> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://respan.ai/docs/apis/errors/get-incident/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://respan.ai/_mcp/server. # Get an incident POST https://api.respan.ai/api/pulses/incidents/{incident_id}/ Content-Type: application/json Returns one incident with exact counts, the error groups behind it, the providers, models, endpoints and customers it hit, and its latest failed requests. Send an empty body. Reference: https://respan.ai/docs/apis/errors/get-incident ## Authentication - `Authorization` header (bearer token, required) — Use your Respan API key for Respan API authentication. Enter only the Respan API key value; clients send Authorization: Bearer \. For /api/responses, provider credentials such as Perplexity, OpenAI, or Azure OpenAI go in Settings -> Providers or respan\_params.credential\_override in the request body, not in this authentication field. ## Request ### Path parameters - `incident_id` (string, required) — Incident ID, from List incidents. ## Response ### 200 The incident. - `incident` (ErrorIncident, required) — The incident, with exact `impact`, `error_count` and `request_count`, and `dominant_fingerprint` set from the top error group. - `affected` (ErrorIncidentAffected, required) - `contributors` (ErrorIncidentContributors, required) - `occurrence_preview` (list of ErrorIncidentOccurrence, required) — The 20 most recent failed requests. - `data_status` (ErrorIncidentDetailDataStatus, required) - `links` (ErrorIncidentDetailLinks, required) ## Errors ### 403 Forbidden Error Forbidden: the API key is missing, invalid or expired; the key doesn't grant `logs:read` (Read access does). - `detail` (string, required) ### 404 Not Found Error No incident with this ID in your organization. - `error` (string, required) ### 429 Too Many Requests Error Rate limited. This endpoint allows 60 requests per minute per organization. - `detail` (string, required) ## Types ### ErrorIncident A window where one environment's error rate for one fault domain rose well above its usual level. - `id` (string, required) — Incident ID. - `title` (string, required) — Main error class and environment, in words. - `environment` (string, required) - `fault_domain` (enum, required) — Whose fault the failure is, derived from `error_class`: `user` (your requests or your own provider keys), `provider` (the upstream provider), `respan` (Respan's gateway or managed capacity), or `none` (client cancellations). - Allowed values: `user`, `respan`, `provider`, `none` - `started_at` (datetime, required) - `ended_at` (datetime, required, nullable) — End of the last elevated minute, or `null` while ongoing. - `duration_seconds` (integer, required) — From `started_at` to `data_through_at`. - `data_through_at` (datetime, required) — How far the evidence goes: `ended_at` once past; for an ongoing incident, the latest minute that is fully ingested. - `state` (enum, required) - Allowed values: `ongoing`, `past` - `resolution_reason` (enum, required, nullable) — Why it ended: the rate recovered, requests stopped, or the scope went silent. `null` while ongoing. - Allowed values: `recovered`, `no_traffic`, `stale` - `severity` (enum, required) - Allowed values: `low`, `medium`, `high`, `critical` - `trigger` (enum, required) — `spike` for a sudden jump, `drift` for a sustained smaller rise. - Allowed values: `spike`, `drift` - `peak_error_rate` (double, required) — A fraction from 0 to 1. - `baseline_error_rate` (double, required) — A fraction from 0 to 1. - `error_count` (integer, required) - `request_count` (integer, required) - `hot_bucket_count` (integer, required) — Minutes that tripped the detector. - `error_class_breakdown` (map from string to integer, required) — Failed requests per error class. - `dominant_error_class` (string, required) — Most common error class. - `dominant_fingerprint` (string, required, nullable) — Error group with the most failures. Usually `null` in List incidents; Get an incident fills it. - `impact` (ErrorIncidentImpact, required) - `primary_error` (ErrorIncidentPrimaryError, required) - `acknowledged_at` (datetime, required, nullable) - `is_acknowledged` (boolean, required) - `notes` (string, required) — Team notes. Visible to everyone in the organization. - `created_at` (datetime, required) - `updated_at` (datetime, required) — When the detector last