PagerDuty Tools
Written By Christopher Scaminaci
Last updated 7 days ago
PagerDuty Tools
pd_ · 478 tools · Free 233 · Pro 245
Incident response, on-call scheduling and alert routing over REST API v2. Two regional hosts (US `api.pagerduty.com`, EU `api.eu.pagerduty.com`) chosen by a stored region code. Auth is a static account General Access API key as `Authorization: Token token=...`, never `Bearer`, plus `Accept: application/vnd.pagerduty+json;version=2` on every call and a `From` header naming a real user on writes. Most reads are `offset`/`limit` paged, cap 100, and REFUSED past `offset + limit` 10,000, so narrow sweeps by date, team or service; some are cursor-paged, and the Analytics reads are POSTs paged in the request body. SCIM provisioning shares host and key under `/scim/v2`. `/ip_allow_lists` and `/enrichment` are Early Access, needing account entitlement. The Events API is a separate host, `events.pagerduty.com`, taking no account key: its routing key is a call argument. One record wraps under a singular key, a collection under a plural one, verbatim. 960 a minute per key; StackJack paces 900.
All connector tools · PagerDuty setup guide
PagerDuty tool groups
- Account — 3 tools
- Audit — 1 tool
- Licenses — 2 tools
- Notifications — 1 tool
- OAuth Delegations — 2 tools
- Paused Incident Reports — 2 tools
- Session Configurations — 3 tools
- SRE Agent — 3 tools
- Standards — 4 tools
- Tags — 7 tools
- Templates — 7 tools
- Vendors — 2 tools
- Analytics — 16 tools
- Automation Actions — 25 tools
- Enrichment Integrations — 13 tools
- Enrichment Schemas — 9 tools
- Event Enrichments — 12 tools
- Escalation Policies — 6 tools
- Event Orchestrations — 39 tools
- Recommendations — 4 tools
- Rulesets — 10 tools
- Events API — 3 tools
- Incident Custom Fields — 9 tools
- Incident Types — 14 tools
- Incident Workflows — 15 tools
- Workflow Integrations — 8 tools
- Incidents — 29 tools
- Add-ons — 5 tools
- Change Events — 6 tools
- Extension Schemas — 2 tools
- Extensions — 6 tools
- Webhooks — 12 tools
- IP Allow Lists — 6 tools
- Log Entries — 3 tools
- Maintenance Windows — 5 tools
- On-Call — 1 tool
- Schedules — 25 tools
- Schedules (legacy v2) — 11 tools
- SCIM Provisioning — 10 tools
- Alert Grouping Settings — 5 tools
- Business Services — 16 tools
- Service Custom Fields — 10 tools
- Service Dependencies — 4 tools
- Services — 19 tools
- Status Dashboards — 5 tools
- Status Pages — 26 tools
- Teams — 14 tools
- Users — 38 tools
Account
pd_list_abilities details
pd_list_abilities details
[PagerDuty] List abilities. GET /abilities. Returns raw PagerDuty JSON.
pd_list_priorities details
pd_list_priorities details
[PagerDuty] List priorities. GET /priorities. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_test_ability details
pd_test_ability details
[PagerDuty] Test an ability. GET /abilities/. Path parameters: id. Returns raw PagerDuty JSON.
Audit
pd_list_audit_records details
pd_list_audit_records details
[PagerDuty] List audit records. The audit trail of changes made to the account. Without since and until PagerDuty reports the last 24 hours, and until may not be more than 31 days after since, so a longer history has to be swept in windows. GET /audit/records. Optional filters: since, until, root_resource_types[], actor_type, actor_id, method_type, method_truncated_token, actions[]. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
Licenses
pd_list_license_allocations details
pd_list_license_allocations details
[PagerDuty] List License Allocations. One row per user showing which licence that user holds; this is where a seat count is reconciled against the licences pd_list_licenses reports. GET /license_allocations. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_licenses details
pd_list_licenses details
[PagerDuty] List Licenses. Every licence the account holds comes back in one answer: PagerDuty declares no limit, offset or cursor on this endpoint, so there is nothing to page and no page arguments to send. GET /licenses. Returns raw PagerDuty JSON.
Notifications
pd_list_notifications details
pd_list_notifications details
[PagerDuty] List notifications. Reports the notifications PagerDuty actually SENT to responders - SMS, e-mail, phone and push - in a window. since and until are both REQUIRED and the window must be shorter than 3 months, so a longer history has to be swept in windows. Each record carries the responder's address, which is their real phone number or e-mail. GET /notifications. Required filters: since, until. Optional filters: time_zone, filter, include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
OAuth Delegations
pd_delete_all_oauth_delegations details
pd_delete_all_oauth_delegations details
[PagerDuty] DESTRUCTIVE: revoke one user's OAuth delegations (mobile app, web app or both). Why this is destructive: the named user is signed out of the PagerDuty mobile app, the web app or both at once and has to sign in again everywhere; PagerDuty keeps nothing to restore. Both user_id and type are required, and the vendor's own name for the operation says "all" because it revokes every delegation of those types for that ONE user - it is not an account-wide revocation. DELETE /oauth_delegations. Required filters: user_id, type. Returns raw PagerDuty JSON.
pd_get_oauth_revocation_status details
pd_get_oauth_revocation_status details
[PagerDuty] Get OAuth delegations revocation requests status. PagerDuty deprecated this read when it made OAuth revocation synchronous, so there is no longer an asynchronous request to poll: the replacement is pd_delete_all_oauth_delegations (DELETE /oauth_delegations), which reports the outcome in its own answer. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /oauth_delegations/revocation_requests/status. Optional filters: requested_at_end. Returns raw PagerDuty JSON.
Paused Incident Reports
pd_get_paused_incident_report_counts details
pd_get_paused_incident_report_counts details
[PagerDuty] Get Paused Incident Reporting counts. Requires PagerDuty's Event Intelligence package or a Digital Operations plan - an account without it is refused rather than answering zero. The reporting period looks back at most 6 months. GET /paused_incident_reports/counts. Optional filters: since, until, service_id, suspended_by. Returns raw PagerDuty JSON.
pd_list_paused_incident_report_alerts details
pd_list_paused_incident_report_alerts details
[PagerDuty] Get a sample of recently paused alerts. Requires PagerDuty's Event Intelligence package or a Digital Operations plan - an account without it is refused rather than answering zero. The reporting period looks back at most 6 months. PagerDuty answers with a fixed sample rather than a page: the 5 most recent alerts that triggered after being paused and the 5 most recent that resolved while paused. GET /paused_incident_reports/alerts. Optional filters: since, until, service_id, suspended_by. Returns raw PagerDuty JSON.
Session Configurations
pd_delete_session_configurations details
pd_delete_session_configurations details
[PagerDuty] DESTRUCTIVE: delete an account's session configurations. Why this is destructive: it drops the account's session-lifetime configuration for the types you name and every user falls back to PagerDuty's own defaults; PagerDuty keeps no copy of the values that were set, and type accepts mobile, web, or both as a comma-separated list. DELETE /session_configurations. Required filters: type. Returns raw PagerDuty JSON.
pd_get_session_configurations details
pd_get_session_configurations details
[PagerDuty] Get an account's session configurations. PagerDuty answers 404 when the account has never set a session configuration - that is 'not configured' rather than a broken call, and the account then runs on PagerDuty's own session defaults. Omitting type returns both the mobile and the web configuration. GET /session_configurations. Optional filters: type. Returns raw PagerDuty JSON.
pd_update_session_configurations details
pd_update_session_configurations details
[PagerDuty] DESTRUCTIVE: configure an account's session configurations. Why this is destructive: it sets the session lifetime for EVERY user on the account, and PagerDuty REVOKES every existing session of the types you name the moment it is saved - so everyone signed into that app is signed out immediately; the previous values are not kept. PUT /session_configurations. Required filters: type. The configuration as JSON: {"session_configuration": {"absolute_session_ttl": 3600, "idle_session_ttl": 600}}. Both are seconds and both are required; PagerDuty accepts 600 to 18144000 for absolute_session_ttl and 60 to 15552000 for idle_session_ttl. Returns raw PagerDuty JSON.
SRE Agent
pd_delete_sre_agent_memory details
pd_delete_sre_agent_memory details
[PagerDuty] DESTRUCTIVE: delete an SRE Agent memory. Why this is destructive: it permanently deletes the memory and PagerDuty keeps no copy; a conversation already running may keep using it, so PagerDuty's own advice is to ask the agent to delete a runbook when it has to be gone from a live conversation. DELETE /sre_agent/memories/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_sre_agent_memories details
pd_list_sre_agent_memories details
[PagerDuty] List SRE Agent memories. The memories PagerDuty's SRE Agent works from - runbooks, service profiles and incident playbooks - so an account without the SRE Agent product has none. PagerDuty declares no offset and no cursor here: limit caps at 100 and there is no way to reach a record past it, so narrow with service_id, incident_id or type instead of paging. GET /sre_agent/memories. Optional filters: service_id, incident_id, type. Returns raw PagerDuty JSON.
pd_update_sre_agent_memory details
pd_update_sre_agent_memory details
[PagerDuty] Update an SRE Agent memory. Not destructive: it replaces the text of ONE memory, nothing is paged or notified and the memory can be rewritten again - but the previous text is not kept, and a conversation already running may keep the old one until it ends. PUT /sre_agent/memories/. Path parameters: id. The new memory as JSON: {"memory": {"content": "..."}}. content is the whole memory text and REPLACES what is stored. Returns raw PagerDuty JSON.
Standards
pd_get_resource_standards_scores details
pd_get_resource_standards_scores details
[PagerDuty] List a resource's standards scores. Scores ONE named resource against the account's standards. The sibling pd_list_resources_standards_scores is PagerDuty's many-resource form, but how PagerDuty parses its ids array has not been verified against a live account, so scoring several resources is reliably done by calling THIS tool once per id. GET /standards/scores//. Path parameters: id, resource_type. Returns raw PagerDuty JSON.
pd_list_resources_standards_scores details
pd_list_resources_standards_scores details
[PagerDuty] List resources' standards scores. Scores the resources you name against the account's standards. ids is REQUIRED - PagerDuty scores only the resources you name rather than the whole account - and the endpoint declares no limit, offset or cursor, so the answer is exactly the resources you asked for. PagerDuty documents a maximum of 100 ids for the endpoint; read the ids parameter before asking for more than one. GET /standards/scores/. Path parameters: resource_type. Required filters: ids. Returns raw PagerDuty JSON.
pd_list_standards details
pd_list_standards details
[PagerDuty] List Standards. The account's standards - the rules PagerDuty scores resources against. The endpoint declares no limit, offset or cursor, so every standard comes back at once. Mind the spelling: the resource_type FILTER here is SINGULAR (technical_service) while the same value is plural in the /standards/scores paths (technical_services). GET /standards. Optional filters: active, resource_type. Returns raw PagerDuty JSON.
pd_update_standard details
pd_update_standard details
[PagerDuty] DESTRUCTIVE: update a standard. Why this is destructive: PagerDuty REPLACES the stored standard with the definition you send, so an inclusion, an exclusion or a regex you leave out is gone and the standard scores a different set of resources from the next evaluation onward. Send the COMPLETE definition. Standards SCORE existing resources and page nobody, and the change can be made again once you have read the current definition back. PUT /standards/. Path parameters: id. The standard as JSON. PagerDuty documents active (whether the standard is in force), values.regex (the pattern it tests), description, and the inclusions and exclusions lists that pick which resources are scored. Send the COMPLETE definition - PagerDuty replaces the stored standard with what you send. Returns raw PagerDuty JSON.
Tags
pd_change_entity_tags details
pd_change_entity_tags details
[PagerDuty] DESTRUCTIVE: add and remove tags on a user, team or escalation policy. Why this is destructive: the remove list DELETES tag assignments from the entity in the same call that adds, PagerDuty keeps no record of what was assigned before, and an add element of type tag CREATES a new account-wide tag when no tag with that label exists. POST ///change_tags. Path parameters: entity_type, id. The tag changes as JSON. add takes {"type": "tag", "label": "Batman"} - which reuses the existing tag with that label or creates one - or {"type": "tag_reference", "id": "PTAG123"}; remove takes {"type": "tag_reference", "id": "PTAG123"}. Both arrays are optional and are applied in the one call. Returns raw PagerDuty JSON.
pd_create_tags details
pd_create_tags details
[PagerDuty] Create a tag. Not destructive: additive: a new tag labels nothing until it is assigned to a user, team or escalation policy, and it changes nothing else on the account. POST /tags. The tag as JSON: {"tag": {"type": "tag", "label": "Batman"}}. Only type and label are writable and a label is capped at 191 characters; the id, summary, self and html_url PagerDuty lists on the tag schema are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_delete_tag details
pd_delete_tag details
[PagerDuty] DESTRUCTIVE: delete a tag. Why this is destructive: deleting a tag removes it from every user, team and escalation policy it was assigned to, in one step, and PagerDuty keeps no record of which entities carried it. DELETE /tags/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_tag details
pd_get_tag details
[PagerDuty] Get a tag. Returns the tag itself - its label - and not the users, teams or escalation policies it is assigned to; pd_list_tag_entities answers that. GET /tags/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_entity_tags details
pd_list_entity_tags details
[PagerDuty] List the tags on one user, team or escalation policy. The mirror image is pd_list_tag_entities, which starts from a tag and lists the entities carrying it - the two take the same two values in the opposite order. GET ///tags. Path parameters: entity_type, id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_tag_entities details
pd_list_tag_entities details
[PagerDuty] List the users, teams or escalation policies carrying a tag. The mirror image is pd_list_entity_tags, which starts from one entity and lists its tags - the two take the same two values in the opposite order. GET /tags//. Path parameters: id, entity_type. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_tags details
pd_list_tags details
[PagerDuty] List tags. Every tag on the account, each with the label it applies. A tag here is only the label: what it is assigned to comes from pd_list_tag_entities. GET /tags. Optional filters: query. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
Templates
pd_create_template details
pd_create_template details
[PagerDuty] Create a template. Not destructive: additive: a new template renders nothing until a status update or notification names it. POST /templates. The template as JSON: {"template": {"template_type": "status_update", "name": "...", "description": "...", "templated_fields": {"email_subject": "...", "email_body": "...", "message": "..."}}}. status_update is the only template_type PagerDuty supports today; email_body is HTML and message is the short form used for SMS, push and chat. Returns raw PagerDuty JSON.
pd_delete_template details
pd_delete_template details
[PagerDuty] DESTRUCTIVE: delete a template. Why this is destructive: it deletes the template and PagerDuty keeps no copy; status updates already sent are unaffected, but anything that rendered from this template has to be pointed at another one. DELETE /templates/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_template details
pd_get_template details
[PagerDuty] Get a template. Returns one template with its templated_fields: the e-mail subject, the HTML e-mail body and the short message PagerDuty renders for SMS, push and chat. pd_render_template renders it against a real incident without changing or sending anything. GET /templates/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_template_fields details
pd_list_template_fields details
[PagerDuty] List template fields. The fields an account's templates may reference - read this before writing a template body so templated_fields names something PagerDuty will actually substitute. The endpoint declares no limit, offset or cursor, so the whole list comes back at once. GET /templates/fields. Returns raw PagerDuty JSON.
pd_list_templates details
pd_list_templates details
[PagerDuty] List templates. Templates are the bodies PagerDuty renders when a status update is sent on an incident. status_update is the only type PagerDuty supports today and template_type defaults to it. GET /templates. Optional filters: query, template_type, sort_by. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_render_template details
pd_render_template details
[PagerDuty] Render a template. This is a POST-shaped READ: it renders the template against the object you name and stores nothing. PagerDuty's own scope line for it is templates.read. POST /templates//render. Path parameters: id. The render input as JSON. PagerDuty varies the shape by template type; for status_update it documents {"incident_id": "PABC123", "status_update": {"message": "text passed to the template"}} plus an optional external object the template may reference. Nothing is stored and no status update is sent. Returns raw PagerDuty JSON.
pd_update_template details
pd_update_template details
[PagerDuty] DESTRUCTIVE: update a template. Why this is destructive: PagerDuty replaces the stored template with what you send, so a templated field you leave out is gone and every future status update renders without it. Send the COMPLETE templated_fields set. Updates already sent are unaffected and the template can be rewritten again. PUT /templates/. Path parameters: id. The template as JSON: {"template": {"template_type": "status_update", "name": "...", "description": "...", "templated_fields": {"email_subject": "...", "email_body": "...", "message": "..."}}}. Send the COMPLETE templated_fields set - PagerDuty replaces the stored template with what you send. Returns raw PagerDuty JSON.
Vendors
pd_get_vendor details
pd_get_vendor details
[PagerDuty] Get a vendor. Vendors are PagerDuty's own global integration catalogue - Datadog, AWS CloudWatch and the rest - shared by every account, so this id is the vendor a service integration is created FROM and not anything the account owns. GET /vendors/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_vendors details
pd_list_vendors details
[PagerDuty] List vendors. PagerDuty's global catalogue of integration vendors, identical for every account: this is where the vendor id for a new service integration comes from. GET /vendors. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
Analytics
pd_get_advance_usage_metrics details
pd_get_advance_usage_metrics details
[PagerDuty] Get aggregated PD Advance usage data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. PD Advance is a separately-licensed PagerDuty product; an account without it answers 402 or 403. POST /analytics/metrics/pd_advance_usage/features. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.incident_created_at_start, filters.incident_created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, time_zone. Returns raw PagerDuty JSON.
pd_get_all_escalation_policy_metrics details
pd_get_all_escalation_policy_metrics details
[PagerDuty] Get aggregated metrics for all escalation policies. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/escalation_policies/all. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_all_responder_metrics details
pd_get_all_responder_metrics details
[PagerDuty] Get aggregated metrics for all responders. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/responders/all. Send the request body as JSON; PagerDuty documents these fields: filters.date_range_start, filters.date_range_end, filters.urgency, filters.team_ids, filters.responder_ids, filters.priority_ids, filters.priority_names, time_zone, order, order_by. Returns raw PagerDuty JSON.
pd_get_all_service_metrics details
pd_get_all_service_metrics details
[PagerDuty] Get aggregated metrics for all services. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/services/all. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_all_team_metrics details
pd_get_all_team_metrics details
[PagerDuty] Get aggregated metrics for all teams. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/teams/all. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_all_user_metrics details
pd_get_all_user_metrics details
[PagerDuty] Get aggregated metrics for all users. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/users/all. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.team_ids, filters.user_ids, filters.role_ids, time_zone, order, order_by, aggregate_unit, limit, starting_after, ending_before. Returns raw PagerDuty JSON.
pd_get_escalation_policy_metrics details
pd_get_escalation_policy_metrics details
[PagerDuty] Get aggregated escalation policy data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/escalation_policies. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_incident_metrics details
pd_get_incident_metrics details
[PagerDuty] Get aggregated incident data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/all. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_raw_incident_analytics details
pd_get_raw_incident_analytics details
[PagerDuty] Get raw data - single incident. one incident's analytics record. PagerDuty's analytics data lags live incident data by up to 24 hours, so a very recent incident may not be there yet - pd_get_incident is the live read. GET /analytics/raw/incidents/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_responder_team_metrics details
pd_get_responder_team_metrics details
[PagerDuty] Get responder data aggregated by team. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/responders/teams. Send the request body as JSON; PagerDuty documents these fields: filters.date_range_start, filters.date_range_end, filters.urgency, filters.team_ids, filters.responder_ids, filters.priority_ids, filters.priority_names, time_zone, order, order_by. Returns raw PagerDuty JSON.
pd_get_service_metrics details
pd_get_service_metrics details
[PagerDuty] Get aggregated service data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/services. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_get_team_metrics details
pd_get_team_metrics details
[PagerDuty] Get aggregated team data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/metrics/incidents/teams. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.min_ackowledgements, filters.min_timeout_escalations, filters.min_manual_escalations, filters.team_ids, filters.service_ids, filters.escalation_policy_ids, filters.priority_ids, filters.priority_names, filters.pd_advance_used, time_zone, order, order_by, aggregate_unit. Returns raw PagerDuty JSON.
pd_list_raw_incident_analytics details
pd_list_raw_incident_analytics details
[PagerDuty] Get raw data - multiple incidents. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/raw/incidents. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.updated_after, filters.urgency, filters.major, filters.team_ids, filters.service_ids, filters.priority_ids, filters.priority_names, filters.incident_type_ids, starting_after, ending_before, order, order_by, limit, time_zone. Returns raw PagerDuty JSON.
pd_list_raw_incident_responses details
pd_list_raw_incident_responses details
[PagerDuty] Get raw responses from a single incident. the optional request BODY carries this call's limit, order, order_by and time_zone - the endpoint declares no query parameters. PagerDuty's analytics data lags live incident data by up to 24 hours. GET /analytics/raw/incidents//responses. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: limit, order, order_by, time_zone. Returns raw PagerDuty JSON.
pd_list_raw_responder_incidents details
pd_list_raw_responder_incidents details
[PagerDuty] Get raw incidents for a single responder_id. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/raw/responders//incidents. Path parameters: responder_id. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.urgency, filters.major, filters.team_ids, filters.service_ids, filters.priority_ids, filters.priority_names, filters.incident_type_ids, starting_after, ending_before, order, order_by, limit, time_zone. Returns raw PagerDuty JSON.
pd_list_raw_user_analytics details
pd_list_raw_user_analytics details
[PagerDuty] Get raw user analytics data. This is a POST-shaped READ: the filters AND the paging (starting_after, ending_before, limit) travel in the request body, and the endpoint declares no query parameters at all. PagerDuty's analytics data lags live incident data by up to 24 hours, and a query with no date filter sweeps the whole retention window - always send filters.created_at_start and filters.created_at_end. POST /analytics/raw/users. Send the request body as JSON; PagerDuty documents these fields: filters.created_at_start, filters.created_at_end, filters.team_ids, filters.user_ids, filters.role_ids, time_zone, order, order_by, aggregate_unit, limit, starting_after, ending_before. Returns raw PagerDuty JSON.
Automation Actions
pd_add_automation_action_runner_team details
pd_add_automation_action_runner_team details
[PagerDuty] Associate a runner with a team. Not destructive: it binds one team to this runner so that team's people can use it. The body carries a single team reference rather than a replacement list, so nothing already bound is disturbed, and pd_remove_automation_action_runner_team unbinds it again. Nothing executes as a result. POST /automation_actions/runners//teams. Path parameters: id. Required field: team.type. Send team as an object with id set to the team id and type set to team_reference. Returns raw PagerDuty JSON.
pd_add_automation_action_service details
pd_add_automation_action_service details
[PagerDuty] DESTRUCTIVE: associate an Automation Action with a service. Why this is destructive: it arms remote execution on that service. The bound action runs a script or a Process Automation job on a runner the customer hosts themselves, and once it is bound it becomes invocable on that service's incidents - by a person in PagerDuty, and WITHOUT one by an Event Orchestration, because the action's allow_invocation_from_event_orchestration switch defaults to true. That switch and allow_invocation_manually belong to the ACTION and are not set here, so read the action with pd_get_automation_action before you bind it. The bind itself is additive - the body carries a single service reference rather than a replacement list, so nothing already bound is disturbed - and pd_remove_automation_action_service unbinds it again. POST /automation_actions/actions//services. Path parameters: id. Required field: service.type. Send service as an object with id set to the service id and type set to service_reference. Returns raw PagerDuty JSON.
pd_add_automation_action_team details
pd_add_automation_action_team details
[PagerDuty] Associate an Automation Action with a team. Not destructive: it binds one team to this action so that team's people can see it and invoke it manually. The body carries a single team reference rather than a replacement list, so nothing already bound is disturbed, and pd_remove_automation_action_team unbinds it again. It confers no capability of its own: what the action runs, and whether it may be invoked by hand or by an Event Orchestration at all, are the action's own allow_invocation_manually and allow_invocation_from_event_orchestration switches, which pd_get_automation_action reads. Scope it deliberately all the same - the people in that team can then run it. POST /automation_actions/actions//teams. Path parameters: id. Required field: team.type. Send team as an object with id set to the team id and type set to team_reference. Returns raw PagerDuty JSON.
pd_create_automation_action details
pd_create_automation_action details
[PagerDuty] Create an Automation Action. Not destructive: a new action runs nothing until something invokes it, and pd_delete_automation_action removes it again. Two defaults deserve a deliberate choice: allow_invocation_from_event_orchestration and allow_invocation_manually both default to true, so the action is runnable the moment it is bound to a service, and map_to_all_services set to true binds it to EVERY service on the account in one step. POST /automation_actions/actions. Required field: action. action.action_type is the discriminator and PagerDuty documents two values: script and process_automation. name, description and action_type are required on both. A script action carries action_data_reference.script - the script body the runner writes to a temp file and executes - plus an optional invocation_command naming the interpreter. A process_automation action carries action_data_reference.process_automation_job_id plus optional process_automation_job_arguments and process_automation_node_filter. runner names the runner id it executes on; services and teams bind it at creation; map_to_all_services binds it to every service. action_classification tags the action diagnostic or remediation, and only_invocable_on_unresolved_incidents, default false, confines it to unresolved incidents. PagerDuty caps an account at 10,000 actions and answers 400 beyond that. Returns raw PagerDuty JSON.
pd_create_automation_action_invocation details
pd_create_automation_action_invocation details
[PagerDuty] DESTRUCTIVE: create an Invocation. Why this is destructive: it EXECUTES the action on the customer's own runner immediately - a script or a Process Automation job runs on their infrastructure, and neither PagerDuty nor StackJack can recall it once it is sent. There is no dry run and no preview: the only way to know what it will do is to read the action first with pd_get_automation_action. POST /automation_actions/actions//invocations. Path parameters: id. Required field: invocation.metadata. PagerDuty attaches every invocation to an incident, so metadata.incident_id is required; metadata.alert_id is optional. No arguments travel in this body - what runs is whatever the action's stored definition says. Returns raw PagerDuty JSON.
