Skip to content

incident.io ​

incident.io incident, alert, and escalation webhooks POST JSON to Exhale. Each tenant gets a unique HTTPS URL token. Exhale scrubs the payload, upserts a Pulse (source=incident_io), and runs triage when the event is a created incident, alert, or escalation.

This is companion ingest only (no OAuth, schedules, or note write-back).

See Sources for how incident.io fits with the other incoming webhooks.

On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....


Endpoint ​

After Connect in Connections → Sources → On-call & paging → incident.io:

Preferred (keeps tokens out of proxy access logs):

POST https://exhaleoncall.com/webhooks/incident-io

Send header X-Exhale-Webhook-Token: {token}.

Path form (also supported):

POST https://exhaleoncall.com/webhooks/incident-io/{token}
  • token — opaque URL segment; this token authenticates the delivery.
  • Response: 202 Accepted with pulse_id, status, created, and message.

Unknown tokens return 404. Disabled or expired-trial tenants return 403.

incident.io native webhooks include Svix webhook-signature headers. Exhale authenticates with the unique URL token like other companion sources and does not verify Svix HMAC.


Customer setup ​

  1. Sign in as admin → Connections → Sources → incident.io.
  2. Click Connect incident.io and copy the webhook URL.
  3. In incident.io, open Settings → Webhooks, add the Exhale URL, and subscribe to public incident created/updated/status events (plus alerts/escalations if you want those as Pulses).
  4. Send an incident created event that includes an incident id.
  5. Send test alert creates a synthetic pulse and marks the integration configured.

See incident.io's official guide: Introduction.

Rotate webhook token replaces the previous URL right away. Update incident.io after rotating.


Payload shape ​

FieldRequiredNotes
Resource idYesIncident, alert, or escalation id (source=incident_io)
event_typeNoFor example public_incident.incident_created_v2
name / titleNoPulse title
permalink / source_urlNoDeep link
severity.nameNoNormalized onto Pulse severity

Lifecycle mapping ​

incident.io eventPulse status
Incident, alert, or escalation createdReceived → triage
Incident still live or triage on updatePayload update only
Incident category closed, canceled, declined, merged, or learning; alert resolvedResolved
Escalation acknowledgedAcknowledged
Follow-ups, actions, schedules, catalog, and similarIgnored. 202 with no pulse when the id is unknown

Example ​

bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/incident-io/${TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"event_type":"public_incident.incident_created_v2","public_incident.incident_created_v2":{"id":"01FDAG4SAP5TYPT98WGR2N7W91","name":"Our database is sad"}}'

Exhale by Kolstrom Systems LLC