incident.io for AI agents

incident.io is an incident management and response platform for declaring, tracking, and resolving operational incidents. Engineering teams pull it into internal tools and scripts rather than building the same capability themselves. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsAPI keyMCP + RESTincident.io
AUDIT LOG · INCIDENT.IOPOLICY: acme-support
09:41:07 · claude · u_8f2read
incident_io.list_users_v2
List Users V2✓ allowed · 212ms
09:41:08 · claude · u_8f2read
incident_io.get_users_v2
Get User V2✓ allowed · 164ms
09:41:09 · claude · u_8f2write
incident_io.create_incidents_v2
Create Incident V2✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
incident_io.delete_severity
Delete Severity✕ blocked · policy: deny
EVERY INCIDENT.IO CALL, ON THE RECORD
01 · USE CASES

What agents do in incident.io.

01

Declare a new incident

Create a new incident record with a severity and summary when an outage is reported.

02

Update an incident's status

Update an active incident's status as the team makes progress toward resolution.

03

Delete a severity level with confirmation

Delete a custom severity level only after a team lead confirms it is no longer used.

02 · ACTIONS

86 incident.io actions, graded by risk.

Every incident.io action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

43

Look things up. Allowed by default.

  • incident_io.get_users_v2
    Get User V2
  • incident_io.list_users_v2
    List Users V2
  • incident_io.list_alerts_v2
    List Alerts V2
  • incident_io.get_incident_v2
    Get Incident by ID (V2)
  • incident_io.list_actions_v1
    List Actions V1
  • incident_io.list_actions_v2
    List Actions V2
  • incident_io.get_schedules_v2
    Show Schedules V2
  • incident_io.get_workflows_v2
    Get Workflow V2
  • incident_io.list_identity_v1
    Get API Key Identity
  • incident_io.get_incident_type
    Get Incident Type
  • incident_io.get_severities_v1
    Get Severity V1
  • incident_io.list_incidents_v2
    List Incidents V2
  • incident_io.list_schedules_v2
    List Schedules V2
  • incident_io.list_workflows_v2
    List Workflows V2
  • incident_io.get_escalations_v2
    Show Escalations V2
  • incident_io.list_follow_ups_v2
    List Follow-ups V2
+ 27 MORE

write

29

Create and change things. Allow, or ask the user first.

  • incident_io.create_incidents_v2
    Create Incident V2
  • incident_io.update_schedules_v2
    Update Schedule V2
  • incident_io.update_workflows_v2
    Update Workflow V2
  • incident_io.create_severities_v1
    Create Severity
  • incident_io.update_severities_v1
    Update Severity
  • incident_io.create_escalations_v2
    Create Escalation V2
  • incident_io.create_alert_routes_v2
    Create Alert Route V2
  • incident_io.create_incident_status
    Create Incident Status
  • incident_io.update_incident_status
    Update Incident Status
  • incident_io.create_alert_sources_v2
    Create Alert Source V2
  • incident_io.create_catalog_types_v3
    Create Catalog Type V3
  • incident_io.create_custom_fields_v2
    Create Custom Field V2
  • incident_io.update_alert_sources_v2
    Update Alert Source V2
  • incident_io.update_catalog_types_v3
    Update Catalog Type V3
  • incident_io.update_custom_fields_v1
    Update Custom Fields V1
  • incident_io.update_custom_fields_v2
    Update Custom Field V2
+ 13 MORE

destructive

14

Delete, cancel or archive. Ask first, or deny outright.

  • incident_io.delete_severity
    Delete Severity
  • incident_io.delete_custom_field
    Delete Custom Field
  • incident_io.delete_schedules_v2
    Delete Schedule V2
  • incident_io.delete_workflows_v2
    Delete Workflow V2
  • incident_io.delete_alert_routes_v2
    Delete Alert Route V2
  • incident_io.delete_alert_sources_v2
    Delete Alert Source V2
  • incident_io.delete_catalog_types_v3
    Delete Catalog Type V3
  • incident_io.delete_custom_fields_v2
    Delete Custom Field V2
  • incident_io.delete_incident_roles_v2
    Delete Incident Role V2
  • incident_io.delete_catalog_entries_v3
    Delete Catalog Entry V3
  • incident_io.delete_incident_status_v1
    Delete Incident Status V1
  • incident_io.delete_alert_attributes_v2
    Delete Alert Attribute V2
  • incident_io.delete_escalation_paths_v2
    Delete Escalation Path V2
  • incident_io.delete_custom_field_options_v1
    Delete Custom Field Option
03 · HOW IT WORKS

incident.io in three steps.

  1. 01Your users connect incident.ioThey add their incident.io api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Incident V2” can wait for the user, and “delete Severity” can be denied outright.
  3. 03Any agent can actYour agent calls incident.io through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('incident_io', {
  read: 'allow',
  write: 'ask',        // create_incidents_v2
  destructive: 'deny',  // delete_severity
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How incident.io connects.

Users add their incident.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same incident.io connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use incident.io from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

incident.io and Arc0, answered.

Q01

Can I use incident.io with Claude, ChatGPT or Cursor?

Yes. Connect incident.io to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the incident.io actions you allow.

Q02

How do users connect incident.io?

Users add their incident.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which incident.io actions can my agent take?

86 in total: 43 read, 29 write and 14 destructive, such as “create Incident V2”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in incident.io?

Yes. Actions like “delete Severity” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call incident.io too?

Yes. The same incident.io connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug incident.io into your agent.

Your users connect incident.io once, under your brand. Your agent gets 86 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan