curl --request POST \
--url 'https://api.flashcat.cloud/safari/automation/rule/create?app_key=' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"name": "Weekly on-call review",
"team_id": 123,
"enabled": true,
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"schedule_trigger_enabled": true,
"prompt": "Summarize last week's alert noise and escalation load.",
"http_post_trigger_enabled": true,
"oncall_incident_trigger_enabled": true,
"oncall_incident_channel_ids": [
456
],
"oncall_incident_severities": [
"Critical",
"Warning"
]
}
EOFimport requests
url = "https://api.flashcat.cloud/safari/automation/rule/create?app_key="
payload = {
"name": "Weekly on-call review",
"team_id": 123,
"enabled": True,
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"schedule_trigger_enabled": True,
"prompt": "Summarize last week's alert noise and escalation load.",
"http_post_trigger_enabled": True,
"oncall_incident_trigger_enabled": True,
"oncall_incident_channel_ids": [456],
"oncall_incident_severities": ["Critical", "Warning"]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Weekly on-call review',
team_id: 123,
enabled: true,
cron_expr: '0 9 * * 1',
timezone: 'Asia/Shanghai',
schedule_trigger_enabled: true,
prompt: 'Summarize last week\'s alert noise and escalation load.',
http_post_trigger_enabled: true,
oncall_incident_trigger_enabled: true,
oncall_incident_channel_ids: [456],
oncall_incident_severities: ['Critical', 'Warning']
})
};
fetch('https://api.flashcat.cloud/safari/automation/rule/create?app_key=', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.flashcat.cloud/safari/automation/rule/create?app_key=",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Weekly on-call review',
'team_id' => 123,
'enabled' => true,
'cron_expr' => '0 9 * * 1',
'timezone' => 'Asia/Shanghai',
'schedule_trigger_enabled' => true,
'prompt' => 'Summarize last week\'s alert noise and escalation load.',
'http_post_trigger_enabled' => true,
'oncall_incident_trigger_enabled' => true,
'oncall_incident_channel_ids' => [
456
],
'oncall_incident_severities' => [
'Critical',
'Warning'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.flashcat.cloud/safari/automation/rule/create?app_key="
payload := strings.NewReader("{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.flashcat.cloud/safari/automation/rule/create?app_key=")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.flashcat.cloud/safari/automation/rule/create?app_key=")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"data": {
"rule_id": "arule_7NnLzY2Qp8xS4kUaV3mR6b",
"account_id": 10023,
"team_id": 123,
"owner_id": 80011,
"name": "Weekly on-call review",
"enabled": true,
"run_scope": "team",
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"prompt": "Summarize last week's alert noise and escalation load.",
"environment_kind": "",
"environment_id": "",
"schedule_trigger_id": "atrig_6aKp3wT9mQ2xVc8bR1nY7z",
"schedule_trigger_enabled": true,
"http_post_trigger_id": "atrig_2bLq4xT8mP1sWd9cN3rF6y",
"http_post_trigger_url": "/safari/automation/triggers/atrig_2bLq4xT8mP1sWd9cN3rF6y/fire",
"http_post_trigger_enabled": true,
"can_edit": true,
"created_at": 1780367971228,
"updated_at": 1780367971228,
"http_post_token": "sat_yQ9p8V7n6M5k4J3h2G1f0E9d8C7b6A5z4Y3x2W1v0U",
"schedule_next_fire_at_ms": 1780630800000,
"oncall_incident_trigger_id": "atrig_9cVb2mN7qKs4dEa8T1rY5p",
"oncall_incident_trigger_enabled": true,
"oncall_incident_channel_ids": [
456
],
"oncall_incident_severities": [
"Critical",
"Warning"
]
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "InvalidParameter",
"message": "The specified parameter skill_id is not valid."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "Unauthorized",
"message": "You are unauthorized."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "AccessDenied",
"message": "Access Denied."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "RequestTooFrequently",
"message": "Request too frequently."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "InternalError",
"message": "We encountered an internal error, and it has been reported. Please try again later."
