Skip to content

Preview integration resources as incidents

GET
/v1/integrations/{name}/incidents/import
name
required
string

Integration vendor short name (e.g. ‘jira’, ‘wiz’, ‘bugcrowd’)

Preview incident integration resources before importing

Paginated list envelope: { "results": [...], "pagination": {...} }.

object
pagination
required

Pagination metadata for external-integration responses. The continuation is a single opaque next_page_token — a base64(JSON) blob the producer round-trips through [crate::views::cursor] — so the page/offset/cursor schemes of the underlying APIs are invisible to the SDK/frontend, which only read total_items for the “X of Y” display.

object
next_page_token

Opaque continuation token. Absent means there are no further pages — the sole end-of-collection signal.

string | null
total_items

Total matching items, when the upstream API reports it. Informational only — never used for loop control. Absent when the API reports no total (e.g. HackerOne, GitHub Dependabot).

integer | null format: int64
results
required

The items on this page.

Array<object>

Relationship, core incident information

object
assigned_to
One of:
null
contained_date
string | null format: date-time
created_date
required
string format: date-time
description
required
string
detected_date
required
string format: date-time
id
required
string
Example
INC-00001
occurred_date
string | null format: date-time
opened_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
parent_id

When set, this incident is linked under the named parent incident.

string | null
Example
INC-00001
responded_date
string | null format: date-time
severity
One of:
null
severity_reasoning
string | null
source
required

Where the incident was reported from (e.g. “Employee Reported”). Always present.

string
status
required

The status of an incident

string
Allowed values: New In Progress Review Closed
title
required
string
updated_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
updated_date
required
string format: date-time