Alerts

Alerts raised by the LeadConduit alert detection engine: recipient failure and skip spikes, source rejection spikes, flows that stopped posting, category rejections (duplicates, TrustedForm issues), and new sources. The engine evaluates each account's activity against its own baselines; alerts resolve automatically when the condition clears.

Alert

An active alert raised by the LeadConduit alert detection engine for this account. Each alert has a stable key for its underlying condition: while the condition persists the same key is returned on every read (with severity, message, and data refreshed), and first_seen_at marks when the condition was first detected.

key
string

Stable identifier for the alert condition (type:account:entity, zero-run alerts also carry the run start date)

type
string

Alert type

Enum: "recipient-failure" "recipient-skip" "source-rejects" "no-leads" "new-source" "duplicate-leads" "invalid-email" "invalid-phone" "missing-tf-cert" "tf-failures"
kind
string or null

Sub-classification of the alert, when the type has one (e.g. failure vs error for source rejections)

severity
string

Alert severity

Enum: "critical" "serious" "warning" "info"
message
string

One-line headline describing the condition

detail
string

Diagnostic second line with the supporting numbers

null or ID (string)

ID of the flow the alert concerns; null for alerts that are not flow-scoped (e.g. new-source)

flow_name
string or null

Name of the flow the alert concerns, when flow-scoped

entity_id
string or null

ID of the source or recipient entity the alert concerns; null for flow-level alerts (e.g. no-leads)

entity_name
string or null

Name of the source or recipient entity the alert concerns

recipient_id
string or null

Recipient entity ID for category alerts backed by an integration step (deep-link support)

outcome
string or null

The step outcome counted by a category alert (e.g. skip for missing TrustedForm certificates)

time_zone
string

The account's IANA time zone, for rendering timestamps in the account's local day

first_seen_at
string <date-time>

When the alert condition was first detected (stable while the condition persists)

last_seen_at
string <date-time>

When the alert condition was last confirmed by the detector

object

Type-specific supporting metrics (rates, baselines, counts). Aggregate numbers only, never lead data.

{
  • "key": "recipient-failure:42:5e8b6f...|5f1c...|leadconduit-custom.outbound.form",
  • "type": "recipient-failure",
  • "kind": "failure",
  • "severity": "critical",
  • "message": "100% of submissions to CRM One in Web Leads are failing",
  • "detail": "60 of 60 submissions today · typical last 7 days: 2% · most common reason: Timeout",
  • "flow_id": { },
  • "flow_name": "Web Leads",
  • "entity_id": "5e8b6f91f0d12766e2bfee51",
  • "entity_name": "CRM One",
  • "recipient_id": "string",
  • "outcome": "skip",
  • "time_zone": "America/Chicago",
  • "first_seen_at": "2019-08-24T14:15:22Z",
  • "last_seen_at": "2019-08-24T14:15:22Z",
  • "data": {
    • "rate": 1,
    • "baseline_rate": 0.02,
    • "total": 60
    }
}

Alert Activity Entry

One entry in an alert's activity timeline: a change the detector recorded, a configuration change to the flow, a human action such as an acknowledgement or a comment, or a verification step.

at
string <date-time>

When the entry happened

kind
string

What happened

Enum: "created" "severity_change" "relabel" "message_change" "resolved" "config_change" "verification_started" "verification_check" "verification_failed" "ack" "comment" "viewed" "investigate_clicked"
object

Who produced the entry

visibility
string

customer entries are shown to the account; internal entries are only returned to ActiveProspect staff

Enum: "customer" "internal"
source
string

Where the entry came in from

Enum: "ui" "slack" "api" "collector"
object or null

Kind-specific payload (e.g. from and to for a severity change, text for a comment)

{
  • "at": "2019-08-24T14:15:22Z",
  • "kind": "severity_change",
  • "actor": {
    • "type": "system",
    • "id": "string",
    • "name": "string"
    },
  • "visibility": "customer",
  • "source": "ui",
  • "data": {
    • "from": "warning",
    • "to": "critical"
    }
}

Alerts

The account's active alerts, sorted by severity and then by today's affected volume.