}
}Create Automation rule
Create an Automation rule with schedule, HTTP POST, and On-call incident triggers.
curl --request POST \
--url 'https://api.flashcat.cloud/safari/automation/rule/create?app_key=' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"name": "Weekly on-call review",
"team_id": 123,
"enabled": true,
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"schedule_trigger_enabled": true,
"prompt": "Summarize last week's alert noise and escalation load.",
"http_post_trigger_enabled": true,
"oncall_incident_trigger_enabled": true,
"oncall_incident_channel_ids": [
456
],
"oncall_incident_severities": [
"Critical",
"Warning"
]
}
EOFimport requests
url = "https://api.flashcat.cloud/safari/automation/rule/create?app_key="
payload = {
"name": "Weekly on-call review",
"team_id": 123,
"enabled": True,
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"schedule_trigger_enabled": True,
"prompt": "Summarize last week's alert noise and escalation load.",
"http_post_trigger_enabled": True,
"oncall_incident_trigger_enabled": True,
"oncall_incident_channel_ids": [456],
"oncall_incident_severities": ["Critical", "Warning"]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Weekly on-call review',
team_id: 123,
enabled: true,
cron_expr: '0 9 * * 1',
timezone: 'Asia/Shanghai',
schedule_trigger_enabled: true,
prompt: 'Summarize last week\'s alert noise and escalation load.',
http_post_trigger_enabled: true,
oncall_incident_trigger_enabled: true,
oncall_incident_channel_ids: [456],
oncall_incident_severities: ['Critical', 'Warning']
})
};
fetch('https://api.flashcat.cloud/safari/automation/rule/create?app_key=', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.flashcat.cloud/safari/automation/rule/create?app_key=",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Weekly on-call review',
'team_id' => 123,
'enabled' => true,
'cron_expr' => '0 9 * * 1',
'timezone' => 'Asia/Shanghai',
'schedule_trigger_enabled' => true,
'prompt' => 'Summarize last week\'s alert noise and escalation load.',
'http_post_trigger_enabled' => true,
'oncall_incident_trigger_enabled' => true,
'oncall_incident_channel_ids' => [
456
],
'oncall_incident_severities' => [
'Critical',
'Warning'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.flashcat.cloud/safari/automation/rule/create?app_key="
payload := strings.NewReader("{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.flashcat.cloud/safari/automation/rule/create?app_key=")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.flashcat.cloud/safari/automation/rule/create?app_key=")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Weekly on-call review\",\n \"team_id\": 123,\n \"enabled\": true,\n \"cron_expr\": \"0 9 * * 1\",\n \"timezone\": \"Asia/Shanghai\",\n \"schedule_trigger_enabled\": true,\n \"prompt\": \"Summarize last week's alert noise and escalation load.\",\n \"http_post_trigger_enabled\": true,\n \"oncall_incident_trigger_enabled\": true,\n \"oncall_incident_channel_ids\": [\n 456\n ],\n \"oncall_incident_severities\": [\n \"Critical\",\n \"Warning\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"data": {
"rule_id": "arule_7NnLzY2Qp8xS4kUaV3mR6b",
"account_id": 10023,
"team_id": 123,
"owner_id": 80011,
"name": "Weekly on-call review",
"enabled": true,
"run_scope": "team",
"cron_expr": "0 9 * * 1",
"timezone": "Asia/Shanghai",
"prompt": "Summarize last week's alert noise and escalation load.",
"environment_kind": "",
"environment_id": "",
"schedule_trigger_id": "atrig_6aKp3wT9mQ2xVc8bR1nY7z",
"schedule_trigger_enabled": true,
"http_post_trigger_id": "atrig_2bLq4xT8mP1sWd9cN3rF6y",
"http_post_trigger_url": "/safari/automation/triggers/atrig_2bLq4xT8mP1sWd9cN3rF6y/fire",
"http_post_trigger_enabled": true,
"can_edit": true,
"created_at": 1780367971228,
"updated_at": 1780367971228,
"http_post_token": "sat_yQ9p8V7n6M5k4J3h2G1f0E9d8C7b6A5z4Y3x2W1v0U",
"schedule_next_fire_at_ms": 1780630800000,
"oncall_incident_trigger_id": "atrig_9cVb2mN7qKs4dEa8T1rY5p",
"oncall_incident_trigger_enabled": true,
"oncall_incident_channel_ids": [
456
],
"oncall_incident_severities": [
"Critical",
"Warning"
]
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "InvalidParameter",
"message": "The specified parameter skill_id is not valid."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "Unauthorized",
"message": "You are unauthorized."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "AccessDenied",
"message": "Access Denied."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "RequestTooFrequently",
"message": "Request too frequently."
