This is the Model Context Protocol (MCP) endpoint for Ion, the AI operator for Ionhour workspaces.
Ionhour is an uptime-monitoring and incident-management platform: it watches your services, opens incidents when something breaks, and routes alerts to your team. This MCP server lets an AI agent operate a workspace over natural language — create and inspect monitors, triage and resolve incidents, manage projects, dependencies, deployments, status pages, alert channels, and escalation policies. Not an assistant — an operator.
Ionhour has two DISTINCT kinds of monitor. They are separate entities with separate list/status/uptime tools — do not conflate them:
register_job (returns a token). Manage with the *_job tools (list_jobs, get_job_status, get_job_uptime, find_job_by_name, …).create_check. Manage with the *_check tools (list_checks, get_check_status, get_check_uptime, find_check_by_name, …). Use run_check_probe to test on demand.Status-page components can each link a check, a job, a project, or a dependency.
Transport: Streamable HTTP (POST to this URL).
Authentication: Bearer token — an API key starting with ionh_.
Every call is scoped to the API key's workspace; you never pass a workspace id.
Permission levels:
read_only — maps to the viewer role (view data only).read_write — view + mutate, capped at the admin role. Owner-gated actions are unreachable via any API key.register_check is a tombstoned alias: it returns an error and creates nothing. Use register_job for a heartbeat monitor or create_check for an outbound probe.*escalation_rule tools (list/create/update/delete_escalation_rule) are deprecated aliases, but they remain the MCP-callable path for escalation; get_escalation_policy reads the canonical policy/step shape.# Interactive setup wizard (recommended) — installs in Cursor, Claude, VS Code, Zed, etc. npx @ionhour/mcp-server setup # Or manual setup for Claude Code claude mcp add --transport http ionhour https://mcp.ionhour.com --header "Authorization: Bearer ionh_YOUR_KEY"
get_workspace — Workspace info: name, plan, creation date, the plan's resource limits, and current usage. maxMonitors is the shared checks+jobs pool; maxStatusPageComponentsPerPage and maxOutboundRegionsPerCheck are per-page/per-check caps. Use before bulk-creating resources so you know the cliff in advance.whoami — Returns info about the authenticated API key: workspace, user, permission levelget_workspace_summary — High-level workspace snapshot: project count, monitors grouped by status (Jobs = inbound heartbeats, Checks = outbound probes), and active incident count.get_workspace_reliability — Workspace-wide reliability: overall uptime (time-weighted, incident-based — each monitor weighted by how long it existed in the window), incident count, and MTTR over a time range.list_team_members — List workspace team members with their roles and join dates.list_invitations — List this workspace's invitations (email, role, status, and sent/expiry dates). Optionally filter by status. Invite tokens are never returned.send_invitation — Send workspace invitations to one or more email addresses. Only member or viewer roles can be assigned via chat.revoke_invitation — Revoke (cancel) a pending workspace invitation so its link can no longer be accepted.get_resource_audit_history — Audit history for a resource or the workspace — answers "why" questions (why paused, who deleted or changed something). Returns actor, time, and source.list_projects — List projects in the workspace. Use to resolve a project name to its id before creating checks/jobs or status-page components.create_project — Create a project (a container grouping related checks and jobs). Returns the new project id.update_project — Rename a project or change its environment. Only the fields you pass are changed.delete_project — Permanently delete a project. Its checks, jobs, and incidents are removed with it. This action cannot be undone.list_deleted_projects — List soft-deleted projects that can be restored with restore_project. Restore brings back only the project record — its checks and jobs must each be restored separately; incidents are not recoverable.restore_project — Restore a soft-deleted project (undo delete_project). Brings back only the project record — restore its checks and jobs separately with restore_check/restore_job. Incidents are not recoverable.Checks are OUTBOUND HTTP probes: Ionhour probes a URL you own on a schedule and alerts on failure. Create one with create_check. Status lifecycle: NEW → OK → LATE → DOWN → OK (also PAUSED). register_check is a deprecated tombstone — it creates nothing; use register_job (heartbeats) or create_check (probes).
