.
- `drilldown_filters` (ErrorIncidentContributorDrilldownFilters, required) — Time range and environment to pass to Get an error group to see the same failures.

### ErrorIncidentAffectedValue

- `value` (string, required)
- `occurrence_count` (integer, required) — Failed requests with this value.
- `percentage` (double, required) — Share of the dimension's failures, 0 to 100.
- `first_seen_at` (string, required) — First failure with this value. UTC, ISO 8601 without a timezone suffix.
- `last_seen_at` (string, required) — Latest failure with this value. UTC, ISO 8601 without a timezone suffix.

### ErrorIncidentContributorDrilldownFilters

Time range and environment to pass to Get an error group to see the same failures.

- `start_time` (string, required) — UTC, `YYYY-MM-DD HH:MM:SS`.
- `end_time` (string, required) — UTC, `YYYY-MM-DD HH:MM:SS`.
- `environment` (string, required)

## Examples

**Request**

```json
{}
```

**Response**

```json
{
  "incident": {
    "id": "3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805",
    "title": "Provider rate limit in prod",
    "environment": "prod",
    "fault_domain": "respan",
    "started_at": "2026-09-30T14:02:00Z",
    "ended_at": "2026-09-30T14:47:00Z",
    "duration_seconds": 2700,
    "data_through_at": "2026-09-30T14:47:00Z",
    "state": "past",
    "resolution_reason": "recovered",
    "severity": "high",
    "trigger": "spike",
    "peak_error_rate": 0.42,
    "baseline_error_rate": 0.012,
    "error_count": 1840,
    "request_count": 9620,
    "hot_bucket_count": 31,
    "error_class_breakdown": {
      "provider_rate_limit": 1702,
      "provider_overloaded": 138
    },
    "dominant_error_class": "provider_rate_limit",
    "dominant_fingerprint": "9F3B2C1D4E5A6B7C",
    "impact": {
      "error_count": 1840,
      "request_count": 9620,
      "error_rate": 0.191,
      "peak_error_rate": 0.42,
      "baseline_error_rate": 0.012,
      "rate_delta": 0.179,
      "rate_multiplier": 15.9,
      "is_estimated": false,
      "affected_customers": 37
    },
    "primary_error": {
      "error_class": "provider_rate_limit",
      "fingerprint": "9F3B2C1D4E5A6B7C"
    },
    "acknowledged_at": null,
    "is_acknowledged": false,
    "notes": "",
    "created_at": "2026-09-30T14:05:12.448210Z",
    "updated_at": "2026-09-30T14:52:03.118604Z"
  },
  "affected": {
    "providers": {
      "unique_count": 1,
      "total_occurrences": 1840,
      "values": [
        {
          "value": "openai",
          "occurrence_count": 1840,
          "percentage": 100,
          "first_seen_at": "2026-09-30T14:02:03.517203",
          "last_seen_at": "2026-09-30T14:46:58.006114"
        }
      ]
    },
    "models": {
      "unique_count": 0,
      "total_occurrences": 0,
      "values": []
    },
    "endpoints": {
      "unique_count": 0,
      "total_occurrences": 0,
      "values": []
    },
    "customers": {
      "unique_count": 37,
      "total_occurrences": 1840,
      "values": []
    }
  },
  "contributors": {
    "items": [
      {
        "fingerprint": "9F3B2C1D4E5A6B7C",
        "title": "provider_rate_limit · openai chat/completions · 429",
        "error_class": "provider_rate_limit",
        "provider": "openai",
        "model": "gpt-4o",
        "endpoint": "chat/completions",
        "status": 429,
        "occurrence_count": 1702,
        "percentage": 92.5,
        "affected_customers": 35,
        "first_seen_at": "2026-09-30T14:02:03.517203",
        "last_seen_at": "2026-09-30T14:46:58.006114",
        "error_group_url": "/api/pulses/errors/9f3b2c1d4e5a6b7c/",
        "drilldown_filters": {
          "start_time": "2026-09-30 14:02:00",
          "end_time": "2026-09-30 14:47:00",
          "environment": "prod"
        }
      }
    ],
    "total_groups": 2,
    "total_occurrences": 1840,
    "other_occurrences": 138
  },
  "occurrence_preview": [],
  "data_status": {
    "is_partial": false,
    "data_through_at": "2026-09-30T14:47:00Z",
    "reason": null
  },
  "links": {
    "timeseries": "/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/timeseries/",
    "acknowledgement": "/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/acknowledgement/"
  }
}
```

**SDK Code**

```python Incidents_retrieveIncident_example
import requests

url = "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/"

payload = {}
headers = {
    "Authorization": "Bearer <respanApiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Incidents_retrieveIncident_example
const url = 'https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <respanApiKey>', 'Content-Type': 'application/json'},
  body: '{}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Incidents_retrieveIncident_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/"

	payload := strings.NewReader("{}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <respanApiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Incidents_retrieveIncident_example
require 'uri'
require 'net/http'

url = URI("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <respanApiKey>'
request["Content-Type"] = 'application/json'
request.body = "{}"

response = http.request(request)
puts response.read_body
```

```java Incidents_retrieveIncident_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/")
  .header("Authorization", "Bearer <respanApiKey>")
  .header("Content-Type", "application/json")
  .body("{}")
  .asString();
```

```php Incidents_retrieveIncident_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/', [
  'body' => '{}',
  'headers' => [
    'Authorization' => 'Bearer <respanApiKey>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Incidents_retrieveIncident_example
using RestSharp;

var client = new RestClient("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <respanApiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Incidents_retrieveIncident_example
import Foundation

let headers = [
  "Authorization": "Bearer <respanApiKey>",
  "Content-Type": "application/json"
]
let parameters = [] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```