pd_create_automation_action_runner details
pd_create_automation_action_runner details
[PagerDuty] DESTRUCTIVE: create an Automation Action runner. Why this is destructive: it MINTS a credential: the 201 response carries runner.secret, which PagerDuty documents as the secret a sidecar runner authenticates with, and PagerDuty does not show it again. A runbook runner instead STORES the customer's Runbook Automation API key, sent in this request body. Neither is a reversible edit, and PagerDuty caps an account at 1,000 runners. POST /automation_actions/runners. Required field: runner. runner.runner_type is the discriminator and PagerDuty documents two values: sidecar and runbook. Both require name and description. A runbook runner ALSO requires runbook_base_uri - the subdomain portion of the Runbook Automation host, alphanumerics, periods, underscores and dashes only - and runbook_api_key, the API key PagerDuty stores to reach that server. A sidecar runner takes neither and is handed a secret in the response instead. teams may bind the runner at creation. Returns raw PagerDuty JSON.
pd_delete_automation_action details
pd_delete_automation_action details
[PagerDuty] DESTRUCTIVE: delete an Automation Action. Why this is destructive: the action and its definition are gone and PagerDuty keeps no copy, so a script body that lives nowhere else is lost - read it with pd_get_automation_action first. It is also removed from every service and team it was bound to. Past invocations keep their own snapshot of the action, so the run history survives. DELETE /automation_actions/actions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_automation_action_runner details
pd_delete_automation_action_runner details
[PagerDuty] DESTRUCTIVE: delete an Automation Action runner. Why this is destructive: every action that executes through this runner stops working, and the sidecar or Runbook server on the customer's own infrastructure can no longer connect. The runner secret dies with it: a replacement runner is issued a NEW secret, so whoever owns that machine has to reconfigure it. DELETE /automation_actions/runners/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_automation_action details
pd_get_automation_action details
[PagerDuty] Get an Automation Action. Returns one Automation Action's full definition, including the action_data_reference that holds the script body or the Process Automation job id, and the allow_invocation_manually and allow_invocation_from_event_orchestration switches that decide who may run it. Reading it runs nothing. GET /automation_actions/actions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_automation_action_invocation details
pd_get_automation_action_invocation details
[PagerDuty] Get an Invocation. Returns one run: its state, the timing transitions it went through, a snapshot of the action as it was when it ran, and the agent - a user, an Event Orchestration or an incident workflow - that started it. GET /automation_actions/invocations/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_automation_action_runner details
pd_get_automation_action_runner details
[PagerDuty] Get an Automation Action runner. Returns one runner's registration: its type (sidecar or runbook), its status (Configured once it has connected to PagerDuty at least once, otherwise NotConfigured), its teams and up to three associated actions. The runner secret is NOT here - PagerDuty returns that only on the creation response. GET /automation_actions/runners/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_automation_action_runner_team details
pd_get_automation_action_runner_team details
[PagerDuty] Get the details of a runner / team relation. Answers whether one specific runner / team binding exists, and 404s when it does not. Mind the base: this is the RUNNER side, runners//teams/, while pd_get_automation_action_team is the action side. GET /automation_actions/runners//teams/. Path parameters: id, team_id. Returns raw PagerDuty JSON.
pd_get_automation_action_service details
pd_get_automation_action_service details
[PagerDuty] Get the details of an Automation Action / service relation. Answers whether one specific Automation Action / service binding exists, and 404s when it does not. GET /automation_actions/actions//services/. Path parameters: id, service_id. Returns raw PagerDuty JSON.
pd_get_automation_action_team details
pd_get_automation_action_team details
[PagerDuty] Get the details of an Automation Action / team relation. Answers whether one specific Automation Action / team binding exists, and 404s when it does not. Mind the base: this is the ACTION side, actions//teams/, while pd_get_automation_action_runner_team is the runner side. GET /automation_actions/actions//teams/. Path parameters: id, team_id. Returns raw PagerDuty JSON.
pd_list_automation_action_invocations details
pd_list_automation_action_invocations details
[PagerDuty] List Invocations. An invocation is one past or in-flight RUN of an action on a runner. PagerDuty declares no paging on this endpoint - no limit, no offset and no cursor - so the whole matching collection comes back in one response; narrow it with the filters below. GET /automation_actions/invocations. Optional filters: invocation_state, not_invocation_state, incident_id, action_id. Returns raw PagerDuty JSON.
pd_list_automation_action_runner_teams details
pd_list_automation_action_runner_teams details
[PagerDuty] Get all team references associated with a runner. Lists the teams that can use this runner. PagerDuty declares no paging on this endpoint, so the whole collection comes back in one response. GET /automation_actions/runners//teams. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_automation_action_runners details
pd_list_automation_action_runners details
[PagerDuty] List Automation Action runners. A runner is the customer's own machine or Runbook Automation instance that Automation Actions execute on. This read never returns the runner secret: PagerDuty puts that on the creation response only. GET /automation_actions/runners. Optional filters: name, include[]. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_automation_action_services details
pd_list_automation_action_services details
[PagerDuty] Get all service references associated with an Automation Action. Lists the services this Automation Action is offered on. PagerDuty declares no paging on this endpoint, so the whole collection comes back in one response. GET /automation_actions/actions//services. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_automation_action_teams details
pd_list_automation_action_teams details
[PagerDuty] Get all team references associated with an Automation Action. Lists the teams that can see and invoke this Automation Action. PagerDuty declares no paging on this endpoint, so the whole collection comes back in one response. GET /automation_actions/actions//teams. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_automation_actions details
pd_list_automation_actions details
[PagerDuty] List Automation Actions. An Automation Action is a saved script or Process Automation job that runs on a runner the customer hosts themselves. This read returns definitions only and executes nothing: use pd_get_automation_action for one action's full record, and pd_create_automation_action_invocation to actually run one. GET /automation_actions/actions. Optional filters: name, runner_id, classification, team_id, service_id, action_type. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_remove_automation_action_runner_team details
pd_remove_automation_action_runner_team details
[PagerDuty] DESTRUCTIVE: disassociate a runner from a team. Why this is destructive: the team loses access to this runner and to whatever it was running through it; pd_add_automation_action_runner_team binds it again. DELETE /automation_actions/runners//teams/. Path parameters: id, team_id. Returns raw PagerDuty JSON.
pd_remove_automation_action_service details
pd_remove_automation_action_service details
[PagerDuty] DESTRUCTIVE: disassociate an Automation Action from a service. Why this is destructive: the action stops being offered on that service, so nobody can invoke it there and an Event Orchestration that reaches for it on that service can no longer run it; pd_add_automation_action_service binds it again. DELETE /automation_actions/actions//services/. Path parameters: id, service_id. Returns raw PagerDuty JSON.
pd_remove_automation_action_team details
pd_remove_automation_action_team details
[PagerDuty] DESTRUCTIVE: disassociate an Automation Action from a team. Why this is destructive: the team loses sight of the action and can no longer invoke it; pd_add_automation_action_team binds it again. DELETE /automation_actions/actions//teams/. Path parameters: id, team_id. Returns raw PagerDuty JSON.
pd_update_automation_action details
pd_update_automation_action details
[PagerDuty] DESTRUCTIVE: update an Automation Action. Why this is destructive: an Automation Action carries the script body or the Process Automation job that RUNS on the customer's own runner, so replacing its definition changes what executes the next time anyone invokes it. This is a PUT: send the COMPLETE action object, because what you send becomes the stored definition. Read the current one with pd_get_automation_action first. PUT /automation_actions/actions/. Path parameters: id. Required field: action. action.action_type is the discriminator - script or process_automation - and it has to match the action being updated. A script action carries action_data_reference.script and an optional invocation_command; a process_automation action carries action_data_reference.process_automation_job_id with optional process_automation_job_arguments and process_automation_node_filter. The invocation switches allow_invocation_manually, allow_invocation_from_event_orchestration, only_invocable_on_unresolved_incidents and map_to_all_services are set here too, along with action_classification - diagnostic or remediation - and runner, which moves the action onto a different runner. Returns raw PagerDuty JSON.
pd_update_automation_action_runner details
pd_update_automation_action_runner details
[PagerDuty] DESTRUCTIVE: update an Automation Action runner. Why this is destructive: it STORES a credential and can move where work runs. runbook_api_key is the API key PagerDuty keeps to reach the customer's Runbook Automation server, and what you send overwrites the stored one - PagerDuty keeps the previous key only when the field is omitted entirely. runbook_base_uri re-points every action on this runner at a different Runbook host. This is a PUT: send the COMPLETE runner object. PUT /automation_actions/runners/. Path parameters: id. Required field: runner. PagerDuty declares runner_type as this body's discriminator. The sidecar shape accepts name and description. The runbook shape also accepts runbook_base_uri - the subdomain portion of the Runbook Automation host - and runbook_api_key, and PagerDuty documents that an omitted runbook_api_key leaves the stored key unchanged. Returns raw PagerDuty JSON.
Enrichment Integrations
pd_add_servicenow_table details
pd_add_servicenow_table details
[PagerDuty] Add a CMDB table. Not destructive: the table is registered with status disabled and pulls nothing until its synchronization is enabled by a separate tool; an integration holds at most 8 tables. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/integrations/servicenow//tables. Path parameters: integration_id. Send the request body as JSON with cmdb_table: display_name (the name the Event Enrichment rule editor shows), ci_table_name (the ServiceNow CMDB table, case-sensitive, for example cmdb_ci_server), optional query_filter (a ServiceNow encoded query; null synchronizes every record) and field_mappings - 2 to 20 objects of servicenow_field and event_field, of which at most 3 may set type to query and at least one must be left as an enrichment field. Returns raw PagerDuty JSON.
pd_create_servicenow_credentials details
pd_create_servicenow_credentials details
[PagerDuty] DESTRUCTIVE: create ServiceNow credentials. Why this is destructive: the request body carries the ServiceNow account password in clear text and PagerDuty STORES it as the credential every CMDB table sync and table test authenticates with. An account holds ONE credential set, so a second create is refused while one exists, and PagerDuty declares the ServiceNow password write-only: it is accepted in a request and never returned in a response, so no read recovers it - a lost password can only be replaced, never read back. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/integrations/servicenow/credentials. Send the request body as JSON with credentials: instance_endpoint (the ServiceNow instance URL), user (a ServiceNow account with read access to the CMDB tables) and password. All three are required. The response echoes the record WITHOUT the password. Returns raw PagerDuty JSON.
pd_create_servicenow_integration details
pd_create_servicenow_integration details
[PagerDuty] Create a ServiceNow integration. Not destructive: a new integration synchronizes nothing until a CMDB table is added to it and that table's sync is enabled; PagerDuty allows ONE integration per account, so a second create is refused while one exists. The 201 answers with the whole integration object, which embeds the account's stored ServiceNow credential record - the instance URL and the service-account username, never the password. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/integrations/servicenow. Send the request body as JSON with name, optional description and cmdb_tables - 1 to 8 table configurations, each with display_name, ci_table_name, optional query_filter and 2 to 20 field_mappings of servicenow_field and event_field. Credentials are NOT part of this body: they are stored once per account by the credentials tools. Returns raw PagerDuty JSON.
pd_delete_servicenow_credentials details
pd_delete_servicenow_credentials details
[PagerDuty] DESTRUCTIVE: delete ServiceNow credentials. Why this is destructive: the stored ServiceNow credential is destroyed and every table synchronization and table test that authenticated with it stops. PagerDuty refuses the call while a ServiceNow integration still exists, so the integration has to go first, and the password cannot be read back before deleting - it is write-only, so it has to be re-entered from the customer's own record. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/integrations/servicenow/credentials/. Path parameters: credentials_id. Returns raw PagerDuty JSON.
pd_delete_servicenow_integration details
pd_delete_servicenow_integration details
[PagerDuty] DESTRUCTIVE: delete a ServiceNow integration. Why this is destructive: it destroys the integration with every CMDB table configuration under it AND the enrichment schemas those tables generated, and disables their synchronization; every enrichment rule reading one of those schemas stops enriching from the next event onward. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/integrations/servicenow/. Path parameters: integration_id. Returns raw PagerDuty JSON.
pd_delete_servicenow_table details
pd_delete_servicenow_table details
[PagerDuty] DESTRUCTIVE: remove a CMDB table. Why this is destructive: the table's generated enrichment schema is removed and its synchronization is disabled, so every enrichment rule reading that schema stops enriching from the next event onward. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/integrations/servicenow//tables/. Path parameters: integration_id, table_id. Returns raw PagerDuty JSON.
pd_enable_servicenow_table_sync details
pd_enable_servicenow_table_sync details
[PagerDuty] DESTRUCTIVE: enable CMDB table sync. Why this is destructive: it starts a LIVE synchronization that pulls Configuration Items out of the customer's own ServiceNow instance into PagerDuty and keeps pulling them on a schedule. This API declares no disable endpoint, so the only way to stop it again is to remove the table or the whole integration, and the table can no longer be edited once its first backfill has started. The call itself is idempotent - enabling an already-enabled table succeeds. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/integrations/servicenow//tables//enable. Path parameters: integration_id, table_id. Returns raw PagerDuty JSON.
pd_get_servicenow_credentials details
pd_get_servicenow_credentials details
[PagerDuty] Get ServiceNow credentials. Returns the stored ServiceNow credential record - id, instance_endpoint, user and the timestamps. PagerDuty declares the ServiceNow password write-only: it is accepted in a request and never returned in a response, so no read recovers it, and an account holds at most one credential set. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/integrations/servicenow/credentials/. Path parameters: credentials_id. Returns raw PagerDuty JSON.
pd_get_servicenow_integration details
pd_get_servicenow_integration details
[PagerDuty] Get a ServiceNow integration. Returns the integration with its CMDB tables, their field mappings, the current sync status of each table (disabled, syncing, active or error) and the account's credential record - never the password, which PagerDuty declares write-only. An account holds at most one ServiceNow integration. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/integrations/servicenow/. Path parameters: integration_id. Returns raw PagerDuty JSON.
pd_list_servicenow_integrations details
pd_list_servicenow_integrations details
[PagerDuty] List ServiceNow integrations. PagerDuty allows ONE ServiceNow integration per account, so this returns at most one, with its CMDB tables, field mappings and credential record. There are no paging parameters on this endpoint. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/integrations/servicenow. Returns raw PagerDuty JSON.
pd_test_servicenow_table details
pd_test_servicenow_table details
[PagerDuty] Test a CMDB table. This read runs a LIVE query against the customer's own ServiceNow instance with the stored credentials and returns up to 10 sample records. They come back keyed by ServiceNow field name, NOT by the mapped event_field names. Use it to check the table name, the query filter and the mappings before enabling synchronization - a misconfigured table answers 400 here instead of failing after it is live. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/integrations/servicenow//tables//test. Path parameters: integration_id, table_id. Returns raw PagerDuty JSON.
pd_update_servicenow_credentials details
pd_update_servicenow_credentials details
[PagerDuty] DESTRUCTIVE: update ServiceNow credentials. Why this is destructive: sending password OVERWRITES the stored ServiceNow password, which PagerDuty keeps no copy of and never returns, so every table synchronization and test authenticates with the new one from that moment and a wrong value puts the tables into status error. The update is partial: only the fields present in the body are changed. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/integrations/servicenow/credentials/. Path parameters: credentials_id. Send the request body as JSON with credentials and only the fields to change: instance_endpoint, user and/or password. The response echoes the record WITHOUT the password. Returns raw PagerDuty JSON.
pd_update_servicenow_table details
pd_update_servicenow_table details
[PagerDuty] DESTRUCTIVE: update a CMDB table. Why this is destructive: it is a FULL replacement of the table configuration - ci_table_name and the COMPLETE field_mappings list must be sent, and any mapping left out is dropped, which silently stops the event fields it was enriching. PagerDuty only accepts it while the table's synchronization is disabled and before its first backfill has started, and refuses it afterwards. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/integrations/servicenow//tables/. Path parameters: integration_id, table_id. Send the request body as JSON with cmdb_table: display_name (the name the Event Enrichment rule editor shows), ci_table_name (the ServiceNow CMDB table, case-sensitive, for example cmdb_ci_server), optional query_filter (a ServiceNow encoded query; null synchronizes every record) and field_mappings - 2 to 20 objects of servicenow_field and event_field, of which at most 3 may set type to query and at least one must be left as an enrichment field. Returns raw PagerDuty JSON.
Enrichment Schemas
pd_create_enrichment_schema details
pd_create_enrichment_schema details
[PagerDuty] Create an enrichment schema. Not destructive: a new schema holds no records and enriches nothing until records are uploaded into it and an enrichment rule reads it; an account may hold at most 25 CSV schemas. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/schemas. Optional filters: filename. Send the request body as JSON with name (up to 50 characters), optional description (up to 2048) and fields - 2 to 25 objects of name and type, where type is query or enriched. 1 to 3 fields must be query and at least one must be enriched, and field names are unique case-insensitively. integration_type accepts only CSV and the schema is recorded as CSV whatever is sent. PagerDuty also accepts a CSV file on this route to derive a schema from its columns; this tool sends the JSON definition. Returns raw PagerDuty JSON.
pd_delete_enrichment_record details
pd_delete_enrichment_record details
[PagerDuty] DESTRUCTIVE: delete an enrichment record. Why this is destructive: the record is removed from a live schema, so any enrichment rule that was matching it stops finding it from the next event onward; PagerDuty answers with the deleted record and keeps no other copy. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/schemas//records/. Path parameters: schema_id, record_id. Returns raw PagerDuty JSON.
pd_delete_enrichment_schema details
pd_delete_enrichment_schema details
[PagerDuty] DESTRUCTIVE: delete an enrichment schema. Why this is destructive: it soft-deletes the schema, so every record uploaded into it stops being queryable and every enrichment rule pointing at it stops enriching; PagerDuty answers with the deleted schema. Only a CSV schema can be deleted - a SERVICENOW schema belongs to the CMDB integration and is refused here. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/schemas/. Path parameters: schema_id. Returns raw PagerDuty JSON.
pd_get_enrichment_schema details
pd_get_enrichment_schema details
[PagerDuty] Get an enrichment schema. Returns the schema definition: its name, its integration_type (CSV for a schema created through this API, SERVICENOW for one the CMDB integration generates) and its query and enriched fields. The records held in it are a separate read. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/schemas/. Path parameters: schema_id. Returns raw PagerDuty JSON.
pd_list_enrichment_schema_records details
pd_list_enrichment_schema_records details
[PagerDuty] List enrichment records. Returns the records uploaded into one schema, each as enrichment_data keyed by field name. A populated schema holds far more rows than one page: follow next_cursor until it comes back null. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/schemas//records. Path parameters: schema_id. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_enrichment_schemas details
pd_list_enrichment_schemas details
[PagerDuty] List enrichment schemas. PagerDuty declares no paging parameters on this endpoint, so every schema in the account comes back in one response - the CSV schemas created through this API (at most 25) and the schemas the ServiceNow CMDB integration generates. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/schemas. Returns raw PagerDuty JSON.
pd_query_enrichment_data details
pd_query_enrichment_data details
[PagerDuty] Query enrichment data. This is a POST-shaped READ: the schema id and the field values to match travel in the request body and nothing is written. Send 1 to 3 query field/value pairs; ALL of them must match, and matching is case-insensitive. A standard schema answers with 0 or 1 record; a schema that uses a discriminator field can answer with several. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/query. Send the request body as JSON with schema_id (the enrichment schema UUID) and query, an array of 1 to 3 objects of field and value - for example schema_id 9f194d8d-0f58-4c5c-b1d2-a5adf7171821 with query [{field: Application, value: Authorization}]. Returns raw PagerDuty JSON.
pd_update_enrichment_schema details
pd_update_enrichment_schema details
[PagerDuty] Update an enrichment schema. Not destructive: this route only changes the schema's name and/or description - at least one of the two must be sent - and a schema's fields cannot be changed after it is created, so no record and no enrichment rule can break as a result. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/schemas/. Path parameters: schema_id. Send the request body as JSON with schema: name (up to 50 characters) and/or description (up to 2048). At least one of the two is required and no other field is accepted. Returns raw PagerDuty JSON.
pd_upload_enrichment_schema_records details
pd_upload_enrichment_schema_records details
[PagerDuty] DESTRUCTIVE: upload CSV records. Why this is destructive: it bulk-loads rows into a live schema that event enrichment reads, and the load is an UPSERT - a row whose query-field values match an existing record OVERWRITES that record - with no undo. PagerDuty accepts the file ASYNCHRONOUSLY and answers 202 with an upload_id, so the rows are not in the schema yet when the call returns and a malformed file fails later, out of band. PagerDuty declares two request shapes for this route - multipart/form-data with a required file part, or a raw text/csv body - each capped at 10 MB, and StackJack sends the bytes as text/csv; the CSV columns must line up with the schema's fields, a missing column writes empty values and an extra column is ignored. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/schemas//records. Path parameters: schema_id. Optional filters: filename. The file arrives EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl - exactly one of the two, never both. StackJack fetches an https URL server-side and refuses a non-https URL, a redirect to a different host, or anything over the size cap named on those parameters. Returns raw PagerDuty JSON.
Event Enrichments
pd_add_event_enrichment_associations details
pd_add_event_enrichment_associations details
[PagerDuty] DESTRUCTIVE: add Event Enrichment associations. Why this is destructive: it attaches a LIVE Event Enrichment to the named Services and Event Orchestrations, so their incoming events are enriched differently from the next event onward, and it is a batch that can partially succeed - PagerDuty answers 207 when some targets were attached and others were not, which leaves the enrichment applied to only part of what was asked for. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/event_enrichments//associations. Path parameters: id. Send the request body as JSON with associations, an array of objects of type (service_reference or event_orchestration_reference) and id - the Service id or the Event Orchestration id. PagerDuty answers 207 when only some of them were applied, so read the per-association status in the body rather than the HTTP code alone. Returns raw PagerDuty JSON.
pd_create_event_enrichment details
pd_create_event_enrichment details
[PagerDuty] Create an Event Enrichment. Not destructive: a new Event Enrichment is inert: it enriches nothing until it is associated with a Service or an Event Orchestration, or made the account default, and its rules are written by a separate tool. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. POST /enrichment/event_enrichments. Send the request body as JSON with event_enrichment: name, optional description and optional team.id - those are the only writable fields. Everything else PagerDuty returns on the object (id, is_default, the association counts, privileges, the timestamps and self) is read-only and ignored on the way in. Returns raw PagerDuty JSON.
pd_delete_event_enrichment details
pd_delete_event_enrichment details
[PagerDuty] DESTRUCTIVE: delete an Event Enrichment. Why this is destructive: the enrichment stops running, so the fields it was adding stop appearing on live events for every Service and Event Orchestration it was associated with, and PagerDuty keeps no copy. It also requires Delete privileges on the enrichment AND on every item associated with it, so a caller holding only some of them gets a 403 rather than a partial delete. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/event_enrichments/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_event_enrichment_associations details
pd_delete_event_enrichment_associations details
[PagerDuty] DESTRUCTIVE: delete Event Enrichment associations. Why this is destructive: the named Services and Event Orchestrations stop being enriched from the next event onward - they fall back to the account default if one is set, and to no enrichment at all if none is - and it is a batch that can partially succeed, so a 207 means only some of them were detached. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. DELETE /enrichment/event_enrichments//associations. Path parameters: id. Send the request body as JSON with associations, an array of objects of type (service_reference or event_orchestration_reference) and id - the Service id or the Event Orchestration id. PagerDuty answers 207 when only some of them were applied, so read the per-association status in the body rather than the HTTP code alone. Returns raw PagerDuty JSON.
pd_get_default_event_enrichment details
pd_get_default_event_enrichment details
[PagerDuty] Get the account default Event Enrichment. The account default Event Enrichment is the one applied to every Service and Event Orchestration that is not associated with a more specific enrichment. The response carries default (null when the account has no default) and previous_default, which is only present after a change. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/event_enrichments/default. Returns raw PagerDuty JSON.
pd_get_event_enrichment details
pd_get_event_enrichment details
[PagerDuty] Get an Event Enrichment. Returns one Event Enrichment: its name, description, owning team, whether it is the account default, and how many Services and Event Orchestrations are associated with it. Its rules and the list of associated items are separate reads. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/event_enrichments/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_event_enrichment_associations details
pd_list_event_enrichment_associations details
[PagerDuty] List Event Enrichment associations. Lists the Services and Event Orchestrations one Event Enrichment is attached to. This endpoint's own spec declares no maximum for limit and StackJack clamps it to 100 - PagerDuty's documented general ceiling for offset-paged reads - and an associated item the API key cannot view is silently left out of the results rather than reported. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/event_enrichments//associations. Path parameters: id. Optional filters: association_type. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_event_enrichment_rules details
pd_list_event_enrichment_rules details
[PagerDuty] Get Event Enrichment rules. Despite the name this returns ONE object, not a page: the enrichment's orchestration_path, whose sets carry the rules, each with its conditions and either extractions or enrichments actions. There are no paging parameters. Read this before pd_update_event_enrichment_rules, which replaces the whole set. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/event_enrichments//rules. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_event_enrichments details
pd_list_event_enrichments details
[PagerDuty] List Event Enrichments. Lists every Event Enrichment in the account with its name, owning team and association counts. This endpoint's own spec declares no maximum for limit and StackJack clamps it to 100 - PagerDuty's documented general ceiling for offset-paged reads. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. GET /enrichment/event_enrichments. Optional filters: include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_set_default_event_enrichment details
pd_set_default_event_enrichment details
[PagerDuty] DESTRUCTIVE: mark an Event Enrichment as the account default. Why this is destructive: it changes the ACCOUNT DEFAULT, so every Service and Event Orchestration that is not associated with a more specific enrichment is enriched by the new one from the next event onward; sending default as null CLEARS the default instead, which stops default enrichment account-wide with no other signal. The response returns the enrichment that was replaced as previous_default - keep it if you may need to put it back. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/event_enrichments/default. Send the request body as JSON with default: an object of id (the Event Enrichment id) and type set to event_enrichment_reference - or the literal null to clear the account default. Returns raw PagerDuty JSON.
pd_update_event_enrichment details
pd_update_event_enrichment details
[PagerDuty] DESTRUCTIVE: update an Event Enrichment. Why this is destructive: the PUT REPLACES the stored enrichment with the object you send, and team is the ACCESS CONTROL on it: leave team out and PagerDuty removes the team that owns this enrichment. name and description go the same way, and PagerDuty keeps no prior version. Only those three are writable, so there is no way to say "leave team alone" - read the object with pd_get_event_enrichment first and send back what you want to keep. The enrichment's RULES and its service and orchestration ASSOCIATIONS are untouched here: they live behind separate tools. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/event_enrichments/. Path parameters: id. Send the request body as JSON with event_enrichment: name, description and/or team.id. Every other field PagerDuty returns on the object is read-only. Returns raw PagerDuty JSON.
pd_update_event_enrichment_rules details
pd_update_event_enrichment_rules details
[PagerDuty] DESTRUCTIVE: update Event Enrichment rules. Why this is destructive: it REPLACES the enrichment's whole rule set: rules you leave out are removed, the fields they were adding stop appearing on live events, and PagerDuty keeps no prior version. Read the current rules with pd_list_event_enrichment_rules and send them back with your edit. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. Access is granted per account - contact your PagerDuty account team - and an account that has not been granted it answers 403. No header is sent: this group declares none. PUT /enrichment/event_enrichments//rules. Path parameters: id. Send the request body as JSON with orchestration_path.sets - an array of rule sets, one of which MUST have id start. Each rule carries label, conditions (each one a PCL expression), optional disabled, and actions, which is EITHER extractions (target plus template, or source plus a RE2 regex; at most 25 per rule) OR enrichments (schema_to_search, search_values and target; at most one per rule). Returns raw PagerDuty JSON.
