API quickstart
The automation API is at https://pingstack.io/api/v1. Use the actual hosted
app origin shown in your account if it differs. The documentation host is
not an API endpoint.
An Admin creates a manual automation grant in Settings > MCP. Start with read scopes, then add only the writes needed. Copy the token once into a private local environment:
PINGSTACK_TOKEN: your manual automation bearer token.PINGSTACK_BASE_URL: the app origin, normallyhttps://pingstack.io.
Do not paste tokens into source, screenshots, shell history or AI conversations.
Read capabilities
Section titled “Read capabilities”curl --fail-with-body --silent --show-error \ --header "Authorization: Bearer $PINGSTACK_TOKEN" \ "$PINGSTACK_BASE_URL/api/v1/capabilities"The grant needs account:read. Confirm the returned account is the intended
one and inspect effective_min_interval_seconds, quotas and effective scopes.
List checks
Section titled “List checks”curl --fail-with-body --silent --show-error \ --header "Authorization: Bearer $PINGSTACK_TOKEN" \ "$PINGSTACK_BASE_URL/api/v1/checks?limit=20"This needs checks:read. Follow next_cursor when non-null. IDs from these
responses are the IDs to pass to subsequent operations.
Create a test website check
Section titled “Create a test website check”This writes to the bound account and consumes quota. Use a separately authorized test account and a public URL you control. The example domain is illustrative, not a promise of a particular health response.
curl --fail-with-body --silent --show-error \ --request POST \ --header "Authorization: Bearer $PINGSTACK_TOKEN" \ --header 'Content-Type: application/json' \ --header 'Idempotency-Key: website-test-001' \ --data '{ "check": { "name": "Test public website", "kind": "website", "url": "https://example.com/health", "interval_seconds": 3600, "expected_status_code": 200, "follow_redirects": false, "failing_threshold": 1 } }' \ "$PINGSTACK_BASE_URL/api/v1/checks"This needs checks:create. Success returns HTTP 201 and a check resource;
it does not prove the first probe succeeded. Keep the key unchanged when
retrying the same creation, but use a new key for a different creation.
Use the signed-in UI to remove the test check when finished; the public API does not expose check deletion. Continue with authentication, conventions and the operation map.