API
Warden exposes a REST API for managing monitors, incidents, status pages, and more. All endpoints live under /api/.
Swagger
Section titled “Swagger”Interactive API docs are available at:
http://localhost:9090/api/docs/index.htmlAuthentication
Section titled “Authentication”Most endpoints require a valid session or API key.
Session
Section titled “Session”Login via POST /api/auth/login with username and password. The server sets a session cookie.
API Keys
Section titled “API Keys”Create API keys from the dashboard under Settings > API Keys. Pass the key as a bearer token:
curl -H "Authorization: Bearer sk_live_..." http://localhost:9090/api/monitorsKeys carry a role. Use viewer for anything that only needs to read.
Monitors
Section titled “Monitors”A monitor carries a type alongside its target, which decides what check runs against it — http (default), tcp, ping, dns or docker. The target format differs per type, and so do the options in requestConfig. See Monitor Types.
curl -X POST http://localhost:9090/api/monitors \ -H "Authorization: Bearer sk_live_..." -H 'Content-Type: application/json' \ -d '{"name":"Postgres","type":"tcp","url":"db.internal:5432","groupId":"g-default","interval":60}'Omitting type on a PUT keeps the type the monitor already has.
Moving a monitor between groups
Section titled “Moving a monitor between groups”Grouping is not part of the PUT. Like pausing and muting, it has its own endpoint, so a regroup is one request that cannot half-apply alongside an edit:
curl -X POST http://localhost:9090/api/monitors/m-postgres-a1b2c3/group \ -H "Authorization: Bearer sk_live_..." -H 'Content-Type: application/json' \ -d '{"groupId":"g-production"}'The monitor keeps its id, so its checks, uptime, outages and incidents move with it. Sending the group it is already in is a no-op rather than an error. A group that does not exist returns 404. Note that a status page scoped to the old group stops showing the monitor the moment it leaves.
Warden also speaks the Model Context Protocol at /api/mcp, so an assistant can answer questions about your monitoring. See MCP Server.
Public Endpoints
Section titled “Public Endpoints”These do not require authentication:
| Method | Path | Description |
|---|---|---|
POST | /api/auth/login | Login |
POST | /api/setup | Initial admin setup |
GET | /api/s/{slug} | Public status page data |
Automation
Section titled “Automation”A helper script is included to bulk-create monitors:
python3 tools/create_stack.py --key "sk_live_..." --group "Google" --urls https://google.com