Escalation Policies
pd_create_escalation_policy details
pd_create_escalation_policy details
[PagerDuty] Create an escalation policy. Not destructive: additive: a new policy pages nobody until a service is pointed at it, and deleting it is a separate tool. POST /escalation_policies. Send the request body as JSON; PagerDuty documents these fields: escalation_policy.type, escalation_policy.name, escalation_policy.description, escalation_policy.num_loops, escalation_policy.on_call_handoff_notifications, escalation_policy.escalation_rules, escalation_policy.services, escalation_policy.teams. Returns raw PagerDuty JSON.
pd_delete_escalation_policy details
pd_delete_escalation_policy details
[PagerDuty] DESTRUCTIVE: delete an escalation policy. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /escalation_policies/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_escalation_policy details
pd_get_escalation_policy details
[PagerDuty] Get an escalation policy. GET /escalation_policies/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_escalation_policies details
pd_list_escalation_policies details
[PagerDuty] List escalation policies. GET /escalation_policies. Optional filters: query, user_ids[], team_ids[], include[], sort_by. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_escalation_policy_audit_records details
pd_list_escalation_policy_audit_records details
[PagerDuty] List audit records for an escalation policy. GET /escalation_policies//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_update_escalation_policy details
pd_update_escalation_policy details
[PagerDuty] DESTRUCTIVE: update an escalation policy. Why this is destructive: PagerDuty replaces the rule set with what you send, so omitting rules removes them and nobody is escalated to at those levels. Send the COMPLETE escalation_rules list. The policy can be edited again, but only after you have read the current rules back. PUT /escalation_policies/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: escalation_policy.type, escalation_policy.name, escalation_policy.description, escalation_policy.num_loops, escalation_policy.on_call_handoff_notifications, escalation_policy.escalation_rules, escalation_policy.services, escalation_policy.teams. Returns raw PagerDuty JSON.
Event Orchestrations
pd_create_orchestration details
pd_create_orchestration details
[PagerDuty] DESTRUCTIVE: create an Orchestration. Why this is destructive: it MINTS a routing key. PagerDuty creates a Default Integration with the new orchestration and its 201 response carries that integration's live 32-character routing_key, which can open incidents on this account from anywhere. The orchestration itself routes nothing until a monitoring tool starts sending to that key and pd_update_orchestration_router_path gives it rules. POST /event_orchestrations. The request body as JSON: { "orchestration": { "name": "...", "description": "...", "team": { "id": "PXXXXXX" } } }. Only name, description and team are writable; id, self, integrations, routes, created_at, created_by, updated_at, updated_by and version are read-only and are ignored on the way in. Omitting team leaves the orchestration accessible to admins only. Returns raw PagerDuty JSON.
pd_create_orchestration_cache_variable details
pd_create_orchestration_cache_variable details
[PagerDuty] Create a Cache Variable for a Global Event Orchestration. Not destructive: additive: a new cache variable is evaluated but nothing reads it until a rule names it. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. POST /event_orchestrations//cache_variables. Path parameters: id. The request body as JSON: { "cache_variable": { "name": "...", "disabled": false, "conditions": [ { "expression": "..." } ], "configuration": } }. configuration.type picks the shape: recent_value takes source and regex, trigger_event_count takes ttl_seconds, external_data takes data_type (string, number or boolean) and ttl_seconds. id, created_at, created_by, updated_at and updated_by are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_create_orchestration_integration details
pd_create_orchestration_integration details
[PagerDuty] DESTRUCTIVE: create an Integration for an Event Orchestration. Why this is destructive: it MINTS a routing key that can open incidents on this account from anywhere, and the 201 response returns that live 32-character routing_key. Treat the result as a credential: anyone holding the key can page this account's on-call through pd_send_event. POST /event_orchestrations//integrations. Path parameters: id. The request body as JSON: { "integration": { "label": "..." } }. label is the only writable field and it is required; id and parameters.routing_key are read-only and are what PagerDuty hands back. Returns raw PagerDuty JSON.
pd_create_service_orchestration_cache_variable details
pd_create_service_orchestration_cache_variable details
[PagerDuty] Create a Cache Variable for a Service Event Orchestration. Not destructive: additive: a new cache variable is evaluated but nothing reads it until a rule on this service's orchestration names it. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. POST /event_orchestrations/services//cache_variables. Path parameters: service_id. The request body as JSON: { "cache_variable": { "name": "...", "disabled": false, "conditions": [ { "expression": "..." } ], "configuration": } }. configuration.type picks the shape: recent_value takes source and regex, trigger_event_count takes ttl_seconds, external_data takes data_type (string, number or boolean) and ttl_seconds. id, created_at, created_by, updated_at and updated_by are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_delete_orchestration details
pd_delete_orchestration details
[PagerDuty] DESTRUCTIVE: delete an Orchestration. Why this is destructive: deleting an Event Orchestration destroys its Router, Global and Unrouted rule sets and every integration created on it, so every routing key it issued stops routing and the monitoring tools still sending to those keys are silently dropped. PagerDuty keeps no copy. DELETE /event_orchestrations/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_orchestration_cache_variable details
pd_delete_orchestration_cache_variable details
[PagerDuty] DESTRUCTIVE: delete a Cache Variable for a Global Event Orchestration. Why this is destructive: the variable and its stored value are gone and any live orchestration rule that matches on it stops finding it, so those rules stop firing from the next event onward. DELETE /event_orchestrations//cache_variables/. Path parameters: id, cache_variable_id. Returns raw PagerDuty JSON.
pd_delete_orchestration_cache_variable_data details
pd_delete_orchestration_cache_variable_data details
[PagerDuty] DESTRUCTIVE: delete Data for an External Data Cache Variable on a Global Event Orchestration. Why this is destructive: the external-data value live orchestration rules are matching on is cleared, so every rule that tests it behaves differently from the next event onward. The variable itself survives; only its value is gone, and only a new pd_set_orchestration_cache_variable_data call restores one. DELETE /event_orchestrations//cache_variables//data. Path parameters: id, cache_variable_id. Returns raw PagerDuty JSON.
pd_delete_orchestration_integration details
pd_delete_orchestration_integration details
[PagerDuty] DESTRUCTIVE: delete an Integration for an Event Orchestration. Why this is destructive: the routing key that integration issued stops working immediately, and every monitoring tool still sending events to it is silently dropped - no incident opens and nobody is paged. PagerDuty does not re-issue the same key, so recovery means creating a new integration and reconfiguring every tool that used the old one. DELETE /event_orchestrations//integrations/. Path parameters: id, integration_id. Returns raw PagerDuty JSON.
pd_delete_service_orchestration_cache_var_data details
pd_delete_service_orchestration_cache_var_data details
[PagerDuty] DESTRUCTIVE: delete Data for an External Data Cache Variable on a Service Event Orchestration. Why this is destructive: the external-data value live rules on this service's orchestration are matching on is cleared, so every rule that tests it behaves differently from the next event onward. The variable itself survives; only its value is gone, and only a new pd_set_service_orchestration_cache_var_data call restores one. DELETE /event_orchestrations/services//cache_variables//data. Path parameters: service_id, cache_variable_id. Returns raw PagerDuty JSON.
pd_delete_service_orchestration_cache_variable details
pd_delete_service_orchestration_cache_variable details
[PagerDuty] DESTRUCTIVE: delete a Cache Variable for a Service Event Orchestration. Why this is destructive: the variable and its stored value are gone and any live rule on this service's orchestration that matches on it stops finding it, so those rules stop firing from the next event onward. DELETE /event_orchestrations/services//cache_variables/. Path parameters: service_id, cache_variable_id. Returns raw PagerDuty JSON.
pd_get_orchestration details
pd_get_orchestration details
[PagerDuty] Get an Orchestration. The response is the FULL Orchestration object, and its integrations member carries each integration's live 32-character routing KEY (Orchestration.integrations[].parameters.routing_key), which can open incidents on this account from anywhere - handle the result as a credential. The routing RULES are separate reads: pd_get_orchestration_router_path, pd_get_orchestration_global_path and pd_get_orchestration_unrouted_path. GET /event_orchestrations/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_orchestration_cache_variable details
pd_get_orchestration_cache_variable details
[PagerDuty] Get a Cache Variable for a Global Event Orchestration. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. configuration.type says which of the three this one is, and disabled says whether rules are still evaluating it. GET /event_orchestrations//cache_variables/. Path parameters: id, cache_variable_id. Returns raw PagerDuty JSON.
pd_get_orchestration_cache_variable_data details
pd_get_orchestration_cache_variable_data details
[PagerDuty] Get Data for an External Data Cache Variable on a Global Event Orchestration. Reads the CURRENT VALUE of an external_data type Cache Variable - the value live orchestration rules are matching on right now. Only external_data variables have data, and PagerDuty drops the value once the variable's ttl_seconds has passed. GET /event_orchestrations//cache_variables//data. Path parameters: id, cache_variable_id. Returns raw PagerDuty JSON.
pd_get_orchestration_global_path details
pd_get_orchestration_global_path details
[PagerDuty] Get the Global Orchestration for an Event Orchestration. The Global rules run on the events this orchestration receives. There is at least a start set and rules may route to further sets to form a directional graph; catch_all.actions (suppress, suspend, drop_event, severity, priority, annotate and the rest) applies when no rule matched. GET /event_orchestrations//global. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_orchestration_integration details
pd_get_orchestration_integration details
[PagerDuty] Get an Integration for an Event Orchestration. The response carries the integration's live 32-character routing KEY (integration.parameters.routing_key), which can open incidents on this account from anywhere - handle the result as a credential. This is the key a monitoring tool sends events to; pd_send_event is the tool that uses one. GET /event_orchestrations//integrations/. Path parameters: id, integration_id. Returns raw PagerDuty JSON.
pd_get_orchestration_router_path details
pd_get_orchestration_router_path details
[PagerDuty] Get the Router for an Event Orchestration. The Router is the first thing an event meets. PagerDuty's own words: it contains a single start set, evaluates events against those rules one at a time and routes each event to a specific Service on the first rule that matches; catch_all.actions.route_to with the value unrouted sends everything else to the Unrouted Orchestration. Read this before changing anything - pd_update_orchestration_router_path REPLACES the whole set. GET /event_orchestrations//router. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_orchestration_unrouted_path details
pd_get_orchestration_unrouted_path details
[PagerDuty] Get the Unrouted Orchestration for an Event Orchestration. The Unrouted Orchestration handles the events the Router matched no rule for - what the Router's catch_all sends here. Same shape as the other paths: at least a start set, plus catch_all actions for events no unrouted rule matched. GET /event_orchestrations//unrouted. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_service_orchestration_active_status details
pd_get_service_orchestration_active_status details
[PagerDuty] Get the Service Orchestration active status for a Service. Answers whether the service's Event Orchestration is switched on. While it is off, events reaching the service are handled by the service's default behaviour instead of these rules - so a rule set that looks wrong may simply be inactive. GET /event_orchestrations/services//active. Path parameters: service_id. Returns raw PagerDuty JSON.
pd_get_service_orchestration_cache_var_data details
pd_get_service_orchestration_cache_var_data details
[PagerDuty] Get Data for an External Data Cache Variable on a Service Event Orchestration. Reads the CURRENT VALUE of an external_data type Cache Variable on a service's orchestration - the value live rules are matching on right now. Only external_data variables have data, and PagerDuty drops the value once the variable's ttl_seconds has passed. GET /event_orchestrations/services//cache_variables//data. Path parameters: service_id, cache_variable_id. Returns raw PagerDuty JSON.
pd_get_service_orchestration_cache_variable details
pd_get_service_orchestration_cache_variable details
[PagerDuty] Get a Cache Variable for a Service Event Orchestration. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. configuration.type says which of the three this one is, and disabled says whether rules are still evaluating it. GET /event_orchestrations/services//cache_variables/. Path parameters: service_id, cache_variable_id. Returns raw PagerDuty JSON.
pd_get_service_orchestration_path details
pd_get_service_orchestration_path details
[PagerDuty] Get the Service Orchestration for a Service. A Service Orchestration is the rule set belonging to ONE service, applied after the Global Orchestration's Router has routed the event to it. Its catch_all actions can suppress, suspend, re-prioritise, re-route the escalation policy or annotate whatever matched no rule. GET /event_orchestrations/services/. Path parameters: service_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_event_orchestration_feature_enablements details
pd_list_event_orchestration_feature_enablements details
[PagerDuty] List Enablements for an Event Orchestration. Feature enablements are the product add-ons switched on for this orchestration. PagerDuty currently documents exactly one, aiops, and the response carries any warnings that apply to it. PagerDuty declares no limit, offset or cursor on this endpoint, so the whole collection comes back in one response and StackJack invents no page parameters. GET /event_orchestrations//enablements. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_event_orchestrations details
pd_list_event_orchestrations details
[PagerDuty] List Event Orchestrations. A Global Event Orchestration is the account-level routing layer an event meets BEFORE any service: its Router decides which service each event lands on (pd_get_orchestration_router_path) and its Unrouted path handles what no route matched (pd_get_orchestration_unrouted_path). These rows carry NO routing keys - the per-orchestration read pd_get_orchestration returns those. GET /event_orchestrations. Optional filters: sort_by. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_orchestration_cache_variables details
pd_list_orchestration_cache_variables details
[PagerDuty] List Cache Variables for a Global Event Orchestration. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. PagerDuty declares no limit, offset or cursor on this endpoint, so the whole collection comes back in one response and StackJack invents no page parameters. GET /event_orchestrations//cache_variables. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_orchestration_integrations details
pd_list_orchestration_integrations details
[PagerDuty] List Integrations for an Event Orchestration. The response carries each integration's live 32-character routing KEY (integrations[].parameters.routing_key), which can open incidents on this account from anywhere - handle the result as a credential. PagerDuty declares no limit, offset or cursor on this endpoint, so the whole collection comes back in one response and StackJack invents no page parameters. GET /event_orchestrations//integrations. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_service_orchestration_cache_variables details
pd_list_service_orchestration_cache_variables details
[PagerDuty] List Cache Variables for a Service Event Orchestration. A Cache Variable remembers something across events - the most recent value matched out of an event (recent_value), how many trigger events arrived in a window (trigger_event_count), or a value pushed in through the API (external_data) - and live orchestration rules match on it. PagerDuty declares no limit, offset or cursor on this endpoint, so the whole collection comes back in one response and StackJack invents no page parameters. GET /event_orchestrations/services//cache_variables. Path parameters: service_id. Returns raw PagerDuty JSON.
pd_migrate_orchestration_integration details
pd_migrate_orchestration_integration details
[PagerDuty] DESTRUCTIVE: migrate an Integration from one Event Orchestration to another. Why this is destructive: it moves an integration - and the routing key already deployed in the customer's monitoring tools - from the orchestration named in the body to the one named in the URL, so events sent to that key are routed by the DESTINATION orchestration's rules from the moment it lands. PagerDuty publishes no reverse migration: undoing it means migrating back and hoping the source orchestration still exists. The response lists the destination's integrations with their live routing keys, so handle the result as a credential. POST /event_orchestrations//integrations/migration. Path parameters: id. The request body as JSON: { "source_id": "<orchestration id the integration is moving FROM>", "source_type": "orchestration", "integration_id": "<the integration being moved>" }. All three are required and source_type is pinned to orchestration. The DESTINATION is the id in the URL, not in the body. Returns raw PagerDuty JSON.
pd_set_orchestration_cache_variable_data details
pd_set_orchestration_cache_variable_data details
[PagerDuty] Update Data for an External Data Cache Variable on a Global Event Orchestration. Not destructive: this endpoint exists to be called repeatedly - it pushes the current value of an external_data cache variable and can be pushed again, and PagerDuty expires the value after the variable's ttl_seconds anyway. Live orchestration rules match on that value, so the change takes effect on the next event. PUT /event_orchestrations//cache_variables//data. Path parameters: id, cache_variable_id. The request body as JSON: { "cache_variable_data": <value> }, where <value> is a string, a number or a boolean matching the variable's declared data_type. Only an external_data type Cache Variable has data; PagerDuty keeps the value for the variable's ttl_seconds and then drops it. Returns raw PagerDuty JSON.
pd_set_service_orchestration_active_status details
pd_set_service_orchestration_active_status details
[PagerDuty] DESTRUCTIVE: update the Service Orchestration active status for a Service. Why this is destructive: switching a service's Event Orchestration off returns every incoming event to the service's default handling, which changes what is suppressed, what is escalated and who is paged from the next event onward. The rules are not deleted - switching it back on restores them. PUT /event_orchestrations/services//active. Path parameters: service_id. The request body as JSON: { "active": true } or { "active": false }. active is the only field this endpoint takes. Returns raw PagerDuty JSON.
pd_set_service_orchestration_cache_var_data details
pd_set_service_orchestration_cache_var_data details
[PagerDuty] Update Data for an External Data Cache Variable on a Service Event Orchestration. Not destructive: this endpoint exists to be called repeatedly - it pushes the current value of an external_data cache variable on a service's orchestration and can be pushed again, and PagerDuty expires the value after the variable's ttl_seconds anyway. Live rules match on that value, so the change takes effect on the next event. PUT /event_orchestrations/services//cache_variables//data. Path parameters: service_id, cache_variable_id. The request body as JSON: { "cache_variable_data": <value> }, where <value> is a string, a number or a boolean matching the variable's declared data_type. Only an external_data type Cache Variable has data; PagerDuty keeps the value for the variable's ttl_seconds and then drops it. Returns raw PagerDuty JSON.
pd_update_event_orchestration_feature_enablements details
pd_update_event_orchestration_feature_enablements details
[PagerDuty] DESTRUCTIVE: update an Enablement for an Event Orchestration. Why this is destructive: it turns a whole product add-on on or off for this Event Orchestration, which changes how every event flowing through it is processed - switching aiops off stops the AIOps features its rules depend on and the response may return warnings explaining what is now ineligible. PUT /event_orchestrations//enablements/. Path parameters: id, feature_name. The request body as JSON: { "enablement": { "enabled": true } }. enabled is the only writable field; feature, updated_at and warnings are read-only. Returns raw PagerDuty JSON.
pd_update_orchestration details
pd_update_orchestration details
[PagerDuty] DESTRUCTIVE: update an Orchestration. Why this is destructive: the PUT REPLACES the stored orchestration with the object you send, and team is the ACCESS CONTROL on it: leave team out and PagerDuty removes the team that owns this orchestration, after which - in PagerDuty's own words - only admins have access to routing that is still live. name and description go the same way, and PagerDuty keeps no prior version. The routing RULES are untouched here: they live behind pd_update_orchestration_router_path, pd_update_orchestration_global_path and pd_update_orchestration_unrouted_path. Read the object with pd_get_orchestration first and send back what you want to keep; the response returns every integration's live routing key. PUT /event_orchestrations/. Path parameters: id. The request body as JSON: { "orchestration": { "name": "...", "description": "...", "team": { "id": "PXXXXXX" } } }. Only those three are writable; id, self, integrations, routes, created_at, created_by, updated_at, updated_by and version are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_update_orchestration_cache_variable details
pd_update_orchestration_cache_variable details
[PagerDuty] DESTRUCTIVE: update a Cache Variable for a Global Event Orchestration. Why this is destructive: the PUT replaces the whole definition, so a name, condition or configuration field you leave out is gone - send every field you want to keep. Live orchestration rules MATCH on this variable, so a changed name, condition or configuration changes how events are handled from the next event onward. No incident or notification already raised is touched and the variable can be edited again. PUT /event_orchestrations//cache_variables/. Path parameters: id, cache_variable_id. The request body as JSON: { "cache_variable": { "name": "...", "disabled": false, "conditions": [ { "expression": "..." } ], "configuration": } }. configuration.type picks the shape: recent_value takes source and regex, trigger_event_count takes ttl_seconds, external_data takes data_type (string, number or boolean) and ttl_seconds. id, created_at, created_by, updated_at and updated_by are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_update_orchestration_global_path details
pd_update_orchestration_global_path details
[PagerDuty] DESTRUCTIVE: update the Global Orchestration for an Event Orchestration. Why this is destructive: it REPLACES the global rule set wholesale: sets and rules you leave out are removed, so events stop being suppressed, suspended, dropped or re-prioritised the way they were from the next event onward, and PagerDuty keeps no prior version. Read pd_get_orchestration_global_path first and send back everything you want to keep. PUT /event_orchestrations//global. Path parameters: id. The request body as JSON: { "orchestration_path": { "type": "global", "parent": { "id": "<orchestration id>", "type": "event_orchestration_reference" }, "sets": [ ... ], "catch_all": { "actions": } } }. sets[] holds the rule sets (at least one named start) and each rule carries conditions[].expression and actions; catch_all.actions applies to events no rule matched. Send the COMPLETE set - created_at, created_by, updated_at, updated_by and version are read-only. Returns raw PagerDuty JSON.
pd_update_orchestration_integration details
pd_update_orchestration_integration details
[PagerDuty] Update an Integration for an Event Orchestration. Not destructive: it renames the integration and nothing else - the routing key it already issued is unchanged and every monitoring tool sending to it keeps working. The response still carries that live routing key, so handle the result as a credential. PUT /event_orchestrations//integrations/. Path parameters: id, integration_id. The request body as JSON: { "integration": { "label": "..." } }. label is the only writable field; id and parameters.routing_key are read-only. Returns raw PagerDuty JSON.
pd_update_orchestration_router_path details
pd_update_orchestration_router_path details
[PagerDuty] DESTRUCTIVE: update the Router for an Event Orchestration. Why this is destructive: the Router decides which SERVICE each incoming event lands on, and this REPLACES its whole rule set: rules you leave out are removed and events start landing on a different service - or on nothing but the Unrouted Orchestration - from the next event onward, with no prior version kept. Read pd_get_orchestration_router_path first and send back everything you want to keep. PUT /event_orchestrations//router. Path parameters: id. The request body as JSON: { "orchestration_path": { "type": "router", "parent": { "id": "<orchestration id>", "type": "event_orchestration_reference" }, "sets": [ { "id": "start", "rules": [ ... ] } ], "catch_all": { "actions": { "route_to": "unrouted" } } } }. The Router has a single start set, evaluated one rule at a time, and each rule's actions carry route_to with the target service ID. sets[] holds the rule sets (at least one named start) and each rule carries conditions[].expression and actions; catch_all.actions applies to events no rule matched. Send the COMPLETE set - created_at, created_by, updated_at, updated_by and version are read-only. Returns raw PagerDuty JSON.
pd_update_orchestration_unrouted_path details
pd_update_orchestration_unrouted_path details
[PagerDuty] DESTRUCTIVE: update the Unrouted Orchestration for an Event Orchestration. Why this is destructive: it REPLACES the whole rule set that handles events the Router matched nothing for: rules you leave out are removed and unrouted events are handled differently from the next event onward, with no prior version kept. Read pd_get_orchestration_unrouted_path first and send back everything you want to keep. PUT /event_orchestrations//unrouted. Path parameters: id. The request body as JSON: { "orchestration_path": { "type": "unrouted", "parent": { "id": "<orchestration id>", "type": "event_orchestration_reference" }, "sets": [ ... ], "catch_all": { "actions": } } }. sets[] holds the rule sets (at least one named start) and each rule carries conditions[].expression and actions; catch_all.actions applies to events no rule matched. Send the COMPLETE set - created_at, created_by, updated_at, updated_by and version are read-only. Returns raw PagerDuty JSON.
pd_update_service_orchestration_cache_variable details
pd_update_service_orchestration_cache_variable details
[PagerDuty] DESTRUCTIVE: update a Cache Variable for a Service Event Orchestration. Why this is destructive: the PUT replaces the whole definition, so a name, condition or configuration field you leave out is gone - send every field you want to keep. Live rules on this service's orchestration MATCH on this variable, so a changed name, condition or configuration changes how events are handled from the next event onward. No incident or notification already raised is touched and the variable can be edited again. PUT /event_orchestrations/services//cache_variables/. Path parameters: service_id, cache_variable_id. The request body as JSON: { "cache_variable": { "name": "...", "disabled": false, "conditions": [ { "expression": "..." } ], "configuration": } }. configuration.type picks the shape: recent_value takes source and regex, trigger_event_count takes ttl_seconds, external_data takes data_type (string, number or boolean) and ttl_seconds. id, created_at, created_by, updated_at and updated_by are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_update_service_orchestration_path details
pd_update_service_orchestration_path details
[PagerDuty] DESTRUCTIVE: update the Service Orchestration for a Service. Why this is destructive: it REPLACES a service's whole Event Orchestration rule set: rules you leave out are removed, so events that were being suppressed, suspended, re-prioritised, annotated or sent to a different escalation policy stop being, from the next event onward, and PagerDuty keeps no prior version. Read pd_get_service_orchestration_path first and send back everything you want to keep. PUT /event_orchestrations/services/. Path parameters: service_id. The request body as JSON: { "orchestration_path": { "type": "service", "parent": { "id": "<service id>", "type": "service_reference" }, "sets": [ ... ], "catch_all": { "actions": } } }. catch_all.actions takes suppress, suspend, priority, escalation_policy, annotate, severity, event_action, variables, extractions, pagerduty_automation_actions, automation_actions and incident_custom_field_updates. sets[] holds the rule sets (at least one named start) and each rule carries conditions[].expression and actions; catch_all.actions applies to events no rule matched. Send the COMPLETE set - created_at, created_by, updated_at, updated_by and version are read-only. Returns raw PagerDuty JSON.
