Connect AlertOps
AlertOps is an on-call scheduling and incident-response platform. Alerts arrive from your monitoring tools, AlertOps routes them by escalation policy to the right group and the right person on the…
Written By Christopher Scaminaci
Last updated 6 days ago
AlertOps is an on-call scheduling and incident-response platform. Alerts arrive from your monitoring tools, AlertOps routes them by escalation policy to the right group and the right person on the on-call schedule, and pages that person by email, SMS, voice or Slack until somebody responds. If you have ever asked "who is on call right now" or "why did that alert go to the wrong team", AlertOps is where the answer lives.
Connecting AlertOps to StackJack gives your AI assistant a family of alertops_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer the on-call question instantly — who is on call right now, which group they belong to, and what each engineer's upcoming schedule looks like
- Work the alert queue — list and read alerts with full detail, follow an alert's timeline, read its notes and messages, and see exactly who was notified and how
- Explain routing — read the escalation policy behind an alert, its recipients and member roles, and the inbound integration that created the alert in the first place
- Track incidents — read incidents, their notifications and their post-incident reviews, and see which status-page services and components are affected
- Audit the setup — users and their contact methods, groups and membership, topics, workflows, conference bridges and open maintenance windows
- Triage and respond (on Pro plans) — assign an alert, add notes, close or snooze it, close a batch in one go, and write up the postmortem
- Manage the rotation (on Pro plans) — create and adjust on-call schedules, add and remove group members, mark an engineer out of office, and open a maintenance window
- Configure routing (on Pro plans) — create and edit escalation policies, their recipients and outbound actions, and enable or disable inbound integrations
How StackJack authenticates to AlertOps
AlertOps uses a single API key. You generate it once in the AlertOps console and paste it into StackJack — there is no client ID, no second secret, no sign-in, and nothing that expires on a schedule.
Sign in as the right user first
This is the one decision worth making carefully, because it determines what works.
AlertOps has no per-key permissions. A key can do exactly what the person who created it can do, and there are no checkboxes to narrow it afterwards. So:
- Create the key as an AlertOps administrator. The user, group, escalation-policy and integration areas need administrator access, and so does the connection test.
- A key created by a limited user will not pass the connection test. The test reads one row from the user directory, which is one of the administrator-only areas. StackJack rechecks the connection on a schedule, so a limited-user key does not merely fail once — after a few failed rechecks StackJack disables the connection and asks you to re-enter it. Use an administrator's key.
It is also worth thinking about whose account you use. The key is tied to the person who made it, so a key minted by someone who later leaves is a key that can stop working without warning. Use an account that will stay active.
Steps
- Sign in to AlertOps as the user whose access you want the key to inherit — an administrator, in most cases.
- Open Configuration → Integrations → API.
- Generate a new API key and give it a name that identifies StackJack, so it is obvious what to revoke later.
- Copy the key immediately and store it securely. Treat it as a password: anyone holding it can read your alerts and page your on-call staff.
- Paste it into StackJack. Open Connectors, choose AlertOps, and paste the key into the API Key field. There is no URL to enter — AlertOps is a single global service.
- Run a Test Connection. A green result means StackJack reached AlertOps and the key was accepted.
Rotating the key
The key never expires on its own, which is convenient and also means nothing will remind you. Rotate it deliberately: generate a replacement in AlertOps, paste the new one into StackJack, run a Test Connection, and only then revoke the old key in the AlertOps console.
Two things to know before you read the results
These are properties of the AlertOps API rather than of StackJack, and both are easy to misread.
Listing alerts returns only today's alerts unless you ask for a date range. AlertOps sets the created-from and created-to filters to today's date when you leave them empty. An AI assistant that asks for "recent alerts" with no window will get today's and reasonably conclude there is nothing else. Ask for an explicit range instead — "alerts from the first of the month to today". The range cannot be wider than six months; a wider one is rejected outright rather than quietly trimmed. The same applies to the closed-date filters.
Most lists return everything at once. Only six of the AlertOps lists page at all — alerts, escalation policies, groups, inbound integrations, users and workflows — and those cap out at 100 results per page. Everything else hands back the whole collection in one response. If a result looks unexpectedly long, that is why.
What only reads, and what reaches a person
AlertOps is unusual among connectors: the risky operations are not mainly the deletions.
Some tools page a real person. Creating an alert does not just write a record — it fires your escalation policy and notifies whoever is on call, potentially in the middle of the night. So does assigning an alert to someone, adding a message to an alert, adding recipients, and creating or updating an incident with the notify, email, SMS or Slack options set. StackJack marks all of these as destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and do not use these tools to test whether the connection works; use a read instead.
Other tools silence alerting. Closing or snoozing an alert, disabling an escalation policy or an inbound integration, opening a maintenance window, and marking a user out of office all reduce what will page you. Nothing is deleted, which is exactly why these are easy to underestimate: the failure mode is a monitoring blind spot, where a real incident stops reaching anybody. These carry the same marking.
Some updates replace the whole object. Several AlertOps update operations take the complete object rather than just the fields you are changing, so anything left out is lost — and what gets lost is often the recipients, the escalation tiers or the notification channels the alert depends on. These carry the same marking. When your AI assistant updates one of these, it should read the object first and send it back complete.
Plans and limits
Read tools are available on the Free tier. Everything that writes, pages, silences or deletes is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated AlertOps tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
AlertOps does not publish a rate limit, so there is no documented threshold to stay under. StackJack paces requests conservatively and backs off automatically if AlertOps throttles you, which usually turns a large report into a slower one. Pacing is not a guarantee: retries are bounded, so a wide enough report can still come back throttled or time out. Narrow the report, honour any retry delay AlertOps sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Troubleshooting
"AlertOps rejected the API key" — the key is no longer valid. Because AlertOps keys do not expire on their own, a key that used to work and now fails was almost certainly revoked in the console, or belonged to a user who has since been deactivated. Generate a new key as a user who will stay active, paste it into StackJack and run a Test Connection.
"AlertOps accepted the key but refused this operation" — almost always the key's reach rather than a fault. The key inherits its creator's access, and there is no way to widen it after the fact. Check the AlertOps role of whoever created it; administrative areas such as users, groups, escalation policies and integrations need an administrator. If you need those, re-create the key as an administrator and re-enter it.
"There are no alerts" — check the date window before believing it. With no explicit range, AlertOps returns only today's alerts. Ask again with a date range covering the period you actually care about.
An alert exists but nobody was paged — read the alert's escalation policy and the group it routes to, then check who was on call at the time and whether a maintenance window was open. All four are readable, and the answer is usually one of them rather than a delivery failure.
A monitoring tool's alerts stopped arriving — check whether its inbound integration is still enabled. A disabled integration looks exactly like a quiet week: nothing errors, and nothing arrives.
AlertOps tools
alertops_ · 217 tools · Free 89 · Pro 128
Alerts
Bridges
Incidents
Maintenance Windows
Postmortem Fields
Schedules
Escalation Policies
User Attributes
Users
Groups
Inbound Integrations
Outbound Integrations
Services
Topics
Workflows
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AteraConnect Autotask PSAStill need help? Ask the team