register_check — register_check is deprecated and no longer creates anything. Use register_job for inbound heartbeat monitors (what this tool used to create) or create_check for outbound HTTP probes (Ionhour probes your URL).create_check — Create an outbound check (HTTP probe): Ionhour probes the given URL on a schedule and alerts when it is unreachable or returns an unexpected status. For inbound heartbeat monitors (your cron/worker pings Ionhour) use register_job instead — this is NOT the same as the deprecated register_check alias, which is a tombstone that creates nothing. Provide exactly one of projectId or dependencyId. Accepts intervalSeconds or a human-readable interval (interval takes priority).update_check — Update an outbound check's configuration (name, schedule, HTTP options, assertions, regions, severity). The monitored URL is immutable — to change it, delete and recreate the check. Accepts intervalSeconds or a human-readable interval (interval takes priority).run_check_probe — Run an on-demand probe for an outbound check ("test this check now"). Dispatches a one-off probe from every configured region. Results arrive asynchronously — read them shortly after via get_check_status. A failing probe counts toward the check's failure threshold. Provide either checkId or token.list_checks — List checks in workspace, optionally filtered by project.list_checks_by_status — List checks in the workspace filtered by status. Valid statuses: NEW, OK, LATE, DOWN, PAUSED, RESUMED.get_check_status — Get detailed check status with recent signals. Provide either checkId or token.get_check — Full STORED configuration of a check: schedule, grace period, alerting (downSeverity, lateSeverity, muteNotifications) and — for outbound probes — every persisted HTTP option, assertion (bodyContains/bodyNotContains), threshold, and region. Complements get_check_status (live state + signals). Use this to verify what create_check/update_check persisted. Provide either checkId or token.list_regions — List the probe regions available for outbound checks (id, display name, flag) plus the default region set. Use before choosing the regions array on create_check/update_check.find_check_by_name — Find checks by name — resolve a mentioned check name to its ID before other tools. Returns matches with status, schedule, lastPingAt, and lastSuccessSignalAt.get_check_uptime — Time-weighted, incident-based uptime percentage for a check over a time range, with daily buckets and lastSuccessSignalAt. Signal counts are supplementary volume data, not the uptime basis.get_check_response_time — Response time (drift) stats for a check: average, p50, p95, min, max, on-time rate. Use when the user asks about response time, latency, or drift.get_check_integration_guide — Integration guide for a check: ping URL and code examples. Use when the user asks how to integrate, set up, or send signals to a check.pause_check — Pause a check (stops monitoring). Provide either checkId or token.resume_check — Resume a paused check. Provide either checkId or token.delete_check — Soft-delete a check. Config and ping token are restorable via restore_check, but signals and incident history are permanently purged and NOT recovered.list_deleted_checks — List soft-deleted checks that can be restored with restore_check. Restore recovers only config and token — purged signals and incidents are not recoverable.restore_check — Restore a soft-deleted check (undo delete_check). Recovers only config and ping token, not purged signals or incidents. Refuses if the parent project is also deleted.Jobs are INBOUND heartbeat monitors: your cron/worker/scheduled script pings Ionhour and Ionhour alerts if a ping is late or missing. Create one with register_job; it returns a token used for the public ping URL. Same status lifecycle as checks.
register_job — Create a Job (INBOUND heartbeat monitor): the user's cron or worker pings Ionhour on a schedule. Returns a ping-URL token. Accepts intervalSeconds or a human-readable interval. For OUTBOUND HTTP probes (Checks, Ionhour probes the URL) use the check tools, not this.update_job — Update a Job (inbound heartbeat monitor): rename it, or change its schedule interval / grace period. Provide jobId plus only the fields to change. Accepts intervalSeconds or a human-readable interval string (interval takes priority).list_jobs — List Jobs (inbound heartbeat monitors) in the workspace, optionally filtered by project.get_job_status — Get detailed Job status with recent signals. Provide either jobId or token.find_job_by_name — Find Jobs by name — resolve a mentioned Job name to its ID before other tools. Returns matches with status and schedule.get_job_uptime — Time-weighted, incident-based uptime percentage for a Job over a time range, with daily buckets and lastSuccessSignalAt. Signal counts are supplementary volume data, not the uptime basis.get_job_integration_guide — Integration guide for a Job (inbound heartbeat monitor): ping URL and code examples. Use when the user asks how to send heartbeats or set up a Job.pause_job — Pause a Job (stops monitoring). Provide either jobId or token.resume_job — Resume a paused Job. Provide either jobId or token.delete_job — Soft-delete a Job (inbound heartbeat monitor). Config and token are restorable via restore_job, but signals and incident history are permanently purged and NOT recovered.list_deleted_jobs — List soft-deleted Jobs (inbound heartbeat monitors) that can be restored with restore_job. Restore recovers only config and token — purged signals and incidents are not recoverable.restore_job — Restore a soft-deleted Job (undo delete_job). Recovers only config and ping token, not purged signals or incidents. Refuses if the parent project or dependency is also deleted.Signals are the individual heartbeat pings a Job receives. Sent to the public ping URL with the Job token — no auth. See ionhour://help/ping-formats.