Recommendations
pd_accept_recommended_rule details
pd_accept_recommended_rule details
[PagerDuty] DESTRUCTIVE: accept a recommended rule. Why this is destructive: accepting WRITES the recommended rule into the service's LIVE Event Orchestration, so matching events are suppressed, re-prioritised or re-severitied from the next event onward - this is a routing change, not a bookmark. It takes no request body; the recommendation_id in the URL is the rule instance hash from pd_list_recommended_rules, and pd_delete_accepted_recommended_rule is how you take it back out. POST /recommendations/event_orchestrations/services//rules//accept. Path parameters: service_id, recommendation_id. Returns raw PagerDuty JSON.
pd_delete_accepted_recommended_rule details
pd_delete_accepted_recommended_rule details
[PagerDuty] DESTRUCTIVE: delete an accepted rule. Why this is destructive: the rule is removed from the service's LIVE Event Orchestration, so events it was suppressing, re-prioritising or re-severitying are handled by whatever matches next, from the next event onward. The recommendation returns to pd_list_recommended_rules; the rule itself is gone. DELETE /recommendations/event_orchestrations/services//accepted_rules/. Path parameters: service_id, rule_id. Returns raw PagerDuty JSON.
pd_dismiss_recommended_rule details
pd_dismiss_recommended_rule details
[PagerDuty] Dismiss a recommended rule. Not destructive: it hides a suggestion and records whether it was useful: no rule is written, no event routes differently, and nothing about the service's live orchestration changes. POST /recommendations/event_orchestrations/services//rules//dismiss. Path parameters: service_id, recommendation_id. The request body as JSON: { "decision": { "feedback": "positive" } } or { "decision": { "feedback": "negative" } }. feedback is required and PagerDuty accepts only those two values. Returns raw PagerDuty JSON.
pd_list_recommended_rules details
pd_list_recommended_rules details
[PagerDuty] List recommended rules. PagerDuty's AI proposes Service Event Orchestration rules from the account's own alert history - each row is a SUGGESTION that has not been applied. pd_accept_recommended_rule writes one into the service's live orchestration and pd_dismiss_recommended_rule hides it with feedback. GET /recommendations/event_orchestrations/rules. Optional filters: service_id, service_ids[], team_ids[], actions[]. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
Rulesets
pd_create_ruleset details
pd_create_ruleset details
[PagerDuty] DESTRUCTIVE: create a Ruleset. Why this is destructive: the 201 response hands back a live routing key. PagerDuty's own example for this endpoint returns the new ruleset already carrying a 32-character key in routing_keys, and routing_keys is read-only, so the caller cannot have supplied it - anyone holding that key can open incidents on this account from anywhere. What the spec does NOT settle is whether this call creates the key or whether the example is the Ruleset object example reused from the read, so StackJack takes the cautious verdict rather than shipping it as a routine additive create. Nothing existing is changed, and the ruleset routes nothing until Event Rules are added with pd_create_ruleset_event_rule. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. POST /rulesets. The request body as JSON: { "ruleset": { "name": "...", "team": { "id": "PXXXXXX", "type": "team_reference" } } }. name is required; team is optional and, when it is omitted, only admins have access. id, self, type, routing_keys, created_at, creator, updated_at and updater are read-only. Returns raw PagerDuty JSON.
pd_create_ruleset_event_rule details
pd_create_ruleset_event_rule details
[PagerDuty] Create an Event Rule. Not destructive: additive: it adds one rule to the ruleset. It takes effect on the next matching event and its position decides evaluation order - rules run from position 0 downward and the first match wins, so place it deliberately. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. POST /rulesets//rules. Path parameters: id. The request body as JSON: { "rule": { "disabled": false, "position": 0, "conditions": { "operator": "and", "subconditions": [ ... ] }, "time_frame": , "actions": } }. conditions.operator (and / or) and conditions.subconditions are required together; actions takes annotate, event_action, extractions, priority, severity, suppress, suspend and route (the target service ID). id, self and catch_all are read-only. Returns raw PagerDuty JSON.
pd_delete_ruleset details
pd_delete_ruleset details
[PagerDuty] DESTRUCTIVE: delete a Ruleset. Why this is destructive: deleting a ruleset destroys every Event Rule in it and the integration keys feeding it stop being processed, so events that were being suppressed, routed or re-prioritised are handled as raw events from the next event onward. PagerDuty keeps no copy. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. DELETE /rulesets/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_ruleset_event_rule details
pd_delete_ruleset_event_rule details
[PagerDuty] DESTRUCTIVE: delete an Event Rule. Why this is destructive: events that were matching this rule are handled by whatever matches next - or by the ruleset's catch_all - from the next event onward, so alerts that were being suppressed can start opening incidents. PagerDuty keeps no copy. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. DELETE /rulesets//rules/. Path parameters: id, rule_id. Returns raw PagerDuty JSON.
pd_get_ruleset details
pd_get_ruleset details
[PagerDuty] Get a Ruleset. The response carries this ruleset's routing_keys - the live 32-character keys routed to it - so handle the result as a credential. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. GET /rulesets/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_ruleset_event_rule details
pd_get_ruleset_event_rule details
[PagerDuty] Get an Event Rule. conditions says what the rule matches, actions says what it does to the resulting alert or incident, position decides when it is evaluated, and disabled says whether it is evaluated at all. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. GET /rulesets//rules/. Path parameters: id, rule_id. Returns raw PagerDuty JSON.
pd_list_ruleset_event_rules details
pd_list_ruleset_event_rules details
[PagerDuty] List Event Rules. Event Rules are evaluated in position order, starting at position 0, and the last rule of a ruleset is its read-only catch_all. Read the order here before inserting anything with pd_create_ruleset_event_rule. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. GET /rulesets//rules. Path parameters: id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_rulesets details
pd_list_rulesets details
[PagerDuty] List Rulesets. A Ruleset is the LEGACY event-routing surface: integration keys feed a ruleset and its Event Rules decide what happens. The response carries each ruleset's routing_keys - the live 32-character keys routed to it - so handle the result as a credential. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. GET /rulesets. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_ruleset details
pd_update_ruleset details
[PagerDuty] DESTRUCTIVE: update a Ruleset. Why this is destructive: the body carries the whole ruleset and the PUT REPLACES the stored one, and team is the ACCESS CONTROL on it: leave team out and PagerDuty removes the owning team, after which only admins have access to a ruleset that is still routing live events. PagerDuty keeps no prior version, so read it with pd_get_ruleset first and send back what you want to keep. routing_keys is read-only and this call does not change it, but the response returns those live 32-character keys, so handle the result as a credential. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. PUT /rulesets/. Path parameters: id. The request body as JSON: { "ruleset": { "name": "...", "team": { "id": "PXXXXXX", "type": "team_reference" } } }. Only name and team are writable; id, self, type, routing_keys, created_at, creator, updated_at and updater are read-only and are ignored on the way in. Returns raw PagerDuty JSON.
pd_update_ruleset_event_rule details
pd_update_ruleset_event_rule details
[PagerDuty] DESTRUCTIVE: update an Event Rule. Why this is destructive: it edits a LIVE routing rule. PagerDuty documents this endpoint as supporting PARTIAL updates, so a field you omit keeps its stored value - but every field you do send replaces the stored one outright, and a changed condition, action or position changes what matches from the next event onward: an alert that was being suppressed can start opening incidents and paging the on-call. position also re-orders evaluation, which can change what matches before this rule is reached, and PagerDuty keeps no prior version. END OF LIFE: PagerDuty's own description of this endpoint warns that Rulesets and Event Rules will end-of-life soon and names Event Orchestration as the replacement - build new routing with pd_create_orchestration and pd_update_orchestration_router_path, and treat these ten tools as migration and read-out only. PUT /rulesets//rules/. Path parameters: id, rule_id. The request body as JSON: { "rule": { "disabled": false, "position": 0, "conditions": { "operator": "and", "subconditions": [ ... ] }, "time_frame": , "actions": } }. PagerDuty documents partial updates here, so send only the writable fields you are changing - but a collection you do send (conditions.subconditions, actions) replaces the stored one, so read the rule with pd_get_ruleset_event_rule first. id, self and catch_all are read-only. Returns raw PagerDuty JSON.
Events API
pd_send_change_event details
pd_send_change_event details
[PagerDuty] Send change events to the PagerDuty Events API. Not destructive: a change event is timeline context, not an alert: it opens no incident and pages nobody. It is used for change correlation on incidents that open later. The routing_key is a per-SERVICE Events API v2 integration key the customer creates in PagerDuty (Service, then Integrations, then Add an integration, then Events API v2). StackJack does NOT store it: it is a call argument, it is not the REST API key this connector is configured with, and the two are not interchangeable. POST /v2/change/enqueue. Send the request body as JSON; PagerDuty documents these fields: payload.summary, payload.timestamp, payload.source, payload.custom_details, routing_key, links, images. Returns raw PagerDuty JSON.
pd_send_event details
pd_send_event details
[PagerDuty] DESTRUCTIVE: send an event to PagerDuty. Why this is destructive: a trigger event OPENS A REAL INCIDENT on the service the routing key belongs to and pages whoever is on call for it, through every channel their notification rules name; an acknowledge or resolve event changes a live incident the same way. The routing_key is a per-SERVICE Events API v2 integration key the customer creates in PagerDuty (Service, then Integrations, then Add an integration, then Events API v2). StackJack does NOT store it: it is a call argument, it is not the REST API key this connector is configured with, and the two are not interchangeable. POST /v2/enqueue. Send the request body as JSON; PagerDuty documents these fields: payload.summary, payload.timestamp, payload.severity, payload.source, payload.component, payload.group, payload.class, payload.custom_details, routing_key, event_action, dedup_key, client, client_url, links, images. Returns raw PagerDuty JSON.
pd_send_event_v1 details
pd_send_event_v1 details
[PagerDuty] DESTRUCTIVE: send an event to PagerDuty. Why this is destructive: a trigger event OPENS A REAL INCIDENT on the service the service key belongs to and pages whoever is on call for it. This is the DEPRECATED Events API v1 - new integrations should use pd_send_event (Events API v2). The service_key is the per-service Events API v1 integration key, supplied per call and never stored by StackJack. POST /generic/2010-04-15/create_event.json. Send the request body as JSON; PagerDuty documents these fields: service_key, event_type, incident_key, description, details, client, client_url, contexts. Returns raw PagerDuty JSON.
Incident Custom Fields
pd_create_incident_custom_field details
pd_create_incident_custom_field details
[PagerDuty] Create an account-level incident custom field (Base Incident Type). Not destructive: additive: the new field holds no values until one is set on an incident, and nothing about existing incidents changes. This deprecated endpoint only creates fields on the Base Incident Type; the replacement is pd_create_incident_type_custom_field. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. POST /incidents/custom_fields. Wrap the field in a field object. PagerDuty's own sample for this endpoint is {"field": {"name": "environment", "display_name": "Environment", "description": "The environment that the issue occurred in", "data_type": "string", "field_type": "single_value_fixed", "default_value": "production", "field_options": [{"data": {"data_type": "string", "value": "production"}}]}}. field_options may only be supplied for a field_type ending in _fixed. The schema ALSO lists the server-assigned id, self, summary, type, namespace, created_at and updated_at in its required array; the vendor sample sends none of them, so send only the fields above. Returns raw PagerDuty JSON.
pd_create_incident_custom_field_option details
pd_create_incident_custom_field_option details
[PagerDuty] Add a selectable option to an account-level custom field. Not destructive: additive: a new option becomes selectable but is not set on any incident until someone chooses it. This deprecated endpoint only reaches fields on the Base Incident Type; the replacement is pd_create_incident_type_custom_field_option. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. POST /incidents/custom_fields//field_options. Path parameters: field_id. Wrap the option in a field_option object. PagerDuty's own sample is {"field_option": {"data": {"data_type": "string", "value": "production"}}}. Options can only be added to a field whose field_type ends in _fixed. Returns raw PagerDuty JSON.
pd_delete_incident_custom_field details
pd_delete_incident_custom_field details
[PagerDuty] DESTRUCTIVE: delete an account-level incident custom field definition. Why this is destructive: deleting the field destroys the values recorded against it on every incident that carried it and PagerDuty keeps no copy. This deprecated endpoint only reaches fields on the Base Incident Type; the replacement is pd_delete_incident_type_custom_field. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. DELETE /incidents/custom_fields/. Path parameters: field_id. Returns raw PagerDuty JSON.
pd_delete_incident_custom_field_option details
pd_delete_incident_custom_field_option details
[PagerDuty] DESTRUCTIVE: delete one selectable option of an account-level custom field. Why this is destructive: every incident that had this option selected loses that value and PagerDuty keeps no copy. This deprecated endpoint only reaches fields on the Base Incident Type; the replacement is pd_delete_incident_type_custom_field_field_option. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. DELETE /incidents/custom_fields//field_options/. Path parameters: field_id, field_option_id. Returns raw PagerDuty JSON.
pd_get_incident_custom_field details
pd_get_incident_custom_field details
[PagerDuty] Get an account-level incident custom field definition (Base Incident Type). This returns the field's DEFINITION - name, data type, field type, default, enabled - and NOT what any incident holds in it: pd_get_incident_custom_field_values reads an incident's values. This deprecated endpoint only sees fields on the Base Incident Type; the replacement is pd_get_incident_type_custom_field. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /incidents/custom_fields/. Path parameters: field_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_incident_custom_field_options details
pd_list_incident_custom_field_options details
[PagerDuty] List the selectable options of an account-level custom field. Only a field whose field_type ends in _fixed has options. This deprecated endpoint only sees fields on the Base Incident Type; the replacement is pd_list_incident_type_custom_field_options. PagerDuty declares no paging parameters on this endpoint, so the whole collection comes back in one response. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /incidents/custom_fields//field_options. Path parameters: field_id. Returns raw PagerDuty JSON.
pd_list_incident_custom_fields details
pd_list_incident_custom_fields details
[PagerDuty] List account-level incident custom field definitions (Base Incident Type). This deprecated endpoint only sees fields on the Base Incident Type; the replacement is pd_list_incident_type_custom_fields, which lists the fields of any incident type. These are the field DEFINITIONS; pd_get_incident_custom_field_values reads the VALUES one incident holds in its fields. PagerDuty declares no paging parameters on this endpoint, so the whole collection comes back in one response. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /incidents/custom_fields. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_update_incident_custom_field details
pd_update_incident_custom_field details
[PagerDuty] Update an account-level incident custom field definition. Not destructive: it edits only display_name, description, default_value and enabled - PagerDuty's schema exposes nothing else here - and the values already recorded on incidents are untouched. This deprecated endpoint only reaches fields on the Base Incident Type; the replacement is pd_update_incident_type_custom_field. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. PUT /incidents/custom_fields/. Path parameters: field_id. Wrap the changes in a field object; PagerDuty documents display_name, description, default_value and enabled: {"field": {"display_name": "Environment", "enabled": true}}. Returns raw PagerDuty JSON.
pd_update_incident_custom_field_option details
pd_update_incident_custom_field_option details
[PagerDuty] Update one selectable option of an account-level custom field. Not destructive: it rewrites one option's value, and every incident already carrying that option reads the new text - the change is retroactive across existing incidents - but nothing is deleted and writing the old value back undoes it. This deprecated endpoint only reaches fields on the Base Incident Type; the replacement is pd_update_incident_type_custom_field_field_option. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. PUT /incidents/custom_fields//field_options/. Path parameters: field_id, field_option_id. Wrap the option in a field_option object. PagerDuty's own sample sends the new value alone: {"field_option": {"data": {"data_type": "string", "value": "prod"}}}. Its schema additionally marks id, type, created_at and updated_at required, so if a bare data body is refused, round-trip the object pd_list_incident_custom_field_options returned and change only data.value. Returns raw PagerDuty JSON.
Incident Types
pd_create_incident_type details
pd_create_incident_type details
[PagerDuty] Create an incident type. Not destructive: additive: a new type becomes selectable on new incidents and changes nothing about existing ones. name is permanent - PagerDuty does not allow it to be changed after creation - while display_name and description can be edited later. POST /incidents/types. Wrap the type in an incident_type object; PagerDuty requires name, display_name and parent_type: {"incident_type": {"name": "fraud_incident", "display_name": "Fraud Incident", "parent_type": "incident_default"}}. name may not use the _default suffix and cannot be changed afterwards, display_name may not start with PD, PagerDuty or Default, and enabled defaults to true. Returns raw PagerDuty JSON.
pd_create_incident_type_custom_field details
pd_create_incident_type_custom_field details
[PagerDuty] Create a custom field on an incident type. Not destructive: additive: the new field holds no values until one is set on an incident of that type, and incidents that already exist are unchanged. POST /incidents/types//custom_fields. Path parameters: type_id_or_name. Wrap the field in a field object; PagerDuty requires name, display_name, data_type and field_type: {"field": {"name": "custom_field_1", "display_name": "Custom Field 1", "data_type": "string", "field_type": "single_value"}}. field_type is single_value, single_value_fixed, multi_value or multi_value_fixed; field_options may only be supplied for the two _fixed types and is REQUIRED for them, because PagerDuty refuses to create a fixed-value field with no options. Returns raw PagerDuty JSON.
pd_create_incident_type_custom_field_option details
pd_create_incident_type_custom_field_option details
[PagerDuty] Add a selectable option to an incident type custom field. Not destructive: additive: a new option becomes selectable but is not set on any incident until someone chooses it. POST /incidents/types//custom_fields//field_options. Path parameters: type_id_or_name, field_id. Wrap the option in a field_option object; PagerDuty requires data.data_type and data.value: {"field_option": {"data": {"data_type": "string", "value": "option_1"}}}. Options can only be added to a field whose field_type is single_value_fixed or multi_value_fixed. Returns raw PagerDuty JSON.
pd_delete_incident_type_custom_field details
pd_delete_incident_type_custom_field details
[PagerDuty] DESTRUCTIVE: delete a custom field from an incident type. Why this is destructive: deleting the field destroys the values recorded against it on every incident of that type and PagerDuty keeps no copy. DELETE /incidents/types//custom_fields/. Path parameters: type_id_or_name, field_id. Returns raw PagerDuty JSON.
pd_delete_incident_type_custom_field_field_option details
pd_delete_incident_type_custom_field_field_option details
[PagerDuty] DESTRUCTIVE: delete one selectable option of an incident type custom field. Why this is destructive: every incident that had this option selected loses that value and PagerDuty keeps no copy. DELETE /incidents/types//custom_fields//field_options/. Path parameters: type_id_or_name, field_option_id, field_id. Returns raw PagerDuty JSON.
pd_get_incident_type details
pd_get_incident_type details
[PagerDuty] Get an incident type. The id or the name works here, so a name from pd_list_incident_types can be passed straight through. GET /incidents/types/. Path parameters: type_id_or_name. Returns raw PagerDuty JSON.
pd_get_incident_type_custom_field details
pd_get_incident_type_custom_field details
[PagerDuty] Get one custom field definition of an incident type. These are the field DEFINITIONS; pd_get_incident_custom_field_values reads the VALUES one incident holds in its fields. GET /incidents/types//custom_fields/. Path parameters: type_id_or_name, field_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_incident_type_custom_field_option details
pd_get_incident_type_custom_field_option details
[PagerDuty] Get one selectable option of an incident type custom field. The option id comes from pd_list_incident_type_custom_field_options. GET /incidents/types//custom_fields//field_options/. Path parameters: type_id_or_name, field_option_id, field_id. Returns raw PagerDuty JSON.
pd_list_incident_type_custom_field_options details
pd_list_incident_type_custom_field_options details
[PagerDuty] List the selectable options of an incident type custom field. Only a field whose field_type is single_value_fixed or multi_value_fixed has options. PagerDuty declares no paging parameters on this endpoint, so the whole collection comes back in one response. GET /incidents/types//custom_fields//field_options. Path parameters: type_id_or_name, field_id. Returns raw PagerDuty JSON.
pd_list_incident_type_custom_fields details
pd_list_incident_type_custom_fields details
[PagerDuty] List the custom field definitions of an incident type. These are the field DEFINITIONS; pd_get_incident_custom_field_values reads the VALUES one incident holds in its fields. PagerDuty declares no paging parameters on this endpoint, so the whole collection comes back in one response. GET /incidents/types//custom_fields. Path parameters: type_id_or_name. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_incident_types details
pd_list_incident_types details
[PagerDuty] List incident types. filter defaults to enabled, so pass all (or disabled) to see types that are switched off. PagerDuty declares no paging parameters on this endpoint, so the whole collection comes back in one response. GET /incidents/types. Optional filters: filter. Returns raw PagerDuty JSON.
pd_update_incident_type details
pd_update_incident_type details
[PagerDuty] Update an incident type. Not destructive: it edits only display_name, description and enabled - name cannot be changed after creation - and disabling a type stops it being chosen for NEW incidents while leaving existing incidents of that type alone. PUT /incidents/types/. Path parameters: type_id_or_name. Wrap the changes in an incident_type object; PagerDuty documents display_name, description and enabled: {"incident_type": {"display_name": "Fraud Incident", "enabled": false}}. Returns raw PagerDuty JSON.
pd_update_incident_type_custom_field details
pd_update_incident_type_custom_field details
[PagerDuty] DESTRUCTIVE: update a custom field on an incident type, replacing its option set. Why this is destructive: any field_options list you send REPLACES the option set - PagerDuty upserts the entries you include and DELETES every existing option you leave out (its one exception is an option the current default_value points at) - and a deleted option takes with it the value every incident of that type held in it. Omit field_options entirely and the call edits only display_name, description, default_value and enabled, which changes nothing already recorded. PUT /incidents/types//custom_fields/. Path parameters: type_id_or_name, field_id. Wrap the changes in a field object. display_name, description, default_value and enabled are edited in place, and PagerDuty's simplest sample is {"field": {"display_name": "Custom Field 1"}}. field_options is a REPLACING UPSERT: an entry WITH an id updates that option, an entry WITHOUT one adds a new option, and any existing option you do not send is DELETED - so send the array only when it is the WHOLE option set. PagerDuty's own upsert sample is {"field": {"display_name": "Single Select Field Updated", "field_options": [{"id": "PQ9K7I8", "data": {"data_type": "string", "value": "Updated value for an existing field option"}}, {"data": {"data_type": "string", "value": "A brand new field option, added by not providing an id"}}]}}. Returns raw PagerDuty JSON.
pd_update_incident_type_custom_field_field_option details
pd_update_incident_type_custom_field_field_option details
[PagerDuty] Update one selectable option of an incident type custom field. Not destructive: it rewrites one option's value, and every incident already carrying that option reads the new text - the change is retroactive across existing incidents - but nothing is deleted and writing the old value back undoes it. PUT /incidents/types//custom_fields//field_options/. Path parameters: type_id_or_name, field_option_id, field_id. Wrap the option in a field_option object; PagerDuty requires data.data_type and data.value: {"field_option": {"data": {"data_type": "string", "value": "option_1"}}}. Returns raw PagerDuty JSON.
