Skip to content

API quickstart

The automation API is at https://pingstack.io/api/v1. Use the actual hosted app origin shown in your account if it differs. The documentation host is not an API endpoint.

An Admin creates a manual automation grant in Settings > MCP. Start with read scopes, then add only the writes needed. Copy the token once into a private local environment:

  • PINGSTACK_TOKEN: your manual automation bearer token.
  • PINGSTACK_BASE_URL: the app origin, normally https://pingstack.io.

Do not paste tokens into source, screenshots, shell history or AI conversations.

Terminal window
curl --fail-with-body --silent --show-error \
--header "Authorization: Bearer $PINGSTACK_TOKEN" \
"$PINGSTACK_BASE_URL/api/v1/capabilities"

The grant needs account:read. Confirm the returned account is the intended one and inspect effective_min_interval_seconds, quotas and effective scopes.

Terminal window
curl --fail-with-body --silent --show-error \
--header "Authorization: Bearer $PINGSTACK_TOKEN" \
"$PINGSTACK_BASE_URL/api/v1/checks?limit=20"

This needs checks:read. Follow next_cursor when non-null. IDs from these responses are the IDs to pass to subsequent operations.

This writes to the bound account and consumes quota. Use a separately authorized test account and a public URL you control. The example domain is illustrative, not a promise of a particular health response.

Terminal window
curl --fail-with-body --silent --show-error \
--request POST \
--header "Authorization: Bearer $PINGSTACK_TOKEN" \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: website-test-001' \
--data '{
"check": {
"name": "Test public website",
"kind": "website",
"url": "https://example.com/health",
"interval_seconds": 3600,
"expected_status_code": 200,
"follow_redirects": false,
"failing_threshold": 1
}
}' \
"$PINGSTACK_BASE_URL/api/v1/checks"

This needs checks:create. Success returns HTTP 201 and a check resource; it does not prove the first probe succeeded. Keep the key unchanged when retrying the same creation, but use a new key for a different creation.

Use the signed-in UI to remove the test check when finished; the public API does not expose check deletion. Continue with authentication, conventions and the operation map.