evaluated the incident. Acknowledging or editing notes doesn't change it. ### ErrorIncidentAffected - `providers` (ErrorIncidentAffectedDimension, required) - `models` (ErrorIncidentAffectedDimension, required) - `endpoints` (ErrorIncidentAffectedDimension, required) - `customers` (ErrorIncidentAffectedDimension, required) ### ErrorIncidentContributors - `items` (list of ErrorIncidentContributor, required) — Top 20 error groups by failures. - `total_groups` (integer, required) — Error groups in the incident. - `total_occurrences` (integer, required) — Failed requests in the incident. - `other_occurrences` (integer, required) — Failures in groups past the top 20. ### ErrorIncidentOccurrence - `unique_id` (string, required) — Span ID. - `timestamp` (string, required) — When the request failed. UTC, ISO 8601 without a timezone suffix. - `fingerprint` (string, required) - `error_class` (string, required) - `provider` (string, required) - `model` (string, required) - `endpoint` (string, required) - `status` (integer, required) - `customer_identifier` (string, required) - `error_group_url` (string, required, nullable) - `log_url` (string, required, nullable) — Path of Get a span for this request. ### ErrorIncidentDetailDataStatus - `is_partial` (boolean, required) — `true` when the breakdowns couldn't be loaded. `affected`, `contributors` and `occurrence_preview` are then empty. - `data_through_at` (datetime, required) - `reason` (string, required, nullable) — `analytics_unavailable` when `is_partial` is `true`, else `null`. ### ErrorIncidentDetailLinks - `timeseries` (string, required) - `acknowledgement` (string, required) ### ErrorIncidentImpact - `error_count` (integer, required) — Failed requests in the incident window. - `request_count` (integer, required) — All requests in the incident's environment over the window. - `error_rate` (double, required) — `error_count` / `request_count`. A fraction from 0 to 1. - `peak_error_rate` (double, required) — Highest one-minute error rate. A fraction from 0 to 1. - `baseline_error_rate` (double, required) — The scope's usual error rate when the incident was detected. A fraction from 0 to 1. - `rate_delta` (double, required) — `error_rate` minus `baseline_error_rate`. - `rate_multiplier` (double, required, nullable) — `error_rate` / `baseline_error_rate`, or `null` when the baseline is 0. - `is_estimated` (boolean, required) — `true` when the counts are the detector's estimate (incidents longer than 4 hours in List incidents). Get an incident returns exact counts. - `affected_customers` (integer, optional) — Distinct customers with a failed request. Only in Get an incident. ### ErrorIncidentPrimaryError - `error_class` (string, required) - `fingerprint` (string, required, nullable) ### ErrorIncidentAffectedDimension - `unique_count` (integer, required) — Distinct values hit. - `total_occurrences` (integer, required) - `values` (list of ErrorIncidentAffectedValue, required) — Top 10 values by failures. ### ErrorIncidentContributor - `fingerprint` (string, required) — Error group fingerprint. - `title` (string, required) - `error_class` (string, required) - `provider` (string, required) - `model` (string, required) — Model of the group's latest failure. - `endpoint` (string, required) - `status` (integer, required) - `occurrence_count` (integer, required) - `percentage` (double, required) — Share of the incident's failures, 0 to 100. - `affected_customers` (integer, required) — Distinct customers with a failure in this group. - `first_seen_at` (string, required) — First failure in the incident. UTC, ISO 8601 without a timezone suffix. - `last_seen_at` (string, required) — Latest failure in the incident. UTC, ISO 8601 without a timezone suffix. - `error_group_url` (string, required, nullable) — Path of Get an error group for this fingerprint. - `drilldown_filters` (ErrorIncidentContributorDrilldownFilters, required) — Time range and environment to pass to Get an error group to see the same failures. ### ErrorIncidentAffectedValue - `value` (string, required) - `occurrence_count` (integer, required) — Failed requests with this value. - `percentage` (double, required) — Share of the dimension's failures, 0 to 100. - `first_seen_at` (string, required) — First failure with this value. UTC, ISO 8601 without a timezone suffix. - `last_seen_at` (string, required) — Latest failure