Incident Workflows
pd_associate_service_to_incident_workflow_trigger details
pd_associate_service_to_incident_workflow_trigger details
[PagerDuty] DESTRUCTIVE: associate a service with an incident workflow trigger. Why this is destructive: it arms the trigger for that service, so the workflow starts running on that service's live incidents - its steps post to chat, call outside systems and can page people. POST /incident_workflows/triggers//services. Path parameters: id. Wrap the service reference in a service object; its id is the only field PagerDuty documents: {"service": {"id": "PSERVICE"}}. Returns raw PagerDuty JSON.
pd_create_incident_workflow details
pd_create_incident_workflow details
[PagerDuty] Create an incident workflow. Not destructive: additive: a workflow with no trigger runs nothing. It starts firing only once pd_create_incident_workflow_trigger arms it, or someone starts it by hand. POST /incident_workflows. Wrap the workflow in an incident_workflow object. PagerDuty's own sample is {"incident_workflow": {"name": "Example Incident Workflow", "description": "This Incident Workflow is an example", "steps": [{"name": "Send Status Update", "action_configuration": {"action_id": "pagerduty.com:incident-workflows:send-status-update:1", "inputs": [{"name": "Message", "value": "Example status message"}]}}]}}. Valid action_id values and input names come from pd_list_incident_workflow_actions. Returns raw PagerDuty JSON.
pd_create_incident_workflow_instance details
pd_create_incident_workflow_instance details
[PagerDuty] DESTRUCTIVE: start an incident workflow on a live incident. Why this is destructive: it RUNS the workflow against the incident you name, now: its steps post to chat, call outside systems and can page people, and StackJack cannot recall them. POST /incident_workflows//instances. Path parameters: id. Wrap the run in an incident_workflow_instance object naming the incident it runs against: {"incident_workflow_instance": {"id": "optional-label", "incident": {"id": "PINCIDENT", "type": "incident_reference"}}}. The outer id is an optional label that tells executions apart; incident.id is the live incident. Returns raw PagerDuty JSON.
pd_create_incident_workflow_trigger details
pd_create_incident_workflow_trigger details
[PagerDuty] DESTRUCTIVE: create an incident workflow trigger. Why this is destructive: a trigger ARMS the workflow against live incidents: a conditional trigger starts it automatically on the next matching incident, and the workflow's steps post to chat, call outside systems and can page people. is_subscribed_to_all_services arms it for every service in the account at once. POST /incident_workflows/triggers. Wrap the trigger in a trigger object. PagerDuty documents type (workflow_trigger), trigger_type (conditional, manual or incident_type), condition (a PCL condition string, required for and allowed only on conditional triggers), workflow.id, services[].id, is_subscribed_to_all_services, incident_types[] and permissions {restricted, team_id} for manual triggers. A conditional trigger sent with no condition executes on incident creation. is_disabled is deprecated here - the workflow's own is_enabled drives it. Returns raw PagerDuty JSON.
pd_delete_incident_workflow details
pd_delete_incident_workflow details
[PagerDuty] DESTRUCTIVE: delete an incident workflow. Why this is destructive: deleting the workflow destroys its step list and every trigger that pointed at it stops starting anything; PagerDuty keeps no copy. DELETE /incident_workflows/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_incident_workflow_trigger details
pd_delete_incident_workflow_trigger details
[PagerDuty] DESTRUCTIVE: delete an incident workflow trigger. Why this is destructive: the workflow stops running on every incident this trigger was arming it for, so automation the customer relies on goes quiet; the workflow itself survives. DELETE /incident_workflows/triggers/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_service_from_incident_workflow_trigger details
pd_delete_service_from_incident_workflow_trigger details
[PagerDuty] DESTRUCTIVE: dissociate a service from an incident workflow trigger. Why this is destructive: the workflow stops running on that service's incidents, so automation the customer relies on there goes quiet with nothing on the incident to show it happened. DELETE /incident_workflows/triggers//services/. Path parameters: trigger_id, service_id. Returns raw PagerDuty JSON.
pd_get_incident_workflow details
pd_get_incident_workflow details
[PagerDuty] Get an incident workflow. The response carries the workflow's ordered step list. The triggers that start it are separate objects - read those with pd_list_incident_workflow_triggers filtered by workflow_id. GET /incident_workflows/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_incident_workflow_action details
pd_get_incident_workflow_action details
[PagerDuty] Get one incident workflow step action. The response describes the action's inputs - the names a step's action_configuration.inputs entries have to use. Each input carries its type, default_value and is_required, outputs lists what the step publishes, and action_tier marks a premium action. GET /incident_workflows/actions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_incident_workflow_trigger details
pd_get_incident_workflow_trigger details
[PagerDuty] Get an incident workflow trigger. The response carries the trigger's condition and the services it is armed for. GET /incident_workflows/triggers/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_incident_workflow_actions details
pd_list_incident_workflow_actions details
[PagerDuty] List the actions an incident workflow step can run. This is PagerDuty's catalogue of step actions rather than anything configured on the account: the action_id values here are what a workflow step's action_configuration.action_id has to be set to. Each action carries the inputs a step has to fill (name, type, is_required) and an action_tier that marks the premium ones. GET /incident_workflows/actions. Optional filters: keyword. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_incident_workflow_triggers details
pd_list_incident_workflow_triggers details
[PagerDuty] List incident workflow triggers. A trigger is what starts a workflow: a conditional trigger fires on the next matching incident, a manual one is started by a person. incident_id and service_id cannot be sent together. GET /incident_workflows/triggers. Optional filters: workflow_id, incident_id, service_id, trigger_type, workflow_name_contains, is_disabled, sort_by. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_incident_workflows details
pd_list_incident_workflows details
[PagerDuty] List incident workflows. A workflow carries no service of its own: to find the workflows configured for one service, list triggers instead with pd_list_incident_workflow_triggers and a service_id. GET /incident_workflows. Optional filters: query, include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_incident_workflow details
pd_update_incident_workflow details
[PagerDuty] DESTRUCTIVE: update an incident workflow, replacing its step list. Why this is destructive: it REPLACES the workflow's definition: the steps array you send becomes the whole step list, so a step you leave out is removed, and the next incident that triggers this workflow runs the new definition against live systems. PUT /incident_workflows/. Path parameters: id. Wrap the whole workflow in an incident_workflow object - name, description and the COMPLETE steps array, because the array replaces the stored one: {"incident_workflow": {"name": "Example Incident Workflow", "steps": [{"name": "Send Status Update", "action_configuration": {"action_id": "pagerduty.com:incident-workflows:send-status-update:1", "inputs": [{"name": "Message", "value": "Example status message"}]}}]}}. Returns raw PagerDuty JSON.
pd_update_incident_workflow_trigger details
pd_update_incident_workflow_trigger details
[PagerDuty] DESTRUCTIVE: update an incident workflow trigger, replacing its condition and services. Why this is destructive: it replaces the trigger's condition and its services list wholesale, so from the next matching incident the workflow starts running on incidents it was not handling and stops on ones it was - and the workflow's steps post to chat, call outside systems and can page people. PUT /incident_workflows/triggers/. Path parameters: id. Wrap the trigger in a trigger object and send the COMPLETE services array, because it replaces the stored one. PagerDuty documents type (workflow_trigger), condition (a PCL condition string), services[].id, is_subscribed_to_all_services, incident_types[] and permissions {restricted, team_id}. is_disabled is deprecated here - set is_enabled on the workflow instead. Returns raw PagerDuty JSON.
Workflow Integrations
pd_create_workflow_integration_connection details
pd_create_workflow_integration_connection details
[PagerDuty] DESTRUCTIVE: create a workflow integration connection, storing its credential. Why this is destructive: it STORES A CREDENTIAL: the required secrets object is the token, password or signing secret PagerDuty keeps and authenticates to the outside system with, and every incident-workflow step bound to this connection can then act there. PagerDuty never gives the value back - the response's secrets is always null - so a wrong value can only be replaced, never read. POST /workflows/integrations//connections. Path parameters: integration_id. The connection object at the TOP level, not wrapped in an envelope. PagerDuty marks name and secrets REQUIRED and documents id, type, integration_id, name, service_url, external_id, external_id_label, scopes, is_default, health, configuration, secrets, teams and apps. The shapes of configuration and secrets are per-integration: read configuration_schema and secrets_schema from pd_get_workflow_integration first. Returns raw PagerDuty JSON.
pd_delete_workflow_integration_connection details
pd_delete_workflow_integration_connection details
[PagerDuty] DESTRUCTIVE: delete a workflow integration connection. Why this is destructive: every incident-workflow step that acts through this connection stops being able to reach the outside system, and the stored credential goes with it - PagerDuty keeps no copy and never returned it, so rebuilding the connection means fetching the secret from the outside system again. DELETE /workflows/integrations//connections/. Path parameters: integration_id, id. Returns raw PagerDuty JSON.
pd_get_workflow_integration details
pd_get_workflow_integration details
[PagerDuty] Get a workflow integration. Read secrets_schema here before creating a connection: it names the credential fields that connection's secrets object has to carry, and configuration_schema names the rest. The entitled flag says whether this account is licensed for the integration, and is_deprecated whether PagerDuty has retired it. GET /workflows/integrations/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_workflow_integration_connection details
pd_get_workflow_integration_connection details
[PagerDuty] Get a workflow integration connection. The response carries the connection's configuration, scopes and health. PagerDuty never gives a stored credential back: its own schema documents the connection's secrets object as always null on a response. GET /workflows/integrations//connections/. Path parameters: integration_id, id. Returns raw PagerDuty JSON.
pd_list_workflow_integration_connections details
pd_list_workflow_integration_connections details
[PagerDuty] List every workflow integration connection on the account. A connection is one authorized link to an outside system that incident-workflow steps act through. PagerDuty never gives a stored credential back: its own schema documents the connection's secrets object as always null on a response. GET /workflows/integrations/connections. Optional filters: name. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_workflow_integration_connections_by_integration details
pd_list_workflow_integration_connections_by_integration details
[PagerDuty] List the connections of one workflow integration. PagerDuty never gives a stored credential back: its own schema documents the connection's secrets object as always null on a response. GET /workflows/integrations//connections. Path parameters: integration_id. Optional filters: name. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_workflow_integrations details
pd_list_workflow_integrations details
[PagerDuty] List the workflow integrations available to the account. A workflow integration is the catalogue entry for an outside system - chat, ticketing, conferencing - that incident-workflow steps act through. Its configuration_schema and secrets_schema say what a connection to it has to supply. Each entry's entitled flag says whether this account is licensed for it, and PagerDuty leaves the integrations it has retired out of the list unless include_deprecated is true. GET /workflows/integrations. Optional filters: include_deprecated. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_update_workflow_integration_connection details
pd_update_workflow_integration_connection details
[PagerDuty] DESTRUCTIVE: update a workflow integration connection, re-storing its credential. Why this is destructive: PagerDuty serves this as a PATCH, but its schema marks name AND secrets REQUIRED, so every update RE-STORES the credential the connection authenticates with: send a stale or wrong secret and every incident-workflow step bound to this connection stops being able to act in the outside system. The previous value cannot be read back - PagerDuty returns secrets as null - so this is not undoable from the API. PATCH /workflows/integrations//connections/. Path parameters: integration_id, id. The connection object at the TOP level, not wrapped in an envelope. PagerDuty marks name and secrets REQUIRED and documents id, type, integration_id, name, service_url, external_id, external_id_label, scopes, is_default, health, configuration, secrets, teams and apps. The shapes of configuration and secrets are per-integration: read configuration_schema and secrets_schema from pd_get_workflow_integration first. Served as a PATCH, so a field you do not send is left as it is - but name and secrets are required on every call. Returns raw PagerDuty JSON.
Incidents
pd_add_incident_status_subscribers details
pd_add_incident_status_subscribers details
[PagerDuty] DESTRUCTIVE: add Notification Subscribers. Why this is destructive: a new subscriber starts receiving this incident's status emails. POST /incidents//status_updates/subscribers. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribers. Returns raw PagerDuty JSON.
pd_cancel_incident_responder_request details
pd_cancel_incident_responder_request details
[PagerDuty] DESTRUCTIVE: cancel responder requests for an incident. Why this is destructive: it withdraws a page already sent to a responder. PUT /incidents//responder_requests/cancel. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: requester_id, responder_request_targets. Returns raw PagerDuty JSON.
pd_create_incident details
pd_create_incident details
[PagerDuty] DESTRUCTIVE: create an Incident. Why this is destructive: it pages whoever is on call for the service, through every channel their notification rules name. POST /incidents. Send the request body as JSON; PagerDuty documents these fields: incident.type, incident.title, incident.service, incident.priority, incident.urgency, incident.body, incident.incident_key, incident.assignments, incident.incident_type, incident.escalation_policy, incident.conference_bridge. Returns raw PagerDuty JSON.
pd_create_incident_note details
pd_create_incident_note details
[PagerDuty] DESTRUCTIVE: create a note on an incident. Why this is destructive: PagerDuty notifies the incident's responders when a note is added. POST /incidents//notes. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: note.content. Returns raw PagerDuty JSON.
pd_create_incident_responder_request details
pd_create_incident_responder_request details
[PagerDuty] DESTRUCTIVE: create a responder request for an incident. Why this is destructive: it pages an additional person and asks them to join the incident. POST /incidents//responder_requests. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: requester_id, message, responder_request_targets. Returns raw PagerDuty JSON.
pd_create_incident_status_update details
pd_create_incident_status_update details
[PagerDuty] DESTRUCTIVE: create a status update on an incident. Why this is destructive: it emails every status-update subscriber, who are usually the customer's own stakeholders. POST /incidents//status_updates. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: message, subject, html_message. Returns raw PagerDuty JSON.
pd_delete_incident_note details
pd_delete_incident_note details
[PagerDuty] DESTRUCTIVE: delete a note on an incident. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /incidents//notes/. Path parameters: id, note_id. Returns raw PagerDuty JSON.
pd_get_incident details
pd_get_incident details
[PagerDuty] Get an incident. GET /incidents/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_incident_alert details
pd_get_incident_alert details
[PagerDuty] Get an alert. GET /incidents//alerts/. Path parameters: id, alert_id. Returns raw PagerDuty JSON.
pd_get_incident_custom_field_values details
pd_get_incident_custom_field_values details
[PagerDuty] Get Custom Field Values. GET /incidents//custom_fields/values. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_outlier_incident details
pd_get_outlier_incident details
[PagerDuty] Get Outlier Incident. GET /incidents//outlier_incident. Path parameters: id. Optional filters: since, additional_details[]. Returns raw PagerDuty JSON.
pd_list_incident_alerts details
pd_list_incident_alerts details
[PagerDuty] List alerts for an incident. GET /incidents//alerts. Path parameters: id. Optional filters: alert_key, statuses[], sort_by, include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_incident_impacted_business_services details
pd_list_incident_impacted_business_services details
[PagerDuty] List Business Services impacted by the given Incident. GET /incidents//business_services/impacts. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_incident_log_entries details
pd_list_incident_log_entries details
[PagerDuty] List log entries for an incident. GET /incidents//log_entries. Path parameters: id. Optional filters: time_zone, since, until, is_overview, include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_incident_notes details
pd_list_incident_notes details
[PagerDuty] List notes for an incident. GET /incidents//notes. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_incident_status_subscribers details
pd_list_incident_status_subscribers details
[PagerDuty] List Notification Subscribers. GET /incidents//status_updates/subscribers. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_incidents details
pd_list_incidents details
[PagerDuty] List incidents. GET /incidents. Optional filters: date_range, incident_key, service_ids[], team_ids[], user_ids[], urgencies[], time_zone, statuses[], sort_by, include[], since, until. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_past_incidents details
pd_list_past_incidents details
[PagerDuty] Get Past Incidents. GET /incidents//past_incidents. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_related_incidents details
pd_list_related_incidents details
pd_manage_incident_alerts details
pd_manage_incident_alerts details
[PagerDuty] DESTRUCTIVE: manage alerts. Why this is destructive: it resolves or moves alerts in bulk, which can resolve the incident they belong to. PUT /incidents//alerts. Path parameters: id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Send the request body as JSON; PagerDuty documents these fields: alerts. Returns raw PagerDuty JSON.
pd_manage_incidents details
pd_manage_incidents details
[PagerDuty] DESTRUCTIVE: manage incidents. Why this is destructive: it resolves, acknowledges or reassigns incidents in bulk, and reassignment pages the new assignee. PUT /incidents. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Send the request body as JSON; PagerDuty documents these fields: incidents. Returns raw PagerDuty JSON.
pd_merge_incidents details
pd_merge_incidents details
[PagerDuty] DESTRUCTIVE: merge incidents. Why this is destructive: merging folds incidents into one irreversibly — PagerDuty offers no unmerge. PUT /incidents//merge. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: source_incidents. Returns raw PagerDuty JSON.
pd_remove_incident_status_subscribers details
pd_remove_incident_status_subscribers details
[PagerDuty] DESTRUCTIVE: remove Notification Subscriber. Why this is destructive: an unsubscribed stakeholder stops being told what is happening. POST /incidents//status_updates/unsubscribe. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribers. Returns raw PagerDuty JSON.
pd_set_incident_business_service_impact details
pd_set_incident_business_service_impact details
[PagerDuty] DESTRUCTIVE: manually change an Incident's Impact on a Business Service. Why this is destructive: business-service impact is what customer-facing status pages and stakeholder notifications read. PUT /incidents//business_services//impacts. Path parameters: id, business_service_id. Send the request body as JSON; PagerDuty documents these fields: relation. Returns raw PagerDuty JSON.
pd_set_incident_custom_field_values details
pd_set_incident_custom_field_values details
[PagerDuty] Update Custom Field Values. Not destructive: field values are metadata: the call sets only the fields it is given, pages nobody, and can be set again. PUT /incidents//custom_fields/values. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: custom_fields. Returns raw PagerDuty JSON.
pd_snooze_incident details
pd_snooze_incident details
[PagerDuty] DESTRUCTIVE: snooze an incident. Why this is destructive: snoozing stops the incident paging anyone for the duration — the failure mode is a monitoring blind spot. POST /incidents//snooze. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: duration. Returns raw PagerDuty JSON.
pd_update_incident details
pd_update_incident details
[PagerDuty] DESTRUCTIVE: update an incident. Why this is destructive: resolving, acknowledging, reassigning or re-prioritizing a live incident changes who is being paged about it. PUT /incidents/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: incident.type, incident.status, incident.priority, incident.resolution, incident.title, incident.escalation_level, incident.assignments, incident.incident_type, incident.escalation_policy, incident.urgency, incident.conference_bridge, incident.service. Returns raw PagerDuty JSON.
pd_update_incident_alert details
pd_update_incident_alert details
[PagerDuty] DESTRUCTIVE: update an alert. Why this is destructive: resolving an alert or moving it to another incident changes what is paging. PUT /incidents//alerts/. Path parameters: id, alert_id. Send the request body as JSON; PagerDuty documents these fields: alert.status, alert.incident. Returns raw PagerDuty JSON.
pd_update_incident_note details
pd_update_incident_note details
[PagerDuty] DESTRUCTIVE: update a note on an incident. Why this is destructive: it rewrites a note responders were already notified about. PUT /incidents//notes/. Path parameters: id, note_id. Send the request body as JSON; PagerDuty documents these fields: note.content. Returns raw PagerDuty JSON.
Add-ons
pd_create_addon details
pd_create_addon details
[PagerDuty] Install an Add-on. Not destructive: it installs an account-wide panel that renders one https page inside the PagerDuty UI. It pages nobody, touches no incident, and pd_delete_addon removes it. POST /addons. Send {"addon": {"type": "full_page_addon" or "incident_show_addon", "name": "...", "src": "https://..."}}. All three are required, name caps at 100 characters, and src MUST be https - PagerDuty renders that page in an iframe for everyone in the account. Returns raw PagerDuty JSON.
pd_delete_addon details
pd_delete_addon details
[PagerDuty] DESTRUCTIVE: delete an Add-on. Why this is destructive: the add-on's panel disappears from the PagerDuty UI for everyone in the account. DELETE /addons/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_addon details
pd_get_addon details
[PagerDuty] Get an Add-on. An Add-on is an outside https page PagerDuty renders inside its own UI: src is that page and type says whether it is a full page or a panel on the incident screen. GET /addons/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_addons details
pd_list_addons details
[PagerDuty] List installed Add-ons. Add-ons are account-wide - everything installed here is visible to the whole account. GET /addons. Optional filters: include[], service_ids[], filter. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_addon details
pd_update_addon details
[PagerDuty] DESTRUCTIVE: update an Add-on. Why this is destructive: PagerDuty replaces the stored one with what you send, so a member you leave out is lost. Send the COMPLETE addon object - its type, name and src. The edit can be made again once you have read the current add-on back. PUT /addons/. Path parameters: id. Send {"addon": {"type": ..., "name": ..., "src": "https://..."}} - the COMPLETE object, because PagerDuty replaces the stored add-on with what you send. type is full_page_addon or incident_show_addon and src must be https. Returns raw PagerDuty JSON.
Change Events
pd_create_change_event details
pd_create_change_event details
[PagerDuty] DESTRUCTIVE: create a Change Event. Why this is destructive: it pushes a change event onto a live service's timeline, and change events drive the change correlation PagerDuty shows responders on incidents that open afterwards. POST /change_events. PagerDuty publishes NO request body for this REST route: the operation declares the Accept and Content-Type headers alone and answers 202 with no content, pointing instead at the V2 Events API "Send Change Event". StackJack therefore sends no body here - use pd_send_change_event, which calls the documented Events endpoint with routing_key and payload. Returns raw PagerDuty JSON.
pd_get_change_event details
pd_get_change_event details
[PagerDuty] Get a Change Event. A Change Event is a deploy, build or configuration-change record on a service timeline - not an alert and not an incident. PagerDuty correlates them with incidents that open afterwards. GET /change_events/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_change_events details
pd_list_change_events details
[PagerDuty] List Change Events. Change Events are deploy and configuration-change records, never alerts. since and until must be UTC ISO 8601 datetimes - PagerDuty answers 400 to anything else. GET /change_events. Optional filters: team_ids[], integration_ids[], since, until. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_incident_related_change_events details
pd_list_incident_related_change_events details
pd_list_service_change_events details
pd_list_service_change_events details
[PagerDuty] List Change Events for a service. The same collection as pd_list_change_events, already narrowed to one service. since and until must be UTC ISO 8601 datetimes or PagerDuty answers 400. GET /services//change_events. Path parameters: id. Optional filters: since, until, team_ids[], integration_ids[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_change_event details
pd_update_change_event details
[PagerDuty] DESTRUCTIVE: update a Change Event. Why this is destructive: PagerDuty replaces the stored one with what you send, so a field you leave out is gone from a change event that is already on a service timeline. Send the COMPLETE change_event object. The edit can be made again once you have read the current change event back. PUT /change_events/. Path parameters: id. Send {"change_event": {"type": "change_event", "summary": "...", "custom_details": }}. PagerDuty marks every other ChangeEvent member readOnly - timestamp, source, services, integration, routing_key, links and images cannot be edited here - and its own request sample sends type, summary and custom_details alone. Returns raw PagerDuty JSON.
Extension Schemas
pd_get_extension_schema details
pd_get_extension_schema details
[PagerDuty] Get an extension schema (vendor template). An extension schema is PagerDuty's template for one vendor - Slack, a generic webhook and so on. Its id is what an extension create or update must reference in extension_schema. GET /extension_schemas/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_extension_schemas details
pd_list_extension_schemas details
[PagerDuty] List extension schemas (vendor templates). Extension schemas are PagerDuty's per-vendor templates. Take the id you need here and send it as extension_schema when creating an extension. GET /extension_schemas. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
Extensions
pd_create_extension details
pd_create_extension details
[PagerDuty] DESTRUCTIVE: create an extension. Why this is destructive: an extension POSTS every matching incident to the endpoint you give it, so creating one starts sending this account's incident data to an outside system. Extensions are the only part of this family PagerDuty gates on the account's abilities: it answers 402 Payment Required when the account cannot hold another extension, and refuses the create outright rather than queuing it. POST /extensions. Send {"extension": {"name": "...", "extension_schema": {"id": "...", "type": "extension_schema_reference"}, "extension_objects": [{"id": "PSERVICE", "type": "service_reference"}], "endpoint_url": "https://...", "config": }}. name, extension_schema and extension_objects are required; the schema id comes from pd_list_extension_schemas and is what decides the meaning of config. temporarily_disabled is read-only. Returns raw PagerDuty JSON.
pd_delete_extension details
pd_delete_extension details
[PagerDuty] DESTRUCTIVE: delete an extension. Why this is destructive: the outside system stops receiving this account's incident data, and the extension's endpoint and config go with it. DELETE /extensions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_enable_extension details
pd_enable_extension details
[PagerDuty] DESTRUCTIVE: enable an extension. Why this is destructive: it re-arms an extension PagerDuty had temporarily disabled after its endpoint kept rejecting deliveries, so this account's incident data starts reaching that endpoint again. POST /extensions//enable. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_extension details
pd_get_extension details
[PagerDuty] Get an extension. An extension is an outbound integration: PagerDuty posts matching incidents to its endpoint_url, or to whatever its extension schema's config describes. GET /extensions/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_extensions details
pd_list_extensions details
[PagerDuty] List extensions. Extensions are this account's outbound integrations. temporarily_disabled on one means PagerDuty stopped delivering to it after the endpoint repeatedly rejected deliveries. GET /extensions. Optional filters: query, extension_object_id, extension_schema_id, include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_extension details
pd_update_extension details
[PagerDuty] DESTRUCTIVE: update an extension. Why this is destructive: endpoint_url is part of the body, so a replace can re-point this account's incident data at a different outside system, and PagerDuty replaces the stored extension with what you send, so a member you leave out is lost. Like the create, this route is gated on the account's abilities: PagerDuty answers 402 Payment Required rather than applying the update. PUT /extensions/. Path parameters: id. Send the COMPLETE {"extension": {"name": ..., "extension_schema": , "extension_objects": [...], "endpoint_url": "https://...", "config": }} - PagerDuty replaces the stored extension with what you send. name, extension_schema and extension_objects are required; temporarily_disabled is read-only and is cleared through pd_enable_extension, not here. Returns raw PagerDuty JSON.
Webhooks
pd_create_oauth_client details
pd_create_oauth_client details
[PagerDuty] DESTRUCTIVE: create an OAuth client. Why this is destructive: it STORES an OAuth client secret that PagerDuty then uses to authenticate webhook deliveries, and PagerDuty validates the pair on the spot by fetching a token from the token_url you give it. Storing a credential is not a reversible edit, and an account is capped at 10 clients. POST /webhook_subscriptions/oauth_clients. Send {"oauth_client": {"name": "...", "client_id": "...", "client_secret": "...", "token_url": "https://...", "grant_type": "client_credentials", "scope": "..."}}. Everything but scope is required and grant_type accepts client_credentials only. The SECRET travels in this body and StackJack does not record it. Needs an API key belonging to an account admin or owner. Returns raw PagerDuty JSON.
pd_create_webhook_subscription details
pd_create_webhook_subscription details
[PagerDuty] DESTRUCTIVE: create a webhook subscription. Why this is destructive: it starts POSTing this account's incident events to the delivery URL you give it, and the creation response carries delivery_method.secret - the HMAC key PagerDuty signs every delivery with, returned on this one call and never again. POST /webhook_subscriptions. Send {"webhook_subscription": {"type": "webhook_subscription", "delivery_method": {"type": "http_delivery_method", "url": "https://...", "custom_headers": [{"name": "...", "value": "..."}]}, "events": ["incident.triggered", ...], "filter": {"type": "service_reference", "id": "PSERVICE"}, "description": "...", "oauth_client_id": "..."}}. type, delivery_method, events and filter are required; filter.type is account_reference, service_reference or team_reference and the last two also need an id; oauth_client_id comes from pd_list_oauth_clients and authenticates the deliveries. custom_headers values ride every delivery verbatim and are redacted from later reads, so treat them as secrets - StackJack does not record this request body. id and oauth_client are read-only response members, not inputs. Returns raw PagerDuty JSON.
pd_delete_oauth_client details
pd_delete_oauth_client details
[PagerDuty] DESTRUCTIVE: delete an OAuth client. Why this is destructive: it also removes the client from EVERY webhook subscription using it, so those subscriptions lose the credential their deliveries authenticate with. DELETE /webhook_subscriptions/oauth_clients/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_webhook_subscription details
pd_delete_webhook_subscription details
[PagerDuty] DESTRUCTIVE: delete a webhook subscription. Why this is destructive: the destination stops receiving this account's incident events, and the signing secret goes with the subscription - a replacement is issued a new one. DELETE /webhook_subscriptions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_enable_webhook_subscription details
pd_enable_webhook_subscription details
[PagerDuty] DESTRUCTIVE: enable a webhook subscription. Why this is destructive: it re-arms a subscription PagerDuty had temporarily disabled after its URL kept rejecting deliveries, so deliveries to that URL resume. POST /webhook_subscriptions//enable. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_oauth_client details
pd_get_oauth_client details
[PagerDuty] Get an OAuth client. Needs an API key belonging to an account admin or owner. PagerDuty never returns client_secret on a read: the response declares id, type, name, client_id, scope, token_url, grant_type and status only. GET /webhook_subscriptions/oauth_clients/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_webhook_subscription details
pd_get_webhook_subscription details
[PagerDuty] Get a webhook subscription. delivery_method.secret - the key PagerDuty signs every delivery with - is returned ONLY on the create response, and custom_headers values are redacted here, so a read recovers neither. GET /webhook_subscriptions/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_oauth_clients details
pd_list_oauth_clients details
[PagerDuty] List OAuth clients. Needs an API key belonging to an account admin or owner. PagerDuty declares NO paging parameters on this route, so the whole collection comes back in one response - an account is capped at 10 OAuth clients. No client_secret is returned. GET /webhook_subscriptions/oauth_clients. Returns raw PagerDuty JSON.
pd_list_webhook_subscriptions details
pd_list_webhook_subscriptions details
[PagerDuty] List webhook subscriptions. Signing secrets and custom header values are never returned on a read; only the create response carries delivery_method.secret. GET /webhook_subscriptions. Optional filters: filter_type, filter_id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_ping_webhook_subscription details
pd_ping_webhook_subscription details
[PagerDuty] DESTRUCTIVE: send a test ping to a webhook subscription. Why this is destructive: it FIRES a real pagey.ping webhook at the subscription's own delivery URL, so whatever the customer wired that URL to - a chat channel, a ticket queue, an automation - receives it. PagerDuty answers 202 with no body, so this tool returns an empty JSON object. POST /webhook_subscriptions//ping. Path parameters: id. Returns raw PagerDuty JSON.
pd_update_oauth_client details
pd_update_oauth_client details
[PagerDuty] DESTRUCTIVE: update an OAuth client. Why this is destructive: any change makes PagerDuty re-validate against the customer's OAuth server, and a client_secret you send OVERWRITES the stored one, which PagerDuty returns to nobody afterwards. PUT /webhook_subscriptions/oauth_clients/. Path parameters: id. Send {"oauth_client": } carrying the members you are changing - name, client_id, client_secret, scope, token_url, grant_type. PagerDuty re-validates with the OAuth server on any change, and a client_secret here replaces the stored secret, which no read ever returns. The secret travels in this body and StackJack does not record it. Needs an API key belonging to an account admin or owner. Returns raw PagerDuty JSON.
pd_update_webhook_subscription details
pd_update_webhook_subscription details
[PagerDuty] DESTRUCTIVE: update a webhook subscription. Why this is destructive: it REPLACES the subscription's event list, filter, active flag and OAuth client, so it changes both what this account emits and what authenticates the deliveries, and active:false silently stops delivery with the subscription still in place. PUT /webhook_subscriptions/. Path parameters: id. Send {"webhook_subscription": {"description": "...", "events": [...], "filter": {"type": "...", "id": "..."}, "active": true, "oauth_client_id": "..."}} - the COMPLETE set you want, because PagerDuty replaces what is stored. The delivery method is NOT here: PagerDuty's update schema declares no delivery_method, so this call can change neither the destination URL nor its custom headers - delete and recreate the subscription for that. Returns raw PagerDuty JSON.
