Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
Where your organisation id goes
This endpoint takes org_id as a query parameter. Leave it out and the call covers your whole tenancy subtree; send it to narrow the call to one organisation.
Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/alerts \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
docs/87. What the bell in the dashboard header reads. ⚖️ Owner ask 2026-08-26: *"maybe have an alerts bit somewhere like the other hosting platfroms do that has like an ! when something is open and then a list of them, like in other enterprise apps type of thing."* Unions seven sources: the customer's live **notices** (maintenance, DNS drift, a lost delegation, a paused posting run, a stranded card, a new PHP build, a certificate lapsing), an **expired or expiring stored card**, a **past-due subscription**, **domains** expiring without auto-renew or already lapsed, **suspended / restricted / quarantined** sites and orgs, any **supplier** we depend on reporting degraded or out, **our own** published open incidents and announced windows, and sites with **malware** on them. ⛔ The last two are each deliberately distinct from the one before it. `incidents` is not `upstream` — that reports a *supplier* being unwell, this reports **Zinn®**, and a customer whose site is slow wants the second far more. `security` is not the suspended/restricted/quarantined family — those are *enforcement outcomes* and the site is already off, where an infected site inside its grace window is still serving and the customer can still act. A site that is both appears in both, and that is deliberate: the second alert is the reason for the first. ⛔ No permission key — being told your card has expired is not a privilege. Gating it would mean a member whose role lacks `org.read` silently never learns their sites are suspended. ⛔⛔ **This shipped in the same change that stopped platform notices bannering on every page.** Landing that alone would have made maintenance *unreachable* from `/sites` rather than merely quieter — a false all-clear with nothing red (§2.44). A banner policy without a bell is not a smaller feature, it is a worse one. ⛔ The header calls this on every page, so it is seven bounded queries against indexed columns and reaches no vendor (§2.16). Every count that could be per-site is a grouped aggregate returning ONE row, so an estate with 40,000 suspended or infected sites produces one alert saying so rather than 40,000.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
org_id (query) | string | No | Narrow to one organization. Omitted, the caller's whole accessible subtree is considered. An id outside that scope narrows to nothing rather than 403-ing. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
data | Alert[] | Yes | — |
unread_action_count | integer | Yes | The badge. Unread `critical` + `action` items only. ⛔ Computed server-side rather than by counting `data` in the client — a second copy of "which severities count" is a copy tha… |
degraded | string[] | Yes | ⛔⛔ **Non-empty means the list above is INCOMPLETE.** Alert providers that raised, by name. A failing provider contributes nothing, and nothing is the reassuring value — without… |
Errors this endpoint can return
401 · 429