}
}{
"request_id": "01HK8XQE3Z7JM2NTFQ5YJ8P9R4",
"error": {
"code": "InternalError",
"message": "We encountered an internal error, and it has been reported. Please try again later."
}
}Restrictions
| Aspect | Value |
|---|---|
| Rate limits | 300 requests/minute; 20 requests/second per account |
| Permissions | Valid app_key; management operations require the caller to manage the target rule |
Usage
- A caller may create personal rules and rules for any team in the current account;
team_idis immutable after creation. cron_expris evaluated intimezoneif provided, else the caller’s member timezone, else the account timezone, else UTC.http_post_trigger_enabled=truecreates and enables an HTTP POST trigger; the response’shttp_post_tokenis a one-time value returned only on creation — save it immediately.oncall_incident_trigger_enabled=truerequires at least oneoncall_incident_channel_idsentry and oneoncall_incident_severitiesvalue; matching incidents run withtrigger_kind=oncall_incident.- Every call is recorded in the account audit log.
Authorizations
App key issued from the Flashduty console. Required on every public API call. Keep it secret — it grants the same access as the owning account.
Body
Create an Automation rule.
Rule name.
1 - 255Run cadence. Supports 4 fields (hour day month weekday, minute defaults to 0) and 5 fields (minute hour day month weekday). The minute must be one fixed integer; 6-field seconds are not supported. A cron that sets both day-of-month and day-of-week is rejected. The create API currently requires this field even for HTTP-POST-only rules; send a valid cron and set schedule_trigger_enabled=false.
"15 9 * * *"
Task prompt sent to the AI SRE agent on each run.
1Scope team ID. 0 or omitted means a personal rule; >0 means a team in the account. Immutable after creation.
x >= 0Whether the rule is enabled after creation. Omitted API value is false; Chat/CLI create sends true by default unless the user asks for disabled.
IANA timezone cron_expr is evaluated in, e.g. Asia/Shanghai. Must be a timezone name loadable by the server; an invalid value is rejected. Defaults to the caller's member timezone, then the account timezone, then UTC when omitted.
Whether the schedule trigger is enabled. Defaults to true when omitted; HTTP-POST-only rules should send false.
Runtime environment kind. Omit or send an empty value for automatic selection.
, cloud, byoc BYOC Runner ID. Used only when environment_kind=byoc.
Whether to create and enable an HTTP POST trigger. When enabled, the response includes a one-time token.
Whether the On-call incident trigger is enabled.
On-call integration IDs to watch. Creating or enabling this trigger requires at least one valid ID.
x >= 1Incident severities to watch. Supported values are Critical, Warning, and Info; creating or enabling this trigger requires at least one value.
Critical, Warning, Info Response
Success
Standard response envelope used by every Flashduty public API. On success data contains the endpoint-specific payload and error is absent. On failure error is present and data is absent. request_id is always present and is also mirrored in the Flashcat-Request-Id response header.
Unique ID for this request. Mirrored in the Flashcat-Request-Id header. Include it when reporting issues.
"01HK8XQE3Z7JM2NTFQ5YJ8P9R4"
Error payload inside the response envelope. Present only on non-2xx responses.
Show child attributes
Show child attributes
Automation rule.
Show child attributes
Show child attributes
Was this page helpful?