with this value. UTC, ISO 8601 without a timezone suffix. ### ErrorIncidentContributorDrilldownFilters Time range and environment to pass to Get an error group to see the same failures. - `start_time` (string, required) — UTC, `YYYY-MM-DD HH:MM:SS`. - `end_time` (string, required) — UTC, `YYYY-MM-DD HH:MM:SS`. - `environment` (string, required) ## Examples **Request** ```json {} ``` **Response** ```json { "incident": { "id": "3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805", "title": "Provider rate limit in prod", "environment": "prod", "fault_domain": "respan", "started_at": "2026-09-30T14:02:00Z", "ended_at": "2026-09-30T14:47:00Z", "duration_seconds": 2700, "data_through_at": "2026-09-30T14:47:00Z", "state": "past", "resolution_reason": "recovered", "severity": "high", "trigger": "spike", "peak_error_rate": 0.42, "baseline_error_rate": 0.012, "error_count": 1840, "request_count": 9620, "hot_bucket_count": 31, "error_class_breakdown": { "provider_rate_limit": 1702, "provider_overloaded": 138 }, "dominant_error_class": "provider_rate_limit", "dominant_fingerprint": "9F3B2C1D4E5A6B7C", "impact": { "error_count": 1840, "request_count": 9620, "error_rate": 0.191, "peak_error_rate": 0.42, "baseline_error_rate": 0.012, "rate_delta": 0.179, "rate_multiplier": 15.9, "is_estimated": false, "affected_customers": 37 }, "primary_error": { "error_class": "provider_rate_limit", "fingerprint": "9F3B2C1D4E5A6B7C" }, "acknowledged_at": null, "is_acknowledged": false, "notes": "", "created_at": "2026-09-30T14:05:12.448210Z", "updated_at": "2026-09-30T14:52:03.118604Z" }, "affected": { "providers": { "unique_count": 1, "total_occurrences": 1840, "values": [ { "value": "openai", "occurrence_count": 1840, "percentage": 100, "first_seen_at": "2026-09-30T14:02:03.517203", "last_seen_at": "2026-09-30T14:46:58.006114" } ] }, "models": { "unique_count": 0, "total_occurrences": 0, "values": [] }, "endpoints": { "unique_count": 0, "total_occurrences": 0, "values": [] }, "customers": { "unique_count": 37, "total_occurrences": 1840, "values": [] } }, "contributors": { "items": [ { "fingerprint": "9F3B2C1D4E5A6B7C", "title": "provider_rate_limit · openai chat/completions · 429", "error_class": "provider_rate_limit", "provider": "openai", "model": "gpt-4o", "endpoint": "chat/completions", "status": 429, "occurrence_count": 1702, "percentage": 92.5, "affected_customers": 35, "first_seen_at": "2026-09-30T14:02:03.517203", "last_seen_at": "2026-09-30T14:46:58.006114", "error_group_url": "/api/pulses/errors/9f3b2c1d4e5a6b7c/", "drilldown_filters": { "start_time": "2026-09-30 14:02:00", "end_time": "2026-09-30 14:47:00", "environment": "prod" } } ], "total_groups": 2, "total_occurrences": 1840, "other_occurrences": 138 }, "occurrence_preview": [], "data_status": { "is_partial": false, "data_through_at": "2026-09-30T14:47:00Z", "reason": null }, "links": { "timeseries": "/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/timeseries/", "acknowledgement": "/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/acknowledgement/" } } ``` **SDK Code** ```python Incidents_retrieveIncident_example import requests url = "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/" payload = {} headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Incidents_retrieveIncident_example const url = 'https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/'; const options = { method: 'POST', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Incidents_retrieveIncident_example package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Incidents_retrieveIncident_example require 'uri' require 'net/http' url = URI("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java Incidents_retrieveIncident_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php Incidents_retrieveIncident_example request('POST', 'https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/', [ 'body' => '{}', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp Incidents_retrieveIncident_example using RestSharp; var client = new RestClient("https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Incidents_retrieveIncident_example import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = [] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.respan.ai/api/pulses/incidents/3c9d7e1a-58b2-4f0e-a6d4-91c2b7e3f805/")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```