send_heartbeat — Send a heartbeat (success) signal to a check or job.send_failure_signal — Send a failure signal to a check or job (drives it DOWN and opens an incident).list_signals — List recent signals for a check or job.Incidents are auto-created when a monitor (check or job) goes LATE/DOWN. Lifecycle: ACTIVE → ACKNOWLEDGED → RESOLVED.
list_incidents — List incidents in the workspace, optionally filtered by state.search_incidents — Search incidents in the workspace. Can filter by state (ACTIVE/RESOLVED), severity, or search by title text.get_incident — Get details for a specific incident.get_incident_timeline — Incident history for a monitor (check or job), including resolved incidents with timing and acknowledgment details. Pass exactly one of checkId or jobId. MCP display name for the incident timeline. Accepts checkId OR jobId (exactly one).diagnose_incident — Diagnose the likely root cause of an incident from its history and similar past incidents. Accepts an incidentId, or a checkName for that check's most recent incident.acknowledge_incident — Acknowledge an active incident.resolve_incident — Manually resolve an incident.create_incident — Create a manual incident.add_incident_note — Add a note to an incident.update_incident — Edit an incident's title and/or summary. The summary is rich text (HTML) and is sanitized server-side before it is saved. Only the fields you provide change.set_incident_severity — Change an incident's severity. Valid values: P1 (critical), P2 (high), P3 (moderate), P4 (low).reopen_incident — Reopen a resolved incident, moving it back to active. Only a resolved incident can be reopened.publish_incident_to_status_page — Publish an incident to a status page as a public, incident-linked announcement. Idempotent: if this incident is already published to that page, the existing announcement is returned instead of creating a duplicate. Prefer this over create_announcement whenever an incident exists — it links the announcement to the incident so status updates stay in sync.create_incident_update — Post a stakeholder update to an incident. This is an internal record and does NOT publish to a status page — use publish_incident_update for that. status is one of investigating, identified, monitoring, resolved.publish_incident_update — Publish an existing stakeholder update to the workspace's status page. The update must belong to the given incident. Idempotent: an update already published returns its current state without re-publishing.list_dependencies — List external dependencies in the workspace, optionally filtered by category. dependentChecksCount = project checks that DEPEND on the dependency (attached health monitors are listed by get_dependency).get_dependency — Get details of a specific dependency. Returns dependencyChecks (health monitors ATTACHED to this dependency, counted by attachedChecksCount) and serviceChecks (project checks that DEPEND on it, counted by dependentChecksCount).create_dependency — Register an external dependency.update_dependency_status — Update a dependency's operational status. Setting NEW/OK/DOWN PINS the status (statusSource=MANUAL): automatic rollup from attached monitors will NOT overwrite it. Pass "AUTO" to release the pin and resume automatic rollup (recomputed immediately).delete_dependency — Soft-delete an external dependency (linked checks stop tracking it). Restorable via restore_dependency, but its health monitors and incidents removed on delete are NOT recovered.list_deleted_dependencies — List soft-deleted dependencies that can be restored with restore_dependency. Restore brings back only the dependency record — its health monitors and incidents are not recovered.restore_dependency — Restore a soft-deleted dependency (undo delete_dependency). Brings back only the dependency record — its health monitors and incidents are not recovered.create_deployment — Start a deployment window. Can auto-pause associated checks.end_deployment — End an active deployment. Resumes any auto-paused checks.list_deployments — List deployment windows for a project, optionally filtered by status.list_status_pages — List status pages in the workspace: name, slug, visibility, enabled state, custom domain + status, and a component preview. componentCount is the FULL count; `components` previews at most 10 rows (componentsTruncated:true marks a cut list — use list_status_page_components for all rows).create_status_page — Create a status page. The slug forms the public URL (returned as `url`). Starts empty — add rows with add_status_page_component.create_announcement — Post a status update announcement to a status page.delete_announcement — Permanently delete an announcement from its status page. This action cannot be undone.list_status_page_components — List a status page's components (rows) in display order. Each links to one check, job, project, or dependency (id + name). Call first to get component ids before reorder/update/delete.get_status_page_preview — The RENDERED state of a status page, exactly as the public page shows it: overall status, every row with its live status and uptimePct (null = no uptime bar renders, e.g. dependency-linked rows), active incidents, announcements, and scheduled maintenances — plus the real public URL. Use after composing a page to verify it without a browser. Works for disabled/private pages too (owner view).add_status_page_component — Add one row to a status page, linked to EXACTLY ONE of checkId (outbound probe), jobId (inbound heartbeat), projectId, or dependencyId.update_status_page_component — Edit a status page component in place (name, description, groupName, enabled, showUptimeBar, position, projectDisplayMode). Only fields you pass change. Does not re-point the row's linked resource.reorder_status_page_components — Set a status page's component display order. Pass the FULL ordered list of component ids (position = array index); omitted ids collide.delete_status_page_component — Permanently remove one row from a status page (componentId must belong to statusPageId). The linked check/job/project/dependency is untouched. To hide instead of deleting, use update with enabled:false.update_status_page — Update a status page's settings (not its rows). Only fields you pass change: name, slug (changes URL), visibility, enabled (enabled:false takes the WHOLE page offline), branding, and history toggles.delete_status_page — Delete a status page along with its components and announcements. Soft-delete: the page goes offline and any custom domain is deregistered from Cloudflare. Restorable with restore_status_page (the custom domain is NOT re-registered on restore).list_deleted_status_pages — List soft-deleted status pages that can be restored with restore_status_page. Restoring brings back the page with its components and announcements, but does NOT re-register a custom domain.restore_status_page — Restore a soft-deleted status page (undo delete_status_page). Its components and announcements come back with it. A custom domain is NOT re-registered — its stored value is cleared on restore; re-add it in the status page settings to reconnect.list_alert_channels — List alert channels in the workspace, optionally filtered by type (email, slack, webhook).get_alert_routing — How alerts actually route to channels: the workspace routing policies (rules match on check STATUS plus optional project/check scopes — severity is NOT a match dimension), each rule's actions, the no-match fallback (ALL enabled channels), and the channel inventory. Use this to verify where a DOWN alert will land before relying on it.create_alert_channel — Create an alert channel (email or webhook).update_alert_channel — Update an alert channel's name or enabled state.delete_alert_channel — Soft-delete an alert channel — escalation steps using it stop firing. Restorable via restore_alert_channel with recipients intact.list_deleted_alert_channels — List soft-deleted alert channels that can be restored with restore_alert_channel. A restored channel keeps its recipients and resumes dispatching.restore_alert_channel — Restore a soft-deleted alert channel (undo delete_alert_channel). Recipients return intact, dispatching resumes, and escalation steps using it work again.The four *escalation_rule tools (list/create/update/delete_escalation_rule) are deprecated aliases, but they remain the MCP-callable way to manage escalation — use them, not the registry-side step tools (which are not exposed over MCP). create_escalation_rule adds a single-channel step; update/delete require projectId. get_escalation_policy reads the canonical policy/step shape.
list_escalation_rules — Get a project's escalation policy: ordered steps with delay minutes and alert-channel targets. Deprecated flattened-rules view — prefer get_escalation_policy to read the canonical policy/step model.create_escalation_rule — Add a step to a project's escalation policy (creates the policy if none exists). A step has a delay and alert-channel targets. Deprecated single-channel escalation shape — still the MCP-callable path to add an escalation step; prefer get_escalation_policy to read the canonical policy/step model.update_escalation_rule — Update a step in a project's escalation policy (delay or position). Deprecated alias — still the MCP-callable path to update an escalation step; requires projectId, and the old "ruleId" is the step id.delete_escalation_rule — Remove a step from a project's escalation policy. Removing the last step deletes the policy. Deprecated alias — still the MCP-callable path to remove an escalation step; requires projectId, and the old "ruleId" is the step id.get_escalation_policy — Get a project's escalation policy: ordered steps with delay minutes and alert-channel targets.setup_monitoring — Guided setup for a new service; branches on monitor type (heartbeat via register_job vs outbound probe via create_check).diagnose_incident — Step-by-step investigation; branches on the incident's monitor type (get_check_status for checks, get_job_status for jobs).deployment_checklist — Pre/post-deploy verification and deployment-window management (auto-pause/resume).weekly_reliability_report — Weekly summary iterating BOTH checks (get_check_uptime) and jobs (get_job_uptime).triage_all_incidents — List and triage all active incidents.ionhour://tools/catalog — Machine-readable catalog of every MCP tool grouped by domain, with descriptions.ionhour://guides/workflows — Common end-to-end workflow patterns (setup, incident response, safe deploy, weekly review).ionhour://help/ping-formats — How to send Job heartbeats: curl/SDK/cron examples for the public ping URL.ionhour://enums — All Ionhour enums: monitor statuses, incident states, severities, etc.ionhour://checks/schema — Check creation schema: valid fields, intervals, and constraints.find_check_by_name / find_job_by_name before status/update/delete calls.restore_* tools (e.g. restore_project, restore_check, restore_job) bring records back.