IP Allow Lists
pd_create_ip_allow_list details
pd_create_ip_allow_list details
[PagerDuty] DESTRUCTIVE: create an IP allow list. Why this is destructive: an IP allow list restricts which network addresses may reach this PagerDuty account at all, so creating one in the enforcing state can lock the account's own people and integrations out - StackJack included. An allow list restricts which network addresses may reach this PagerDuty account at all. StackJack calls PagerDuty from its own hosting addresses, so an enforcing list that does not include them locks StackJack out of this connector - ask StackJack support for the outbound addresses before you enforce one. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. POST /ip_allow_lists. Send the request body as JSON; PagerDuty documents these fields: ip_allow_list.id, ip_allow_list.type, ip_allow_list.state, ip_allow_list.cidr_entries. Returns raw PagerDuty JSON.
pd_delete_ip_allow_list details
pd_delete_ip_allow_list details
[PagerDuty] DESTRUCTIVE: delete an IP allow list. Why this is destructive: the restriction this list was enforcing is removed and the addresses it was limiting access to are no longer checked. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. DELETE /ip_allow_lists/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_ip_allow_list details
pd_get_ip_allow_list details
[PagerDuty] Get an IP allow list. An allow list restricts which network addresses may reach this PagerDuty account at all. StackJack calls PagerDuty from its own hosting addresses, so an enforcing list that does not include them locks StackJack out of this connector - ask StackJack support for the outbound addresses before you enforce one. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. GET /ip_allow_lists/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_ip_allow_list_audit_records details
pd_list_ip_allow_list_audit_records details
[PagerDuty] List audit records for an IP allow list. the audit trail of who changed this allow list and when. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. GET /ip_allow_lists//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_ip_allow_lists details
pd_list_ip_allow_lists details
[PagerDuty] List IP allow lists. An allow list restricts which network addresses may reach this PagerDuty account at all. StackJack calls PagerDuty from its own hosting addresses, so an enforcing list that does not include them locks StackJack out of this connector - ask StackJack support for the outbound addresses before you enforce one. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. GET /ip_allow_lists. Returns raw PagerDuty JSON.
pd_update_ip_allow_list details
pd_update_ip_allow_list details
[PagerDuty] DESTRUCTIVE: update an IP allow list. Why this is destructive: it REPLACES the list's CIDR entries and state, so an address you leave out stops being allowed to reach this PagerDuty account. An allow list restricts which network addresses may reach this PagerDuty account at all. StackJack calls PagerDuty from its own hosting addresses, so an enforcing list that does not include them locks StackJack out of this connector - ask StackJack support for the outbound addresses before you enforce one. EARLY ACCESS: PagerDuty documents this API as Early Access and it can change at any time. It also needs the account to be entitled to the feature - StackJack sends the required X-EARLY-ACCESS header for you, and a non-entitled account still answers 403. PUT /ip_allow_lists/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: ip_allow_list.id, ip_allow_list.type, ip_allow_list.state, ip_allow_list.cidr_entries. Returns raw PagerDuty JSON.
Log Entries
pd_get_log_entry details
pd_get_log_entry details
[PagerDuty] Get a log entry. GET /log_entries/. Path parameters: id. Optional filters: time_zone, include[]. Returns raw PagerDuty JSON.
pd_list_log_entries details
pd_list_log_entries details
[PagerDuty] List log entries. GET /log_entries. Optional filters: time_zone, since, until, is_overview, include[], team_ids[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_log_entry_channel details
pd_update_log_entry_channel details
[PagerDuty] DESTRUCTIVE: update log entry channel information. Why this is destructive: it rewrites an entry already written to an incident's timeline, and PagerDuty keeps no prior version of a log entry channel. PUT /log_entries//channel. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: channel.details, channel.type. Returns raw PagerDuty JSON.
Maintenance Windows
pd_create_maintenance_window details
pd_create_maintenance_window details
[PagerDuty] Create a maintenance window. Not destructive: it adds a scheduled window that can be ended or deleted again. Be aware of what it does: the services you name stop creating incidents, and therefore stop paging anyone, for the whole window. POST /maintenance_windows. Send the request body as JSON; PagerDuty documents these fields: maintenance_window.type, maintenance_window.sequence_number, maintenance_window.start_time, maintenance_window.end_time, maintenance_window.description, maintenance_window.created_by, maintenance_window.services, maintenance_window.teams. Returns raw PagerDuty JSON.
pd_delete_maintenance_window details
pd_delete_maintenance_window details
[PagerDuty] DESTRUCTIVE: delete or end a maintenance window. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /maintenance_windows/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_maintenance_window details
pd_get_maintenance_window details
[PagerDuty] Get a maintenance window. GET /maintenance_windows/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_maintenance_windows details
pd_list_maintenance_windows details
[PagerDuty] List maintenance windows. GET /maintenance_windows. Optional filters: query, team_ids[], service_ids[], include[], filter. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_maintenance_window details
pd_update_maintenance_window details
[PagerDuty] DESTRUCTIVE: update a maintenance window. Why this is destructive: PagerDuty replaces the stored window with what you send, so a service you leave out of services is no longer covered and starts creating incidents again the moment it is saved, and a team you leave out of teams loses its visibility of the window. Send the COMPLETE services and teams lists. The window itself can be moved or re-scoped again, and the services still in it keep suppressing incidents for its duration. PUT /maintenance_windows/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: maintenance_window.type, maintenance_window.sequence_number, maintenance_window.start_time, maintenance_window.end_time, maintenance_window.description, maintenance_window.created_by, maintenance_window.services, maintenance_window.teams. Returns raw PagerDuty JSON.
On-Call
pd_list_on_calls details
pd_list_on_calls details
[PagerDuty] List all of the on-calls. GET /oncalls. Optional filters: time_zone, include[], user_ids[], escalation_policy_ids[], schedule_ids[], since, until, earliest. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
Schedules
pd_create_schedule details
pd_create_schedule details
[PagerDuty] Create a schedule. Not destructive: additive: a new schedule pages nobody until an escalation policy points at it. POST /v3/schedules. Send the request body as JSON; PagerDuty documents these fields: schedule.name, schedule.time_zone, schedule.description, schedule.teams. Returns raw PagerDuty JSON.
pd_create_schedule_custom_shifts details
pd_create_schedule_custom_shifts details
[PagerDuty] Create custom shifts. Not destructive: additive: a custom shift is added to the schedule and removing it is a separate tool. POST /v3/schedules//custom_shifts. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: custom_shifts. Returns raw PagerDuty JSON.
pd_create_schedule_overrides details
pd_create_schedule_overrides details
[PagerDuty] Create overrides. Not destructive: additive: an override covers a stated window and removing it is a separate tool. POST /v3/schedules//overrides. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: overrides. Returns raw PagerDuty JSON.
pd_create_schedule_rotation details
pd_create_schedule_rotation details
[PagerDuty] Create a rotation. Not destructive: additive: a rotation is added to the schedule and removing it is a separate tool. POST /v3/schedules//rotations. Path parameters: id. Send the request body as JSON, following PagerDuty's documented sample for this endpoint. Returns raw PagerDuty JSON.
pd_create_schedule_rotation_event details
pd_create_schedule_rotation_event details
[PagerDuty] Create an event. Not destructive: additive: an event is added to the rotation and removing it is a separate tool. POST /v3/schedules//rotations//events. Path parameters: id, rotation_id. Send the request body as JSON; PagerDuty documents these fields: event.name, event.start_time, event.end_time, event.effective_since, event.effective_until, event.recurrence, event.assignment_strategy. Returns raw PagerDuty JSON.
pd_delete_schedule details
pd_delete_schedule details
[PagerDuty] DESTRUCTIVE: delete a schedule. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /v3/schedules/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_schedule_custom_shift details
pd_delete_schedule_custom_shift details
[PagerDuty] DESTRUCTIVE: delete a custom shift. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /v3/schedules//custom_shifts/. Path parameters: id, custom_shift_id. Returns raw PagerDuty JSON.
pd_delete_schedule_override details
pd_delete_schedule_override details
[PagerDuty] DESTRUCTIVE: delete an override. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /v3/schedules//overrides/. Path parameters: id, override_id. Returns raw PagerDuty JSON.
pd_delete_schedule_rotation details
pd_delete_schedule_rotation details
[PagerDuty] DESTRUCTIVE: delete a rotation. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /v3/schedules//rotations/. Path parameters: id, rotation_id. Returns raw PagerDuty JSON.
pd_delete_schedule_rotation_event details
pd_delete_schedule_rotation_event details
[PagerDuty] DESTRUCTIVE: delete an event. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /v3/schedules//rotations//events/. Path parameters: id, rotation_id, event_id. Returns raw PagerDuty JSON.
pd_get_schedule details
pd_get_schedule details
[PagerDuty] Get a schedule. GET /v3/schedules/. Path parameters: id. Optional filters: since, until, time_zone, overflow, include[]. Returns raw PagerDuty JSON.
pd_get_schedule_custom_shift details
pd_get_schedule_custom_shift details
[PagerDuty] Get a custom shift. GET /v3/schedules//custom_shifts/. Path parameters: id, custom_shift_id. Returns raw PagerDuty JSON.
pd_get_schedule_override details
pd_get_schedule_override details
[PagerDuty] Get an override. GET /v3/schedules//overrides/. Path parameters: id, override_id. Returns raw PagerDuty JSON.
pd_get_schedule_rotation details
pd_get_schedule_rotation details
[PagerDuty] Get a rotation. GET /v3/schedules//rotations/. Path parameters: id, rotation_id. Optional filters: since, until. Returns raw PagerDuty JSON.
pd_get_schedule_rotation_event details
pd_get_schedule_rotation_event details
[PagerDuty] Get an event. GET /v3/schedules//rotations//events/. Path parameters: id, rotation_id, event_id. Optional filters: since, until. Returns raw PagerDuty JSON.
pd_list_schedule_audit_records details
pd_list_schedule_audit_records details
[PagerDuty] List audit records for a schedule. GET /v3/schedules//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_schedule_custom_shifts details
pd_list_schedule_custom_shifts details
[PagerDuty] List custom shifts. GET /v3/schedules//custom_shifts. Path parameters: id. Required filters: since, until. Optional filters: time_zone, overflow. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_schedule_overrides details
pd_list_schedule_overrides details
[PagerDuty] List overrides. GET /v3/schedules//overrides. Path parameters: id. Required filters: since, until. Optional filters: time_zone, overflow. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_schedule_rotation_events details
pd_list_schedule_rotation_events details
[PagerDuty] List events. GET /v3/schedules//rotations//events. Path parameters: id, rotation_id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_schedule_rotations details
pd_list_schedule_rotations details
[PagerDuty] List rotations. GET /v3/schedules//rotations. Path parameters: id. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_schedules details
pd_list_schedules details
[PagerDuty] List schedules. GET /v3/schedules. Optional filters: query, team_ids[]. Paged with limit and offset: limit caps at 1000. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_schedule details
pd_update_schedule details
[PagerDuty] DESTRUCTIVE: update a schedule. Why this is destructive: PagerDuty replaces the schedule with what you send, so anything you leave out is gone and a schedule with no one on it pages no one. Send the COMPLETE definition. The schedule can be edited again once you have read the current one back. PUT /v3/schedules/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: schedule.name, schedule.time_zone, schedule.description. Returns raw PagerDuty JSON.
pd_update_schedule_custom_shift details
pd_update_schedule_custom_shift details
[PagerDuty] DESTRUCTIVE: update a custom shift. Why this is destructive: PagerDuty replaces the stored shift with what you send, so an assignee you leave out of assignments is off the shift and whoever is left on it takes those pages. Send the COMPLETE assignments list. The shift's window and members can be edited again. PUT /v3/schedules//custom_shifts/. Path parameters: id, custom_shift_id. Send the request body as JSON; PagerDuty documents these fields: custom_shift.start_time, custom_shift.end_time, custom_shift.assignments. Returns raw PagerDuty JSON.
pd_update_schedule_override details
pd_update_schedule_override details
[PagerDuty] DESTRUCTIVE: update an override. Why this is destructive: PagerDuty replaces the stored override with what you send, so the overriding_member and the window you leave out are not kept: from the moment it is saved the override covers a different person or a different period, and whoever it was standing in for is back on call. Send the COMPLETE override. The edit can be made again. PUT /v3/schedules//overrides/. Path parameters: id, override_id. Send the request body as JSON; PagerDuty documents these fields: override.start_time, override.end_time, override.overriding_member. Returns raw PagerDuty JSON.
pd_update_schedule_rotation_event details
pd_update_schedule_rotation_event details
[PagerDuty] DESTRUCTIVE: update an event. Why this is destructive: PagerDuty replaces the stored event with what you send, so a recurrence rule or an assignment_strategy you leave out is gone and the rotation stops repeating, or hands its pages to a different person, from the moment it is saved. Send the COMPLETE event. The edit can be made again. PUT /v3/schedules//rotations//events/. Path parameters: id, rotation_id, event_id. Send the request body as JSON; PagerDuty documents these fields: event.name, event.start_time, event.end_time, event.effective_since, event.effective_until, event.recurrence, event.assignment_strategy. Returns raw PagerDuty JSON.
Schedules (legacy v2)
pd_create_schedule_v2 details
pd_create_schedule_v2 details
[PagerDuty] Create a schedule. Not destructive: additive: a new schedule pages nobody until an escalation policy points at it. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. POST /schedules. Optional filters: overflow. Send the request body as JSON; PagerDuty documents these fields: schedule.type, schedule.schedule_layers, schedule.time_zone, schedule.name, schedule.description, schedule.final_schedule, schedule.overrides_subschedule, schedule.escalation_policies, schedule.users, schedule.teams, schedule.next_oncall_for_user. Returns raw PagerDuty JSON.
pd_create_schedule_v2_override details
pd_create_schedule_v2_override details
[PagerDuty] Create one or more overrides. Not destructive: additive: an override covers a stated window and removing it is a separate tool. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. POST /schedules//overrides. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: overrides. Returns raw PagerDuty JSON.
pd_delete_schedule_v2 details
pd_delete_schedule_v2 details
[PagerDuty] DESTRUCTIVE: delete a schedule. Why this is destructive: deleting a schedule removes it from every escalation policy that pointed at it, and the people it put on call stop being paged. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. DELETE /schedules/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_schedule_v2_override details
pd_delete_schedule_v2_override details
[PagerDuty] DESTRUCTIVE: delete an override. Why this is destructive: the override is removed and the underlying rotation covers that window again. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. DELETE /schedules//overrides/. Path parameters: id, override_id. Returns raw PagerDuty JSON.
pd_get_schedule_v2 details
pd_get_schedule_v2 details
[PagerDuty] Get a schedule. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. GET /schedules/. Path parameters: id. Optional filters: time_zone, since, until, overflow, include_next_oncall_for_user. Returns raw PagerDuty JSON.
pd_list_schedule_v2_audit_records details
pd_list_schedule_v2_audit_records details
[PagerDuty] List audit records for a schedule. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. GET /schedules//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_schedule_v2_overrides details
pd_list_schedule_v2_overrides details
[PagerDuty] List overrides. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. GET /schedules//overrides. Path parameters: id. Required filters: since, until. Optional filters: editable, overflow. Returns raw PagerDuty JSON.
pd_list_schedule_v2_users details
pd_list_schedule_v2_users details
[PagerDuty] List users on call. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. GET /schedules//users. Path parameters: id. Optional filters: since, until. Returns raw PagerDuty JSON.
pd_list_schedules_v2 details
pd_list_schedules_v2 details
[PagerDuty] List schedules. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. GET /schedules. Optional filters: query, include[], time_zone, include_next_oncall_for_user, since, until, team_ids[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_preview_schedule_v2 details
pd_preview_schedule_v2 details
[PagerDuty] Preview a schedule. Not destructive: it renders a preview of a schedule and stores nothing. It ships as a write rather than a read because PagerDuty's own scope line for it is schedules.write, so a read-only API key refuses it. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. POST /schedules/preview. Optional filters: since, until, overflow. Send the request body as JSON; PagerDuty documents these fields: schedule.type, schedule.schedule_layers, schedule.time_zone, schedule.name, schedule.description, schedule.final_schedule, schedule.overrides_subschedule, schedule.escalation_policies, schedule.users, schedule.teams, schedule.next_oncall_for_user. Returns raw PagerDuty JSON.
pd_update_schedule_v2 details
pd_update_schedule_v2 details
[PagerDuty] DESTRUCTIVE: update a schedule. Why this is destructive: PagerDuty replaces the schedule with what you send, so an omitted layer is a deleted layer and the people it covered stop being on call. Send the COMPLETE definition. The LEGACY v2 schedules route. Prefer the current v3 tools (pd_list_schedules, pd_get_schedule, pd_create_schedule and siblings), which is the surface PagerDuty builds on; this one exists for accounts and scripts still on /schedules. PUT /schedules/. Path parameters: id. Optional filters: overflow. Send the request body as JSON; PagerDuty documents these fields: schedule.type, schedule.schedule_layers, schedule.time_zone, schedule.name, schedule.description, schedule.final_schedule, schedule.overrides_subschedule, schedule.escalation_policies, schedule.users, schedule.teams, schedule.next_oncall_for_user. Returns raw PagerDuty JSON.
SCIM Provisioning
pd_scim_create_user details
pd_scim_create_user details
[PagerDuty] DESTRUCTIVE: create user. Why this is destructive: it creates a PagerDuty user, which consumes a paid license and emails that person an invitation. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. POST /scim/v2/Users. Send the request body as JSON; PagerDuty documents these fields: active, displayName, entitlements, externalId, roles, schemas, timezone, title, userName. Returns raw PagerDuty JSON.
pd_scim_delete_user details
pd_scim_delete_user details
[PagerDuty] DESTRUCTIVE: delete a user. Why this is destructive: SCIM delete DEPROVISIONS the person: they lose access, are taken off every on-call rotation they covered, and their license is released. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. DELETE /scim/v2/Users/. Path parameters: id. Returns raw PagerDuty JSON.
pd_scim_get_schema details
pd_scim_get_schema details
[PagerDuty] Get individual SCIM Schema by ID. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/Schemas/. Path parameters: id. Returns raw PagerDuty JSON.
pd_scim_get_service_provider_config details
pd_scim_get_service_provider_config details
[PagerDuty] Get SCIM Service Provider Configuration. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/ServiceProviderConfig. Returns raw PagerDuty JSON.
pd_scim_get_user details
pd_scim_get_user details
[PagerDuty] Get user. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/Users/. Path parameters: id. Returns raw PagerDuty JSON.
pd_scim_list_resource_types details
pd_scim_list_resource_types details
[PagerDuty] Get SCIM Resource Types. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/ResourceTypes. Returns raw PagerDuty JSON.
pd_scim_list_schemas details
pd_scim_list_schemas details
[PagerDuty] Get SCIM Schemas. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/Schemas. Returns raw PagerDuty JSON.
pd_scim_list_users details
pd_scim_list_users details
[PagerDuty] List users. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. GET /scim/v2/Users. Optional filters: startIndex, count, filter. Returns raw PagerDuty JSON.
pd_scim_patch_user details
pd_scim_patch_user details
[PagerDuty] DESTRUCTIVE: patch a user. Why this is destructive: a SCIM PATCH is how an identity provider DEPROVISIONS a person: active false signs them out, removes them from on-call rotations and releases their license. Send an Operations array - this is a PATCH and applies only what it is given. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. PATCH /scim/v2/Users/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: Operations, schemas. Returns raw PagerDuty JSON.
pd_scim_update_user details
pd_scim_update_user details
[PagerDuty] DESTRUCTIVE: update user. Why this is destructive: SCIM PUT REPLACES the whole user record - roles and entitlements you leave out are removed - and setting active false deprovisions the person. SCIM is a SEPARATE provisioning surface at /scim/v2 on the same host and the same API key, and it has to be enabled on the PagerDuty account before any of it answers. It speaks the SCIM envelope (a schemas array on every body, a Resources array on every list) rather than PagerDuty's singular/plural wrapper, and its errors come back in SCIM's own format. For ordinary user administration prefer the Users family (pd_list_users, pd_get_user); use these when you are mirroring an identity provider. PUT /scim/v2/Users/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: active, displayName, entitlements, externalId, id, roles, schemas, timezone, title, userName. Returns raw PagerDuty JSON.
Alert Grouping Settings
pd_create_alert_grouping_setting details
pd_create_alert_grouping_setting details
[PagerDuty] DESTRUCTIVE: create an Alert Grouping Setting. Why this is destructive: the setting names services that are already live, so from the moment it lands alerts on those services stop opening separate incidents and are folded into one - it changes what pages and when, which is the same consequence that makes pd_update_alert_grouping_setting destructive. Deleting the setting is the way back. Alert grouping is a PagerDuty PLAN FEATURE - PagerDuty documents these features as available only on certain plans, and this create is the one route in the group that declares a 403, which is what an account or token without the entitlement gets. POST /alert_grouping_settings. Send {"alert_grouping_setting": {"name": "...", "description": "...", "type": "content_based", "config": {"aggregate": "all", "fields": ["summary"], "time_window": 3600}, "services": [{"id": "PSERVIC", "type": "service_reference"}]}}. type is one of content_based, content_based_intelligent, intelligent or time, and config follows it: content_based and content_based_intelligent take aggregate (all or any), fields and time_window in seconds; time takes timeout in seconds, which PagerDuty bounds to between 60 and 86400; intelligent takes time_window and an optional iag_fields array. content_based_intelligent accepts exactly ONE service. id, created_at and updated_at are read-only and are ignored here. Returns raw PagerDuty JSON.
pd_delete_alert_grouping_setting details
pd_delete_alert_grouping_setting details
[PagerDuty] DESTRUCTIVE: delete an Alert Grouping Setting. Why this is destructive: the services this setting covered fall straight back to their own grouping configuration, so the next alert on them can open a new incident and page someone where it would have been folded into one that already existed. PagerDuty keeps no copy of the config. Alert grouping is a PagerDuty PLAN FEATURE - PagerDuty documents these features as available only on certain plans. DELETE /alert_grouping_settings/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_alert_grouping_setting details
pd_get_alert_grouping_setting details
[PagerDuty] Get an Alert Grouping Setting. One setting, with its type, the config that drives the grouping and the services it applies to. Alert grouping is a PagerDuty PLAN FEATURE - PagerDuty's own note on the object is that these features are available only on certain plans, so an account whose plan does not include it has nothing here. The call needs an API key carrying the services.read scope. GET /alert_grouping_settings/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_alert_grouping_settings details
pd_list_alert_grouping_settings details
[PagerDuty] List alert grouping settings. Every alert grouping setting on the account - the single-service ones and the account-wide content-based ones together. This read is CURSOR-paged, not offset-paged: send limit for the page size, then pass the after cursor the response hands back to walk forward, or before to walk back, and stop when no cursor comes back. There is no offset on this route and no record ceiling to plan around. Alert grouping is a PagerDuty PLAN FEATURE - PagerDuty's own note on the object is that these features are available only on certain plans, so an account whose plan does not include it has nothing here. The call needs an API key carrying the services.read scope. GET /alert_grouping_settings. Optional filters: after, before, service_ids[]. Returns raw PagerDuty JSON.
pd_update_alert_grouping_setting details
pd_update_alert_grouping_setting details
[PagerDuty] DESTRUCTIVE: update an Alert Grouping Setting. Why this is destructive: alert grouping decides whether the next alert on the covered services opens a NEW incident or is folded into one that already exists, so replacing the configuration changes what pages and when. PagerDuty documents one mercy on this route: leave services out of the request and the setting keeps the services it already has. Alert grouping is a PagerDuty PLAN FEATURE - PagerDuty documents these features as available only on certain plans, so an account without it has nothing to update. PUT /alert_grouping_settings/. Path parameters: id. Send {"alert_grouping_setting": {"name": "...", "description": "...", "type": "content_based", "config": {"aggregate": "all", "fields": ["summary"], "time_window": 3600}, "services": [{"id": "PSERVIC", "type": "service_reference"}]}}. type is one of content_based, content_based_intelligent, intelligent or time, and config follows it: content_based and content_based_intelligent take aggregate (all or any), fields and time_window in seconds; time takes timeout in seconds, which PagerDuty bounds to between 60 and 86400; intelligent takes time_window and an optional iag_fields array. content_based_intelligent accepts exactly ONE service. id, created_at and updated_at are read-only and are ignored here. On this UPDATE, omitting services leaves the covered services as they are. Returns raw PagerDuty JSON.
