GET /api/v1/alerts
Retrieve a paginated list of triggered alerts for your workspace.Query Parameters
ISO 8601 timestamp. Return alerts triggered at or after this time.
ISO 8601 timestamp. Return alerts triggered at or before this time.
Filter by alert rule type. One of:
new_country, high_volume_destructive, ingestion_spike, repeated_action, off_hours.Number of alerts per page (max 100).
Pagination cursor from a previous response.
Response
Alert Rule Types
| Type | Description |
|---|---|
new_country | Actor performed an action from a previously unseen country |
high_volume_destructive | High volume of destructive actions in a short window |
ingestion_spike | Event ingestion volume exceeded normal baseline |
repeated_action | Same action repeated by the same actor rapidly |
off_hours | Action occurred outside configured business hours |
Examples
Alert Delivery
Alerts are also delivered in real time via:- Email — Sent to workspace members with admin or owner roles.
- Webhook — POSTed to your endpoint with an HMAC-SHA256 signature in the
X-Immutable-Signatureheader. See Webhook Signatures.
Plan Quotas
| Plan | Alert Rule Limit |
|---|---|
| Free | 2 |
| Starter | 10 |
| Pro | 50 |
| Enterprise | Unlimited |