Array
key
string

Stable identifier for the alert condition (type:account:entity, zero-run alerts also carry the run start date)

type
string

Alert type

Enum: "recipient-failure" "recipient-skip" "source-rejects" "no-leads" "new-source" "duplicate-leads" "invalid-email" "invalid-phone" "missing-tf-cert" "tf-failures"
kind
string or null

Sub-classification of the alert, when the type has one (e.g. failure vs error for source rejections)

severity
string

Alert severity

Enum: "critical" "serious" "warning" "info"
message
string

One-line headline describing the condition

detail
string

Diagnostic second line with the supporting numbers

null or ID (string)

ID of the flow the alert concerns; null for alerts that are not flow-scoped (e.g. new-source)

flow_name
string or null

Name of the flow the alert concerns, when flow-scoped

entity_id
string or null

ID of the source or recipient entity the alert concerns; null for flow-level alerts (e.g. no-leads)

entity_name
string or null

Name of the source or recipient entity the alert concerns

recipient_id
string or null

Recipient entity ID for category alerts backed by an integration step (deep-link support)

outcome
string or null

The step outcome counted by a category alert (e.g. skip for missing TrustedForm certificates)

time_zone
string

The account's IANA time zone, for rendering timestamps in the account's local day

first_seen_at
string <date-time>

When the alert condition was first detected (stable while the condition persists)

last_seen_at
string <date-time>

When the alert condition was last confirmed by the detector

object

Type-specific supporting metrics (rates, baselines, counts). Aggregate numbers only, never lead data.

[
  • {
    • "key": "recipient-failure:42:5e8b6f...|5f1c...|leadconduit-custom.outbound.form",
    • "type": "recipient-failure",
    • "kind": "failure",
    • "severity": "critical",
    • "message": "100% of submissions to CRM One in Web Leads are failing",
    • "detail": "60 of 60 submissions today · typical last 7 days: 2% · most common reason: Timeout",
    • "flow_id": { },
    • "flow_name": "Web Leads",
    • "entity_id": "5e8b6f91f0d12766e2bfee51",
    • "entity_name": "CRM One",
    • "recipient_id": "string",
    • "outcome": "skip",
    • "time_zone": "America/Chicago",
    • "first_seen_at": "2019-08-24T14:15:22Z",
    • "last_seen_at": "2019-08-24T14:15:22Z",
    • "data": {
      • "rate": 1,
      • "baseline_rate": 0.02,
      • "total": 60
      }
    }
]

Alert Settings

The alert settings that apply to the account.

enabled
boolean

False when alerting is turned off for the whole account

object

Effective settings keyed by alert type (for example recipient-failure, source-rejects, no-leads). The keys inside each type depend on its detector; enabled and level or severity are common to most.

{
  • "enabled": true,
  • "types": {
    • "property1": {
      • "enabled": true,
      • "send_email": true,
      • "messages": {
        • "property1": "string",
        • "property2": "string"
        },
      • "details": {
        • "property1": "string",
        • "property2": "string"
        }
      },
    • "property2": {
      • "enabled": true,
      • "send_email": true,
      • "messages": {
        • "property1": "string",
        • "property2": "string"
        },
      • "details": {
        • "property1": "string",
        • "property2": "string"
        }
      }
    }
}

Alert Type Settings

Effective configuration of one alert type for the account.

enabled
boolean

False when this alert type is not evaluated for the account

send_email
boolean

Whether critical and serious alerts of this type are emailed

object

Message templates keyed by variant

object

Detail line templates keyed by variant

property name*
additional property
any
{
  • "enabled": true,
  • "send_email": true,
  • "messages": {
    • "property1": "string",
    • "property2": "string"
    },
  • "details": {
    • "property1": "string",
    • "property2": "string"
    }
}

List active alerts

Returns the account's currently active alerts, sorted by severity (critical first) and then by today's affected volume. Alerts are generated by the LeadConduit alert detection engine (recipient failure or skip spikes, source rejection spikes, flows that stopped posting, category rejections such as duplicates or TrustedForm failures, and new sources). Only active alerts are returned; resolved alert history is not available through this endpoint. Responses carry entity IDs, names, and aggregate counts only — never lead data.