Business Services
pd_add_business_service_subscribers details
pd_add_business_service_subscribers details
[PagerDuty] DESTRUCTIVE: create Business Service Subscribers. Why this is destructive: the users and teams you name start receiving this business service's status notifications immediately, so a wrong subscriber_id notifies the wrong person. The array is applied in one request and pd_remove_business_service_subscribers is the only way back. POST /business_services//subscribers. Path parameters: id. Send {"subscribers": [{"subscriber_id": "PUSER01", "subscriber_type": "user"}]}. subscriber_type is user or team, at least one entry is required and PagerDuty refuses duplicates in the same array. Returns raw PagerDuty JSON.
pd_create_business_service details
pd_create_business_service details
[PagerDuty] Create a Business Service. Not destructive: additive: a new business service shows no impact and notifies nobody until technical services are wired underneath it with pd_associate_service_dependencies. PagerDuty caps an account at 5000 business services and answers an error at the limit. POST /business_services. Send {"business_service": {"name": "Checkout", "description": "what it does", "point_of_contact": "Jo Smith", "team": {"id": "PTEAM01"}}}. name is the field that matters; team.id names the owning team and point_of_contact is free text, not a PagerDuty user reference. Returns raw PagerDuty JSON.
pd_create_business_service_account_subscription details
pd_create_business_service_account_subscription details
[PagerDuty] DESTRUCTIVE: create Business Service Account Subscription. Why this is destructive: it subscribes the WHOLE ACCOUNT to this business service, so every user on it starts receiving that service's status notifications. This is not a per-person subscription - pd_add_business_service_subscribers is the one that names people - and the call needs an API key carrying the subscribers.write scope. POST /business_services//account_subscription. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_business_service details
pd_delete_business_service details
[PagerDuty] DESTRUCTIVE: delete a Business Service. Why this is destructive: the business service disappears from the web UI, no new incident can be created for it, and every dependency edge into it goes with it - so anything that referenced it, a status page or a stakeholder subscription, loses its subject. PagerDuty keeps no copy. DELETE /business_services/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_business_service_priority_threshold details
pd_delete_business_service_priority_threshold details
[PagerDuty] DESTRUCTIVE: deletes the account-level priority threshold for Business Service impact. Why this is destructive: clearing the threshold WIDENS impact rather than narrowing it: PagerDuty then treats ANY incident that carries a priority as impacting the business services above it, so customer-facing status pages start showing outages they were filtering out. pd_set_business_service_priority_threshold puts a threshold back. DELETE /business_services/priority_thresholds. Returns raw PagerDuty JSON.
pd_get_business_service details
pd_get_business_service details
[PagerDuty] Get a Business Service. One business service, with its name, description, point of contact and owning team. pd_list_business_service_dependencies lists the services underneath it and pd_list_business_service_impacts says whether it is impacted right now. GET /business_services/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_business_service_priority_threshold details
pd_get_business_service_priority_threshold details
[PagerDuty] Get the global priority threshold for a Business Service to be considered impacted by an Incident. The ACCOUNT-WIDE threshold: an incident whose priority meets or exceeds it counts as impacting every business service that depends on the service the incident belongs to. The account has exactly one global_threshold and it can be null. The call needs an API key carrying the services.read scope. pd_list_priorities resolves the priority id it names, and pd_set_business_service_priority_threshold and pd_delete_business_service_priority_threshold are the two writes. GET /business_services/priority_thresholds. Returns raw PagerDuty JSON.
pd_list_business_service_impactors details
pd_list_business_service_impactors details
[PagerDuty] List Impactors affecting Business Services. What is impacting the account's top-level business services right now. PagerDuty currently reports incidents as the only kind of impactor. The route declares no paging of any kind - the whole collection comes back in one response. GET /business_services/impactors. Optional filters: ids[]. Returns raw PagerDuty JSON.
pd_list_business_service_impacts details
pd_list_business_service_impacts details
[PagerDuty] List Business Services sorted by impacted status. Top-level business services ordered by how badly they are impacted right now, each with its status. NOT AN EXHAUSTIVE LIST: called without ids[] PagerDuty returns only the most impacted, up to 200, and the route declares no limit, no offset and no cursor at all - name the services you care about in ids[] rather than trying to page. pd_list_business_services is the complete inventory. GET /business_services/impacts. Optional filters: additional_fields[], ids[]. Returns raw PagerDuty JSON.
pd_list_business_service_subscribers details
pd_list_business_service_subscribers details
[PagerDuty] List Business Service Subscribers. The users and teams subscribed to this business service's status notifications. PagerDuty returns only subscribers added through pd_add_business_service_subscribers, and the route declares no paging - the whole list comes back. The call needs an API key carrying the subscribers.read scope. GET /business_services//subscribers. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_business_service_supporting_service_impacts details
pd_list_business_service_supporting_service_impacts details
[PagerDuty] List the supporting Business Services for the given Business Service Id, sorted by impacted status. The business services that SUPPORT the one you name, ordered by impact and each with its status. Same cap as pd_list_business_service_impacts: NOT AN EXHAUSTIVE LIST, only the most impacted up to 200, and the route declares no limit, no offset and no cursor at all - there is nothing to page. GET /business_services//supporting_services/impacts. Path parameters: id. Optional filters: additional_fields[], ids[]. Returns raw PagerDuty JSON.
pd_list_business_services details
pd_list_business_services details
[PagerDuty] List Business Services. A business service models a customer-facing capability that several technical services support; this is the account's complete inventory of them. PagerDuty caps an account at 5000 business services. The call needs an API key carrying the services.read scope. GET /business_services. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_remove_business_service_account_subscription details
pd_remove_business_service_account_subscription details
[PagerDuty] DESTRUCTIVE: delete Business Service Account Subscription. Why this is destructive: the whole account stops receiving this business service's status updates and PagerDuty keeps no record of the subscription that was removed. DELETE /business_services//account_subscription. Path parameters: id. Returns raw PagerDuty JSON.
pd_remove_business_service_subscribers details
pd_remove_business_service_subscribers details
[PagerDuty] DESTRUCTIVE: remove Business Service Subscribers. Why this is destructive: the users and teams you name stop being told what is happening to this business service, and PagerDuty keeps no record of the subscription it removed. Note the shape: this is a POST to /unsubscribe rather than a DELETE, so it is easy to reach by accident while looking for a delete verb. POST /business_services//unsubscribe. Path parameters: id. Send {"subscribers": [{"subscriber_id": "PUSER01", "subscriber_type": "user"}]}. subscriber_type is user or team, at least one entry is required and PagerDuty refuses duplicates in the same array. Returns raw PagerDuty JSON.
pd_set_business_service_priority_threshold details
pd_set_business_service_priority_threshold details
[PagerDuty] DESTRUCTIVE: set the Account-level priority threshold for Business Service impact. Why this is destructive: it sets the ACCOUNT-WIDE incident priority at which an incident counts as impacting a business service, so ONE call changes what every customer-facing status page shows and which stakeholders are notified, for every business service on the account at once. There is a single global_threshold and this replaces it. PUT /business_services/priority_thresholds. Send {"global_threshold": {"id": "PTLNKGF", "order": 256}} - PagerDuty's own sample. id is a priority ID (pd_list_priorities lists the account's priorities) and order is its rank. Read the current pair with pd_get_business_service_priority_threshold before you change it: it answers in exactly this shape. PagerDuty documents one exception to the threshold: an incident attached to a business service directly with pd_set_incident_business_service_impact impacts it whatever the threshold says. Returns raw PagerDuty JSON.
pd_update_business_service details
pd_update_business_service details
[PagerDuty] DESTRUCTIVE: update a Business Service. Why this is destructive: StackJack issues the PUT and PagerDuty replaces the stored business service with what you send, so a field you leave out of it can be cleared - read the service with pd_get_business_service first and send the COMPLETE business_service object. Nothing is deleted and nobody is paged; the edit can be made again by sending the values back. PagerDuty documents the same endpoint as also accepting PATCH for a partial edit. PUT /business_services/. Path parameters: id. Send {"business_service": {"name": "Checkout", "description": "what it does", "point_of_contact": "Jo Smith", "team": {"id": "PTEAM01"}}}. name is the field that matters; team.id names the owning team and point_of_contact is free text, not a PagerDuty user reference. Returns raw PagerDuty JSON.
Service Custom Fields
pd_create_service_custom_field details
pd_create_service_custom_field details
[PagerDuty] Create a service custom field definition. Not destructive: additive: a new field DEFINITION holds no values until one is set on a service with pd_update_service_custom_field_values, and it pages nobody. The call needs an API key carrying the custom_fields.write scope. POST /services/custom_fields. Send {"field": {"name": "environment", "display_name": "Environment", "data_type": "string", "field_type": "single_value_fixed", "description": "...", "enabled": true, "field_options": [{"data": {"data_type": "string", "value": "production"}}]}}. name, display_name, data_type and field_type are required. data_type is one of boolean, integer, float, string, datetime or url; field_type is one of single_value, single_value_fixed, multi_value or multi_value_fixed, and only the two fixed kinds may carry field_options. name is at most 50 characters of lowercase letters, digits and underscores, must be unique on the account and CANNOT be changed once created; display_name is at most 50 characters and unique too; description is at most 1000. Returns raw PagerDuty JSON.
pd_create_service_custom_field_option details
pd_create_service_custom_field_option details
[PagerDuty] Create a service custom field option. Not destructive: additive: a new option becomes selectable but is set on no service until someone chooses it. Only a field whose field_type is single_value_fixed or multi_value_fixed accepts options. The call needs an API key carrying the custom_fields.write scope. POST /services/custom_fields//field_options. Path parameters: field_id. Send {"field_option": {"data": {"data_type": "string", "value": "production"}}}. Both data fields are required, data_type must match the field, and value is at most 200 characters and unique within the field. Returns raw PagerDuty JSON.
pd_delete_service_custom_field details
pd_delete_service_custom_field details
[PagerDuty] DESTRUCTIVE: delete a service custom field definition. Why this is destructive: deleting the DEFINITION destroys the values recorded against it on every service, and PagerDuty keeps no copy. DELETE /services/custom_fields/. Path parameters: field_id. Returns raw PagerDuty JSON.
pd_delete_service_custom_field_option details
pd_delete_service_custom_field_option details
[PagerDuty] DESTRUCTIVE: delete a service custom field option. Why this is destructive: services that had selected this option lose it, and PagerDuty keeps no copy of the option. DELETE /services/custom_fields//field_options/. Path parameters: field_id, field_option_id. Returns raw PagerDuty JSON.
pd_get_service_custom_field details
pd_get_service_custom_field details
[PagerDuty] Get a service custom field definition. The account-level DEFINITION of one service custom field - its data type, field type, description and whether it is enabled - not the value on any service, which is pd_get_service_custom_field_values. The call needs an API key carrying the custom_fields.read scope. GET /services/custom_fields/. Path parameters: field_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_service_custom_field_option details
pd_get_service_custom_field_option details
[PagerDuty] Get a service custom field option. One selectable option of a service custom field DEFINITION, with its data_type and value. The call needs an API key carrying the custom_fields.read scope. GET /services/custom_fields//field_options/. Path parameters: field_id, field_option_id. Returns raw PagerDuty JSON.
pd_list_service_custom_field_options details
pd_list_service_custom_field_options details
[PagerDuty] List a service custom field's options. The selectable options of one service custom field DEFINITION. Only a field whose field_type is single_value_fixed or multi_value_fixed has options. The route declares no paging - every option comes back. The call needs an API key carrying the custom_fields.read scope. GET /services/custom_fields//field_options. Path parameters: field_id. Returns raw PagerDuty JSON.
pd_list_service_custom_fields details
pd_list_service_custom_fields details
[PagerDuty] List service custom field definitions. These are the ACCOUNT-LEVEL field DEFINITIONS that can be set on technical services - not the values held by any one service. Use pd_get_service_custom_field_values to read a service's values and pd_update_service_custom_field_values to set them, and the incident custom field tools for incidents. The route declares no paging - every definition comes back. The call needs an API key carrying the custom_fields.read scope. GET /services/custom_fields. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_update_service_custom_field details
pd_update_service_custom_field details
[PagerDuty] DESTRUCTIVE: update a service custom field definition. Why this is destructive: field_options is a REPLACE list, not an append. PagerDuty's own words: an empty array deletes all field options, and not listing an existing option deletes that option, unless it is the field's current default value. A service that had selected a deleted option loses that value and PagerDuty keeps no copy. OMIT the field_options array entirely to edit the display name, description or enabled flag while leaving the options alone. PUT /services/custom_fields/. Path parameters: field_id. Send {"field": {"display_name": "...", "description": "...", "enabled": true}} to edit the definition safely. Adding a field_options array REPLACES the whole option list: options you leave out are deleted. Each option is {"data": {"data_type": "string", "value": "..."}}, and an existing option keeps its id when you include it. Returns raw PagerDuty JSON.
pd_update_service_custom_field_option details
pd_update_service_custom_field_option details
[PagerDuty] Update a service custom field option. Not destructive: it rewrites one option's value, and every service already carrying that option reads the new text - the change is retroactive across existing services, but no service loses its selection and the edit can be made again. PUT /services/custom_fields//field_options/. Path parameters: field_id, field_option_id. Send {"field_option": {"data": {"data_type": "string", "value": "production"}}}. Both data fields are required, data_type must match the field, and value is at most 200 characters and unique within the field. Returns raw PagerDuty JSON.
Service Dependencies
pd_associate_service_dependencies details
pd_associate_service_dependencies details
[PagerDuty] DESTRUCTIVE: associate service dependencies. Why this is destructive: it wires services together in BULK - every pair in relationships is applied in one request - and a dependency edge is what makes a business service show as impacted. A service that is already carrying an open incident can therefore flip the business service above it to impacted the moment the edge lands, which shows on that service's status page and notifies its subscribers. PagerDuty creates exactly the pairs you send rather than replacing the graph, and pd_disassociate_service_dependencies is the only way back. POST /service_dependencies/associate. Send {"relationships": [{"supporting_service": {"id": "P7AD56", "type": "service"}, "dependent_service": {"id": "P99DJ6", "type": "business_service"}}]}. The supporting service is the one underneath; the dependent service is the one that suffers when it breaks. PagerDuty's own sample uses type service for a technical service and business_service for a business service, and either kind may appear on either side. Every pair in the array is applied in one request. Returns raw PagerDuty JSON.
pd_disassociate_service_dependencies details
pd_disassociate_service_dependencies details
[PagerDuty] DESTRUCTIVE: disassociate service dependencies. Why this is destructive: it REMOVES dependency edges in BULK - every pair in relationships goes in one request - so the business-service impact those edges were producing stops being calculated and a customer-facing status page stops reflecting the outage underneath it. PagerDuty keeps no record of a removed edge; pd_associate_service_dependencies has to re-create it. POST /service_dependencies/disassociate. Send {"relationships": [{"supporting_service": {"id": "P7AD56", "type": "service"}, "dependent_service": {"id": "P99DJ6", "type": "business_service"}}]}. The supporting service is the one underneath; the dependent service is the one that suffers when it breaks. PagerDuty's own sample uses type service for a technical service and business_service for a business service, and either kind may appear on either side. Every pair in the array is applied in one request. Returns raw PagerDuty JSON.
pd_list_business_service_dependencies details
pd_list_business_service_dependencies details
[PagerDuty] Get Business Service dependencies. The IMMEDIATE dependencies of one business service - the services directly underneath it, one level, not the whole tree; walk it yourself for deeper levels. Dependency edges are what make a business service show as impacted. The route declares no paging. GET /service_dependencies/business_services/. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_technical_service_dependencies details
pd_list_technical_service_dependencies details
[PagerDuty] Get technical service dependencies. The IMMEDIATE dependencies of one technical service - PagerDuty calls these plain services - one level, not the whole tree. The route declares no paging. GET /service_dependencies/technical_services/. Path parameters: id. Returns raw PagerDuty JSON.
Services
pd_convert_service_event_rules details
pd_convert_service_event_rules details
[PagerDuty] DESTRUCTIVE: convert a Service's Event Rules into Event Orchestration Rules. Why this is destructive: it migrates the service's event rules into an Event Orchestration one way — PagerDuty documents no route back. POST /services//rules/convert. Path parameters: id. Returns raw PagerDuty JSON.
pd_create_service details
pd_create_service details
[PagerDuty] Create a service. Not destructive: additive: a new service pages nobody until an integration routes events to it. POST /services. Send the request body as JSON; PagerDuty documents these fields: service.type, service.name, service.description, service.auto_resolve_timeout, service.acknowledgement_timeout, service.created_at, service.status, service.last_incident_timestamp, service.escalation_policy, service.response_play, service.teams, service.integrations, service.incident_urgency_rule, service.support_hours, service.scheduled_actions, service.addons, service.alert_creation, service.alert_grouping_parameters, service.alert_grouping, service.alert_grouping_timeout, service.auto_pause_notifications_parameters. Returns raw PagerDuty JSON.
pd_create_service_event_rule details
pd_create_service_event_rule details
[PagerDuty] Create an Event Rule on a Service. Not destructive: additive: a new rule is appended and deleting it is a separate tool. POST /services//rules. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: rule.position, rule.actions. Returns raw PagerDuty JSON.
pd_create_service_integration details
pd_create_service_integration details
[PagerDuty] DESTRUCTIVE: create a new integration. Why this is destructive: it MINTS an integration key — a live credential that can trigger incidents on this service from anywhere on the internet. POST /services//integrations. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: integration.type, integration.name, integration.service, integration.created_at, integration.vendor, integration.integration_email, integration.email_incident_creation, integration.email_filter_mode, integration.email_parsers, integration.email_parsing_fallback, integration.email_filters. Returns raw PagerDuty JSON.
pd_delete_service details
pd_delete_service details
[PagerDuty] DESTRUCTIVE: delete a service. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /services/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_service_event_rule details
pd_delete_service_event_rule details
[PagerDuty] DESTRUCTIVE: delete an Event Rule from a Service. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /services//rules/. Path parameters: id, rule_id. Returns raw PagerDuty JSON.
pd_get_service details
pd_get_service details
[PagerDuty] Get a service. GET /services/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_service_custom_field_values details
pd_get_service_custom_field_values details
[PagerDuty] Get Custom Field Values. GET /services//custom_fields/values. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_service_event_rule details
pd_get_service_event_rule details
[PagerDuty] Get an Event Rule from a Service. GET /services//rules/. Path parameters: id, rule_id. Returns raw PagerDuty JSON.
pd_get_service_integration details
pd_get_service_integration details
[PagerDuty] View an integration. GET /services//integrations/. Path parameters: id, integration_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_service_audit_records details
pd_list_service_audit_records details
[PagerDuty] List audit records for a service. GET /services//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_service_enablements details
pd_list_service_enablements details
[PagerDuty] Get Enablements for a Service. GET /services//enablements. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_service_event_rules details
pd_list_service_event_rules details
[PagerDuty] List Service's Event Rules. GET /services//rules. Path parameters: id. Optional filters: include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_services details
pd_list_services details
[PagerDuty] List services. GET /services. Optional filters: query, team_ids[], time_zone, sort_by, include[], name. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_update_service details
pd_update_service details
[PagerDuty] DESTRUCTIVE: update a service. Why this is destructive: A collection you send replaces the stored one, so a member you leave out is dropped from the service. Send complete lists rather than partial ones. Nothing is deleted outright and the service can be edited again, but an omitted member does not come back on its own. PUT /services/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: service.type, service.name, service.description, service.auto_resolve_timeout, service.acknowledgement_timeout, service.created_at, service.status, service.last_incident_timestamp, service.escalation_policy, service.response_play, service.teams, service.integrations, service.incident_urgency_rule, service.support_hours, service.scheduled_actions, service.addons, service.alert_creation, service.alert_grouping_parameters, service.alert_grouping, service.alert_grouping_timeout, service.auto_pause_notifications_parameters. Returns raw PagerDuty JSON.
pd_update_service_custom_field_values details
pd_update_service_custom_field_values details
[PagerDuty] Update Custom Field Values. Not destructive: field values are metadata: the call sets only the fields it is given and they can be set again. PUT /services//custom_fields/values. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: custom_fields. Returns raw PagerDuty JSON.
pd_update_service_enablement details
pd_update_service_enablement details
[PagerDuty] Update an Enablement for a Service. Not destructive: it is a reversible on/off switch for one product feature on one service. PUT /services//enablements/. Path parameters: id, feature_name. Send the request body as JSON; PagerDuty documents these fields: enablement.feature, enablement.enabled, enablement.updated_at, enablement.warnings. Returns raw PagerDuty JSON.
pd_update_service_event_rule details
pd_update_service_event_rule details
[PagerDuty] Update an Event Rule on a Service. Not destructive: it edits one rule's conditions and actions, and the edit can be made again. PUT /services//rules/. Path parameters: id, rule_id. Send the request body as JSON; PagerDuty documents these fields: rule.position, rule.actions, rule_id. Returns raw PagerDuty JSON.
pd_update_service_integration details
pd_update_service_integration details
[PagerDuty] DESTRUCTIVE: update an existing integration. Why this is destructive: PagerDuty replaces the stored integration with what you send, so an email parser you leave out of email_parsers or a filter you leave out of email_filters is gone and mail it was matching is routed or dropped differently from the moment it is saved. Send the COMPLETE lists. The integration key is not reissued and the settings can be edited again. PUT /services//integrations/. Path parameters: id, integration_id. Send the request body as JSON; PagerDuty documents these fields: integration.type, integration.name, integration.service, integration.created_at, integration.vendor, integration.integration_email, integration.email_incident_creation, integration.email_filter_mode, integration.email_parsers, integration.email_parsing_fallback, integration.email_filters. Returns raw PagerDuty JSON.
Status Dashboards
pd_get_status_dashboard details
pd_get_status_dashboard details
[PagerDuty] Get a single Status Dashboard by `id`. A Status Dashboard is PagerDuty's own view of Business Service health - it is not a Status Page and nothing on it is published to the customer's own users. The row also carries the url_slug the by-slug tools take. GET /status_dashboards/. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_status_dashboard_by_url_slug details
pd_get_status_dashboard_by_url_slug details
[PagerDuty] Get a single Status Dashboard by `url_slug`. The same dashboard as pd_get_status_dashboard, addressed by its human-readable url_slug instead of its id. A Status Dashboard is PagerDuty's own view of Business Service health - it is not a Status Page and nothing on it is published to the customer's own users. GET /status_dashboards/url_slugs/. Path parameters: url_slug. Returns raw PagerDuty JSON.
pd_list_status_dashboard_service_impacts details
pd_list_status_dashboard_service_impacts details
[PagerDuty] Get the most impacted Business Services on a Status Dashboard, by dashboard id. NOT an exhaustive list: PagerDuty returns the most impacted Business Services on this dashboard up to a limit of 200 that it applies itself, sorted by impact, then by most recently impacted, then by name. There is no paging parameter on this route; for a Business Service that does not appear, ask for it by id with pd_list_business_service_impacts and its ids[] parameter. GET /status_dashboards//service_impacts. Path parameters: id. Optional filters: additional_fields[]. Returns raw PagerDuty JSON.
pd_list_status_dashboard_service_impacts_by_url_slug details
pd_list_status_dashboard_service_impacts_by_url_slug details
[PagerDuty] Get the most impacted Business Services on a Status Dashboard, by url_slug. NOT an exhaustive list: PagerDuty returns the most impacted Business Services on this dashboard up to a limit of 200 that it applies itself, sorted by impact, then by most recently impacted, then by name. There is no paging parameter on this route; for a Business Service that does not appear, ask for it by id with pd_list_business_service_impacts and its ids[] parameter. GET /status_dashboards/url_slugs//service_impacts. Path parameters: url_slug. Optional filters: additional_fields[]. Returns raw PagerDuty JSON.
pd_list_status_dashboards details
pd_list_status_dashboards details
[PagerDuty] List the account's Status Dashboards. A Status Dashboard is PagerDuty's own view of Business Service health - it is not a Status Page and nothing on it is published to the customer's own users - the customer-facing pages are pd_list_status_pages. Each row carries the id and the url_slug the other dashboard tools take. Unpaged: PagerDuty declares no limit or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries a cursor envelope (limit, next_cursor) that this route gives you no cursor parameter to follow. GET /status_dashboards. Returns raw PagerDuty JSON.
