curl --request GET \
--url https://api.cloud.corbado.io/v1/observe/alertTransitions \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cloud.corbado.io/v1/observe/alertTransitions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cloud.corbado.io/v1/observe/alertTransitions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/alertTransitions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/alertTransitions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cloud.corbado.io/v1/observe/alertTransitions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/alertTransitions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"alertRuleID": "<string>",
"alertInstanceID": "<string>",
"toStatus": "normal",
"reason": "breach",
"notified": true,
"evaluatedMs": 123,
"createdMs": 123,
"labels": {},
"fromStatus": "normal",
"fromSeverity": "info",
"toSeverity": "info",
"value": 123,
"thresholdValue": 123,
"sampleSize": 123,
"message": "<string>"
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}List alert transitions
Lists the append-only status-change history of the project’s alerts, including the silent transitions that never produced a notification. Paginated; newest first. One flat collection with filters rather than a nested route, so the same endpoint answers both “what happened to this alert” (alertInstanceID) and “what has this rule been doing” (alertRuleID).
Required API key permission: observe:alerts:read.
curl --request GET \
--url https://api.cloud.corbado.io/v1/observe/alertTransitions \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cloud.corbado.io/v1/observe/alertTransitions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cloud.corbado.io/v1/observe/alertTransitions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/alertTransitions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/alertTransitions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cloud.corbado.io/v1/observe/alertTransitions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/alertTransitions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"alertRuleID": "<string>",
"alertInstanceID": "<string>",
"toStatus": "normal",
"reason": "breach",
"notified": true,
"evaluatedMs": 123,
"createdMs": 123,
"labels": {},
"fromStatus": "normal",
"fromSeverity": "info",
"toSeverity": "info",
"value": 123,
"thresholdValue": 123,
"sampleSize": 123,
"message": "<string>"
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}Authorizations
Use an Observe API key from the management console. The key selects the project and must grant the permission listed on the operation. Keep this key on your server.
Query Parameters
Filter to transitions of a single alert rule (format aru-<number>).
Filter to transitions of a single alert instance (format ain-<number>).
The page number to retrieve for paginated results.
1
The number of items to return per page. Useful for pagination.
20
Response
Paginated list of alert transitions. Paging metadata is returned in X-Corbado-Page, X-Corbado-TotalPages, and X-Corbado-TotalItems response headers.
1000Alert transition ID (format atr-<number>).
Alert rule ID (format aru-<number>).
Alert instance ID (format ain-<number>).
normal, pending, firing, no_data, error The machine code for why this transition happened. recovery marks a firing instance going quiet and only that, so a pending instance that stops breaching is breach_cleared rather than a recovery that never fired. A transition into no_data carries the instance's noDataReason here instead, so why there was no value survives from the computation into the history - which is why the last four values below overlap that vocabulary.
breach, breach_cleared, for_satisfied, escalation, de_escalation, recovery, no_data, data_returned, error, too_many_instances, rule_changed, division_by_zero, guard_not_met, dimension_not_available, series_not_available The label set of the alert instance this row is about, resolved from alertInstanceID so the history can name the alert the way the alert list does. Absent for the ungrouped alert of a rule with no groupBy, which has no labels.
Show child attributes
Show child attributes
normal, pending, firing, no_data, error The severity band before this transition, absent when none matched.
info, warning, critical The severity band after this transition, absent when none matched. A transition that changes only the level and not the status is still recorded, which is what lets the history show band flapping the inbox never saw.
info, warning, critical Was this page helpful?