SecurityAPIKey
Responses
200

OK

401

Authentication failed

get/alerts
Request samples
Response samples
application/json
[
  • {
    • "key": "recipient-failure:42:5e8b6f...|5f1c...|leadconduit-custom.outbound.form",
    • "type": "recipient-failure",
    • "kind": "failure",
    • "severity": "critical",
    • "message": "100% of submissions to CRM One in Web Leads are failing",
    • "detail": "60 of 60 submissions today · typical last 7 days: 2% · most common reason: Timeout",
    • "flow_id": { },
    • "flow_name": "Web Leads",
    • "entity_id": "5e8b6f91f0d12766e2bfee51",
    • "entity_name": "CRM One",
    • "recipient_id": "string",
    • "outcome": "skip",
    • "time_zone": "America/Chicago",
    • "first_seen_at": "2019-08-24T14:15:22Z",
    • "last_seen_at": "2019-08-24T14:15:22Z",
    • "data": {
      • "rate": 1,
      • "baseline_rate": 0.02,
      • "total": 60
      }
    }
]

Get the account's alert settings

Returns the alert settings that apply to the account: whether alerting is enabled for the account and, per alert type, the effective configuration the detection engine evaluates (thresholds, severity tables, message templates). Effective settings combine the LeadConduit defaults with any adjustments ActiveProspect made for all accounts or for this account. Read only; contact support to change them.

SecurityAPIKey
Responses
200

OK

401

Authentication failed

get/alerts/settings
Request samples
Response samples
application/json
{
  • "enabled": true,
  • "types": {
    • "property1": {
      • "enabled": true,
      • "send_email": true,
      • "messages": {
        • "property1": "string",
        • "property2": "string"
        },
      • "details": {
        • "property1": "string",
        • "property2": "string"
        }
      },
    • "property2": {
      • "enabled": true,
      • "send_email": true,
      • "messages": {
        • "property1": "string",
        • "property2": "string"
        },
      • "details": {
        • "property1": "string",
        • "property2": "string"
        }
      }
    }
}

Get an alert's activity timeline

Returns one alert's timeline, newest first: when it was raised, severity and message changes, configuration changes to the flow, acknowledgements, comments, and how it resolved. Resolved alerts keep serving their timeline. Pages are cursored: pass the previous page's next_before (an opaque position cursor) as before to read older entries; a bare ISO 8601 date is also accepted as before to read everything older than that instant. A page shorter than limit is the end of the timeline and carries a null next_before. An unknown key and a key that belongs to another account both return 404.

SecurityAPIKey
Request
path Parameters
key
required
string

The alert's key, as returned by GET /alerts (URL-encoded)

query Parameters
before
string

The previous page's next_before cursor, or an ISO 8601 date/timestamp to read only entries strictly older than it

limit
integer [ 1 .. 200 ]
Default: 50

Maximum number of entries to return

kind
string

Only entries of this kind

Enum: "created" "severity_change" "relabel" "message_change" "resolved" "config_change" "verification_started" "verification_check" "verification_failed" "ack" "comment" "viewed" "investigate_clicked"
Responses
200

OK

400

Invalid before, limit or kind

401

Authentication failed

404

No alert with that key for this account

get/alerts/{key}/activity
Request samples
Response samples
application/json
{
  • "entries": [
    • {
      • "at": "2019-08-24T14:15:22Z",
      • "kind": "severity_change",
      • "actor": {
        • "type": "system",
        • "id": "string",
        • "name": "string"
        },
      • "visibility": "customer",
      • "source": "ui",
      • "data": {
        • "from": "warning",
        • "to": "critical"
        }
      }
    ],
  • "next_before": "string"
}