Status Pages
pd_create_status_page_post details
pd_create_status_page_post details
[PagerDuty] DESTRUCTIVE: create a Status Page Post. Why this is destructive: it publishes a post to a status page the customer's OWN audience reads - a public page is reachable by anyone on the internet - and the required post.updates array carries Post Updates whose notify_subscribers flag emails or webhooks every subscriber of that page. POST /status_pages//posts. Path parameters: id. The request body as JSON, wrapped in a single post object. PagerDuty's required set is post.type (the literal status_page_post), post.title, post.post_type (incident or maintenance), post.starts_at, post.ends_at, post.status_page (an object carrying the id of this same Status Page) and post.updates, the array of Post Updates the page shows - each entry carries the SAME required set as a standalone Post Update (type, message, status, severity, impacted_services, update_frequency_ms, notify_subscribers and post), so a create can notify subscribers on its first call. starts_at and ends_at are in that required set although PagerDuty's own field notes say they apply only to a maintenance post. Returns raw PagerDuty JSON.
pd_create_status_page_post_update details
pd_create_status_page_post_update details
[PagerDuty] DESTRUCTIVE: create a Status Page Post Update. Why this is destructive: a Post Update is the communication subscribers are notified about, and notify_subscribers is in PagerDuty's required set, so every call decides whether to email or webhook every subscriber of the customer's status page, and the update appears on the page either way. POST /status_pages//posts//post_updates. Path parameters: id, post_id. The request body as JSON, a single post_update object. PagerDuty's required set is post_update.type, post_update.message (what subscribers are sent), post_update.status and post_update.severity (OBJECTS carrying an id from pd_list_status_page_statuses and pd_list_status_page_severities), post_update.impacted_services (an array of {service, impact} pairs, each side an object carrying an id - service ids come from pd_list_status_page_services and impact ids from pd_list_status_page_impacts), post_update.update_frequency_ms, post_update.notify_subscribers and post_update.post (an object carrying the post's id). Optional: post_update.reported_at back-dates when the update was reported. post_update.self is read-only in PagerDuty's schema - do not send it. Returns raw PagerDuty JSON.
pd_create_status_page_subscription details
pd_create_status_page_subscription details
[PagerDuty] DESTRUCTIVE: create a Status Page Subscription. Why this is destructive: it adds a subscriber to the customer's status page - PagerDuty's create schema accepts the email and webhook channels, so the contact is a real person's email address or a live webhook URL, and from this call on it receives that page's notifications until pd_delete_status_page_subscription removes it. POST /status_pages//subscriptions. Path parameters: id. The request body as JSON, a single subscription object. PagerDuty's required set is subscription.channel (email or webhook on a create - slack appears on existing subscriptions but cannot be created here), subscription.contact (the subscriber's email address or webhook URL), subscription.status_page (an object carrying the id of this same Status Page), subscription.subscribable_object (an id plus a type of status_page, status_page_service or status_page_post - what they are subscribing to) and subscription.type. Returns raw PagerDuty JSON.
pd_delete_status_page_post details
pd_delete_status_page_post details
[PagerDuty] DESTRUCTIVE: delete a Status Page Post. Why this is destructive: the post stops being shown on the customer-facing status page and PagerDuty keeps no copy; subscribers already notified about it keep the notification, and its Post Updates and any Postmortem are reachable only through the post. DELETE /status_pages//posts/. Path parameters: id, post_id. Returns raw PagerDuty JSON.
pd_delete_status_page_post_update details
pd_delete_status_page_post_update details
[PagerDuty] DESTRUCTIVE: delete a Status Page Post Update. Why this is destructive: an update subscribers were already emailed or webhooked is removed from the customer-facing page and PagerDuty keeps no copy; the notification itself cannot be recalled. DELETE /status_pages//posts//post_updates/. Path parameters: id, post_id, post_update_id. Returns raw PagerDuty JSON.
pd_delete_status_page_postmortem details
pd_delete_status_page_postmortem details
[PagerDuty] DESTRUCTIVE: delete a Post Postmortem. Why this is destructive: the published follow-up disappears from the customer-facing status page and PagerDuty keeps no copy. DELETE /status_pages//posts//postmortem. Path parameters: id, post_id. Returns raw PagerDuty JSON.
pd_delete_status_page_subscription details
pd_delete_status_page_subscription details
[PagerDuty] DESTRUCTIVE: delete a Status Page Subscription. Why this is destructive: that subscriber stops receiving the customer's status notifications, and putting them back needs their contact again through pd_create_status_page_subscription. DELETE /status_pages//subscriptions/. Path parameters: id, subscription_id. Returns raw PagerDuty JSON.
pd_get_status_page_impact details
pd_get_status_page_impact details
[PagerDuty] Get a Status Page Impact. One impact level from the page's vocabulary: description is the human-readable label and post_type says which kind of post it applies to. GET /status_pages//impacts/. Path parameters: id, impact_id. Returns raw PagerDuty JSON.
pd_get_status_page_post details
pd_get_status_page_post details
[PagerDuty] Get a Status Page Post. One post as the customer's audience sees it. Ask for include[]=status_page_post_update to get the post's updates inline instead of a second call to pd_list_status_page_post_updates. GET /status_pages//posts/. Path parameters: id, post_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_status_page_post_update details
pd_get_status_page_post_update details
[PagerDuty] Get a Status Page Post Update. One update on a post, including the message subscribers were sent and whether notify_subscribers was set on it. GET /status_pages//posts//post_updates/. Path parameters: id, post_id, post_update_id. Returns raw PagerDuty JSON.
pd_get_status_page_postmortem details
pd_get_status_page_postmortem details
[PagerDuty] Get a Post Postmortem. The follow-up published on the post for the customer's own audience; its message supports rich text. A post carries at most one, written by pd_set_status_page_postmortem. GET /status_pages//posts//postmortem. Path parameters: id, post_id. Returns raw PagerDuty JSON.
pd_get_status_page_service details
pd_get_status_page_service details
[PagerDuty] Get a Status Page Service. One service entry on the page: the name the page shows and the business_service it is linked to. GET /status_pages//services/. Path parameters: id, service_id. Returns raw PagerDuty JSON.
pd_get_status_page_severity details
pd_get_status_page_severity details
[PagerDuty] Get a Status Page Severity. One severity level from the page's vocabulary: description is the human-readable label and post_type says which kind of post it applies to. GET /status_pages//severities/. Path parameters: id, severity_id. Returns raw PagerDuty JSON.
pd_get_status_page_status details
pd_get_status_page_status details
[PagerDuty] Get a Status Page Status. One status level from the page's vocabulary: description is the human-readable label and post_type says which kind of post it applies to. GET /status_pages//statuses/. Path parameters: id, status_id. Returns raw PagerDuty JSON.
pd_get_status_page_subscription details
pd_get_status_page_subscription details
[PagerDuty] Get a Status Page Subscription. One subscriber of the page: the channel, their contact (an email address or a webhook URL) and the subscribable_object they subscribed to - the whole page, one service or one post. GET /status_pages//subscriptions/. Path parameters: id, subscription_id. Returns raw PagerDuty JSON.
pd_list_status_page_impacts details
pd_list_status_page_impacts details
[PagerDuty] List a Status Page's Impact levels. Reference data rather than incidents: the impact vocabulary a Post Update's impacted_services entries reference, defined per post_type. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//impacts. Path parameters: id. Optional filters: post_type. Returns raw PagerDuty JSON.
pd_list_status_page_post_updates details
pd_list_status_page_post_updates details
[PagerDuty] List a Post's Updates. Post Updates are the individual communications on a post - each carries the message subscribers were sent, the status and severity it reported, the services it said were impacted and whether notify_subscribers was set. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//posts//post_updates. Path parameters: id, post_id. Optional filters: reviewed_status. Returns raw PagerDuty JSON.
pd_list_status_page_posts details
pd_list_status_page_posts details
[PagerDuty] List a Status Page's Posts. Posts are what the customer's own audience reads on the page: post_type incident is an outage communication, maintenance is a planned window with starts_at and ends_at. Each row's updates array references the Post Updates subscribers were notified about. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//posts. Path parameters: id. Optional filters: post_type, reviewed_status, status[]. Returns raw PagerDuty JSON.
pd_list_status_page_services details
pd_list_status_page_services details
[PagerDuty] List the Business Services published on a Status Page. Each row links a PagerDuty Business Service to this page and is what a Post Update's impacted_services array points at. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//services. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_status_page_severities details
pd_list_status_page_severities details
[PagerDuty] List a Status Page's Severity levels. Reference data rather than incidents: the severity vocabulary a Post Update may reference, defined per post_type. Read it before composing pd_create_status_page_post_update, which sends a severity id from here. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//severities. Path parameters: id. Optional filters: post_type. Returns raw PagerDuty JSON.
pd_list_status_page_statuses details
pd_list_status_page_statuses details
[PagerDuty] List a Status Page's Status levels. Reference data rather than incidents: the status vocabulary a Post Update may reference, and the ids the status[] filter on pd_list_status_page_posts takes, defined per post_type. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//statuses. Path parameters: id. Optional filters: post_type. Returns raw PagerDuty JSON.
pd_list_status_page_subscriptions details
pd_list_status_page_subscriptions details
[PagerDuty] List a Status Page's subscribers. Every row carries a subscriber's own contact - an email address or a webhook URL - so the response is the customer's contact data. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages//subscriptions. Path parameters: id. Optional filters: status, channel. Returns raw PagerDuty JSON.
pd_list_status_pages details
pd_list_status_pages details
[PagerDuty] List the account's Status Pages. A Status Page is the page the customer's OWN users read: status_page_type public means it is reachable by anyone on the internet, private means it needs a sign-in, and each row carries the url it is served on. Every other tool in this family takes that row's id. Unpaged: PagerDuty declares no limit, offset or cursor parameter on this route, so StackJack sends none and one call is all there is. The body still carries PagerDuty's list envelope (offset, limit, more, total) and a more of true has no parameter here to act on - narrow with the filters instead. A large response is handled by StackJack's result-size cap and its spill lane. GET /status_pages. Optional filters: status_page_type. Returns raw PagerDuty JSON.
pd_set_status_page_postmortem details
pd_set_status_page_postmortem details
[PagerDuty] DESTRUCTIVE: create or update a Post Postmortem. Why this is destructive: one call creates or REPLACES the post's postmortem - a post carries at most one and PagerDuty keeps no prior version - and postmortem.notify_subscribers is in its required set, so publishing it can email or webhook every subscriber of the customer's status page. PUT /status_pages//posts//postmortem. Path parameters: id, post_id. The request body as JSON, a single postmortem object. PagerDuty's required set is postmortem.type (the literal status_page_post_postmortem, which its schema also marks read-only), postmortem.post (the post's id), postmortem.message (the follow-up text, rich text supported) and postmortem.notify_subscribers - true notifies every subscriber of the page. Returns raw PagerDuty JSON.
pd_update_status_page_post details
pd_update_status_page_post details
[PagerDuty] DESTRUCTIVE: update a Status Page Post. Why this is destructive: a wholesale PUT replace of a post the customer's own audience has already read - PagerDuty requires type, title, post_type, starts_at, ends_at and status_page on every call, so the post is rewritten from the body you send rather than patched, and it keeps no prior version - read the post with pd_get_status_page_post first and carry every field forward. PUT /status_pages//posts/. Path parameters: id, post_id. The request body as JSON, a single post object; PagerDuty requires post.type, post.title, post.post_type, post.starts_at, post.ends_at and post.status_page. Unlike the create, this schema has no updates array - Post Updates are written with pd_create_status_page_post_update and pd_update_status_page_post_update. Returns raw PagerDuty JSON.
pd_update_status_page_post_update details
pd_update_status_page_post_update details
[PagerDuty] DESTRUCTIVE: update a Status Page Post Update. Why this is destructive: a wholesale PUT replace of an update subscribers were already sent - message, status, severity, impacted_services, update_frequency_ms and notify_subscribers are all in PagerDuty's required set, so the update is rewritten from the body you send and it keeps no prior version, and notify_subscribers rides that same set so a rewrite can notify every subscriber again. PUT /status_pages//posts//post_updates/. Path parameters: id, post_id, post_update_id. The request body as JSON, a single post_update object - the same schema as the create, and a full replace. PagerDuty requires post_update.type, post_update.message, post_update.status and post_update.severity (objects carrying a Status id and a Severity id), post_update.impacted_services (an array of {service, impact} pairs, each side an object carrying an id), post_update.update_frequency_ms, post_update.notify_subscribers and post_update.post. Optional: post_update.reported_at back-dates when the update was reported. post_update.self is read-only - do not send it. Returns raw PagerDuty JSON.
Teams
pd_add_team_escalation_policy details
pd_add_team_escalation_policy details
[PagerDuty] Add an escalation policy to a team. Not destructive: additive: it associates an existing policy with the team and removal is a separate tool. PUT /teams//escalation_policies/. Path parameters: id, escalation_policy_id. Returns raw PagerDuty JSON.
pd_add_team_notification_subscriptions details
pd_add_team_notification_subscriptions details
[PagerDuty] DESTRUCTIVE: create Team Notification Subscriptions. Why this is destructive: everyone on the team starts receiving status updates for the subscribed objects. POST /teams//notification_subscriptions. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribables. Returns raw PagerDuty JSON.
pd_add_team_user details
pd_add_team_user details
[PagerDuty] Add a user to a team. Not destructive: additive: it adds a member to the team and removal is a separate tool. PUT /teams//users/. Path parameters: id, user_id. Send the request body as JSON; PagerDuty documents these fields: role. Returns raw PagerDuty JSON.
pd_create_team details
pd_create_team details
[PagerDuty] Create a team. Not destructive: additive: an empty team pages nobody and deleting it is a separate tool. POST /teams. Send the request body as JSON; PagerDuty documents these fields: team.type, team.name, team.description, team.default_role. Returns raw PagerDuty JSON.
pd_delete_team details
pd_delete_team details
[PagerDuty] DESTRUCTIVE: delete a team. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /teams/. Path parameters: id. Optional filters: reassignment_team. Returns raw PagerDuty JSON.
pd_get_team details
pd_get_team details
[PagerDuty] Get a team. GET /teams/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_team_audit_records details
pd_list_team_audit_records details
[PagerDuty] List audit records for a team. GET /teams//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_team_members details
pd_list_team_members details
[PagerDuty] List members of a team. GET /teams//members. Path parameters: id. Optional filters: include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_list_team_notification_subscriptions details
pd_list_team_notification_subscriptions details
[PagerDuty] List Team Notification Subscriptions. GET /teams//notification_subscriptions. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_teams details
pd_list_teams details
[PagerDuty] List teams. GET /teams. Optional filters: query. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_remove_team_escalation_policy details
pd_remove_team_escalation_policy details
[PagerDuty] DESTRUCTIVE: remove an escalation policy from a team. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /teams//escalation_policies/. Path parameters: id, escalation_policy_id. Returns raw PagerDuty JSON.
pd_remove_team_notification_subscriptions details
pd_remove_team_notification_subscriptions details
[PagerDuty] DESTRUCTIVE: remove team notification subscriptions. Why this is destructive: the team stops being told what is happening to the unsubscribed objects. POST /teams//notification_subscriptions/unsubscribe. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribables. Returns raw PagerDuty JSON.
pd_remove_team_user details
pd_remove_team_user details
[PagerDuty] DESTRUCTIVE: remove a user from a team. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /teams//users/. Path parameters: id, user_id. Returns raw PagerDuty JSON.
pd_update_team details
pd_update_team details
[PagerDuty] Update a team. Not destructive: it renames or re-describes a team; membership and escalation policies are separate tools. PUT /teams/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: team.type, team.name, team.description, team.default_role. Returns raw PagerDuty JSON.
Users
pd_add_user_notification_subscriptions details
pd_add_user_notification_subscriptions details
[PagerDuty] DESTRUCTIVE: create Notification Subcriptions. Why this is destructive: the user starts receiving status updates for the subscribed objects. POST /users//notification_subscriptions. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribables. Returns raw PagerDuty JSON.
pd_create_user details
pd_create_user details
[PagerDuty] DESTRUCTIVE: create a user. Why this is destructive: PagerDuty emails the new user an invitation and the account consumes a paid license. POST /users. Send the request body as JSON; PagerDuty documents these fields: user.license. Returns raw PagerDuty JSON.
pd_create_user_contact_method details
pd_create_user_contact_method details
[PagerDuty] Create a user contact method. Not destructive: additive: it adds a phone number or address to the user and nothing pages it until a notification rule names it. POST /users//contact_methods. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: contact_method. Returns raw PagerDuty JSON.
pd_create_user_handoff_notification_rule details
pd_create_user_handoff_notification_rule details
[PagerDuty] DESTRUCTIVE: create a User Handoff Notification Rule. Why this is destructive: handoff rules decide whether this person is told they are about to go on call. POST /users//oncall_handoff_notification_rules. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: oncall_handoff_notification_rule.id, oncall_handoff_notification_rule.notify_advance_in_minutes, oncall_handoff_notification_rule.handoff_type, oncall_handoff_notification_rule.contact_method. Returns raw PagerDuty JSON.
pd_create_user_notification_rule details
pd_create_user_notification_rule details
[PagerDuty] DESTRUCTIVE: create a user notification rule. Why this is destructive: notification rules decide how and how fast this person is paged. POST /users//notification_rules. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: notification_rule.type, notification_rule.start_delay_in_minutes, notification_rule.contact_method, notification_rule.urgency. Returns raw PagerDuty JSON.
pd_create_user_status_update_rule details
pd_create_user_status_update_rule details
[PagerDuty] DESTRUCTIVE: create a user status update notification rule. Why this is destructive: status-update rules decide which incident updates reach this person. POST /users//status_update_notification_rules. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: status_update_notification_rule.contact_method. Returns raw PagerDuty JSON.
pd_delete_all_user_sessions details
pd_delete_all_user_sessions details
[PagerDuty] DESTRUCTIVE: delete all user sessions. Why this is destructive: it signs the person out of EVERY PagerDuty web session they have open, on every device. A PagerDuty SESSION is that person's own browser sign-in to the PagerDuty web app, not an API credential: the response identifies the session so it can be ended, and never returns a cookie or a token. PagerDuty flags this whole group deprecated and publishes no replacement. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. DELETE /users//sessions. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_user details
pd_delete_user details
[PagerDuty] DESTRUCTIVE: delete a user. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /users/. Path parameters: id. Returns raw PagerDuty JSON.
pd_delete_user_contact_method details
pd_delete_user_contact_method details
[PagerDuty] DESTRUCTIVE: delete a user's contact method. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /users//contact_methods/. Path parameters: id, contact_method_id. Returns raw PagerDuty JSON.
pd_delete_user_handoff_notification_rule details
pd_delete_user_handoff_notification_rule details
[PagerDuty] DESTRUCTIVE: delete a User's Handoff Notification rule. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /users//oncall_handoff_notification_rules/. Path parameters: id, oncall_handoff_notification_rule_id. Returns raw PagerDuty JSON.
pd_delete_user_notification_rule details
pd_delete_user_notification_rule details
[PagerDuty] DESTRUCTIVE: delete a user's notification rule. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /users//notification_rules/. Path parameters: id, notification_rule_id. Returns raw PagerDuty JSON.
pd_delete_user_session details
pd_delete_user_session details
[PagerDuty] DESTRUCTIVE: delete a user's session. Why this is destructive: it signs the person out of that PagerDuty web session. A PagerDuty SESSION is that person's own browser sign-in to the PagerDuty web app, not an API credential: the response identifies the session so it can be ended, and never returns a cookie or a token. PagerDuty flags this whole group deprecated and publishes no replacement. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. DELETE /users//sessions//. Path parameters: id, type, session_id. Returns raw PagerDuty JSON.
pd_delete_user_status_update_rule details
pd_delete_user_status_update_rule details
[PagerDuty] DESTRUCTIVE: delete a user's status update notification rule. Why this is destructive: it deletes the record and PagerDuty keeps no copy. DELETE /users//status_update_notification_rules/. Path parameters: id, status_update_notification_rule_id. Returns raw PagerDuty JSON.
pd_get_current_user details
pd_get_current_user details
[PagerDuty] Get the current user. PagerDuty answers this only for a personal (user-level) API key or an OAuth token - it does not work with the account-level API key this connector normally uses, so prefer pd_list_users or pd_get_user. GET /users/me. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_user details
pd_get_user details
[PagerDuty] Get a user. GET /users/. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_user_contact_method details
pd_get_user_contact_method details
[PagerDuty] Get a user's contact method. GET /users//contact_methods/. Path parameters: id, contact_method_id. Returns raw PagerDuty JSON.
pd_get_user_handoff_notification_rule details
pd_get_user_handoff_notification_rule details
[PagerDuty] Get a user's handoff notification rule. GET /users//oncall_handoff_notification_rules/. Path parameters: id, oncall_handoff_notification_rule_id. Returns raw PagerDuty JSON.
pd_get_user_license details
pd_get_user_license details
[PagerDuty] Get the License allocated to a User. GET /users//license. Path parameters: id. Returns raw PagerDuty JSON.
pd_get_user_notification_rule details
pd_get_user_notification_rule details
[PagerDuty] Get a user's notification rule. GET /users//notification_rules/. Path parameters: id, notification_rule_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_get_user_oauth_delegation details
pd_get_user_oauth_delegation details
[PagerDuty] Get a user's delegation. GET /users//oauth_delegations/. Path parameters: id, delegation_id. Returns raw PagerDuty JSON.
pd_get_user_session details
pd_get_user_session details
[PagerDuty] Get a user's session. A PagerDuty SESSION is that person's own browser sign-in to the PagerDuty web app, not an API credential: the response identifies the session so it can be ended, and never returns a cookie or a token. PagerDuty flags this whole group deprecated and publishes no replacement. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /users//sessions//. Path parameters: id, type, session_id. Returns raw PagerDuty JSON.
pd_get_user_status_update_rule details
pd_get_user_status_update_rule details
[PagerDuty] Get a user's status update notification rule. GET /users//status_update_notification_rules/. Path parameters: id, status_update_notification_rule_id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_user_audit_records details
pd_list_user_audit_records details
[PagerDuty] List audit records for a user. GET /users//audit/records. Path parameters: id. Optional filters: since, until. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_user_contact_methods details
pd_list_user_contact_methods details
[PagerDuty] List a user's contact methods. GET /users//contact_methods. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_user_handoff_notification_rules details
pd_list_user_handoff_notification_rules details
[PagerDuty] List a User's Handoff Notification Rules. GET /users//oncall_handoff_notification_rules. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_user_notification_rules details
pd_list_user_notification_rules details
[PagerDuty] List a user's notification rules. GET /users//notification_rules. Path parameters: id. Optional filters: include[], urgency. Returns raw PagerDuty JSON.
pd_list_user_notification_subscriptions details
pd_list_user_notification_subscriptions details
[PagerDuty] List Notification Subscriptions. GET /users//notification_subscriptions. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_user_oauth_delegations details
pd_list_user_oauth_delegations details
[PagerDuty] List a user's delegations. GET /users//oauth_delegations. Path parameters: id. Optional filters: delegation_type, status. Paged with an opaque cursor: pass the previous response next_cursor value back as cursor. A null next_cursor means there are no more pages. Returns raw PagerDuty JSON.
pd_list_user_sessions details
pd_list_user_sessions details
[PagerDuty] List a user's active sessions. A PagerDuty SESSION is that person's own browser sign-in to the PagerDuty web app, not an API credential: the response identifies the session so it can be ended, and never returns a cookie or a token. PagerDuty flags this whole group deprecated and publishes no replacement. DEPRECATED: PagerDuty flags this operation deprecated in its own API document; prefer the current equivalent where one exists, and expect it to be withdrawn. GET /users//sessions. Path parameters: id. Returns raw PagerDuty JSON.
pd_list_user_status_update_rules details
pd_list_user_status_update_rules details
[PagerDuty] List a user's status update notification rules. GET /users//status_update_notification_rules. Path parameters: id. Optional filters: include[]. Returns raw PagerDuty JSON.
pd_list_users details
pd_list_users details
[PagerDuty] List users. GET /users. Optional filters: query, team_ids[], include[]. Paged with limit and offset: limit caps at 100. PagerDuty REFUSES any request whose offset plus limit exceeds 10000 - it answers 400 rather than an empty page - so narrow by date, team or service instead of paging past that. The response total is null unless explicitly requested and StackJack never requests it (PagerDuty documents it as slow); drive a loop off the more flag. Returns raw PagerDuty JSON.
pd_regenerate_user_calendar_url_key details
pd_regenerate_user_calendar_url_key details
[PagerDuty] DESTRUCTIVE: regenerate a user's calendar feed URL key. Why this is destructive: it mints a new calendar-feed key and the old URL stops working wherever it was subscribed. POST /users//regenerate_private_url_key. Path parameters: id. Returns raw PagerDuty JSON.
pd_remove_user_notification_subscriptions details
pd_remove_user_notification_subscriptions details
[PagerDuty] DESTRUCTIVE: remove Notification Subscriptions. Why this is destructive: the user stops being told what is happening to the unsubscribed objects. POST /users//notification_subscriptions/unsubscribe. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: subscribables. Returns raw PagerDuty JSON.
pd_update_user details
pd_update_user details
[PagerDuty] DESTRUCTIVE: update a user. Why this is destructive: the same body that edits a name can change the user's ROLE, which is a privilege grant. PUT /users/. Path parameters: id. Send the request body as JSON; PagerDuty documents these fields: user.license. Returns raw PagerDuty JSON.
pd_update_user_contact_method details
pd_update_user_contact_method details
[PagerDuty] Update a user's contact method. Not destructive: it edits one contact method's label and address, and the edit can be made again. PUT /users//contact_methods/. Path parameters: id, contact_method_id. Send the request body as JSON; PagerDuty documents these fields: contact_method. Returns raw PagerDuty JSON.
pd_update_user_handoff_notification_rule details
pd_update_user_handoff_notification_rule details
[PagerDuty] DESTRUCTIVE: update a User's Handoff Notification Rule. Why this is destructive: handoff rules decide whether this person is told they are about to go on call. PUT /users//oncall_handoff_notification_rules/. Path parameters: id, oncall_handoff_notification_rule_id. Send the request body as JSON; PagerDuty documents these fields: oncall_handoff_notification_rule.id, oncall_handoff_notification_rule.notify_advance_in_minutes, oncall_handoff_notification_rule.handoff_type, oncall_handoff_notification_rule.contact_method. Returns raw PagerDuty JSON.
pd_update_user_notification_rule details
pd_update_user_notification_rule details
[PagerDuty] DESTRUCTIVE: update a user's notification rule. Why this is destructive: notification rules decide how and how fast this person is paged. PUT /users//notification_rules/. Path parameters: id, notification_rule_id. Send the request body as JSON; PagerDuty documents these fields: notification_rule.type, notification_rule.start_delay_in_minutes, notification_rule.contact_method, notification_rule.urgency. Returns raw PagerDuty JSON.
pd_update_user_status_update_rule details
pd_update_user_status_update_rule details
[PagerDuty] DESTRUCTIVE: update a user's status update notification rule. Why this is destructive: status-update rules decide which incident updates reach this person. PUT /users//status_update_notification_rules/. Path parameters: id, status_update_notification_rule_id. Send the request body as JSON; PagerDuty documents these fields: status_update_notification_rule.contact_method. Returns raw PagerDuty JSON.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team