Authentication
All requests require a Bearer token. Recommended: a personal token from User menu > API Tokens. Personal tokens attribute all actions to your user identity. For shared service integrations or scripts that run on behalf of the organization, use an organization token from Admin > API Tokens instead. Include the token in all requests:Trigger an Investigation
https://app0.resolve.ai
Requires a personal token (User menu > API Tokens). Organization tokens cannot trigger investigations (401), because every investigation is attributed to a real user.
Body: exactly one of the following.
Example (free-form text):
202 Accepted immediately; the investigation continues in the background. Poll Get Investigation Details until isComplete is true, then read the markdown report from the reports array. canvasUrl is the link to paste into the ServiceNow work notes.
To find the alert id for an incident, if the alert carries the INC number as a label, look it up first with List Investigations, then trigger by id:
List Investigations
https://app0.resolve.ai
Query Parameters:
Multiple label filters use AND logic: all specified labels must match.
Example:
Get Investigation Details
Resolution timing: mttrMetrics
How long the investigation took to reach its milestones. null while the investigation is still running.
Each milestone carries
at (timestamp) and elapsedSeconds (seconds from investigation start, excluding any time the investigation sat waiting on a human response, so elapsedSeconds is deliberately not at minus the start time). investigationEnd is always present. When measured is true, convergedRca is always present too (an investigation that never settled earlier converges at its final report state), and only firstHypothesis can be absent, for the rare report that never states a cause. When measured is false, only investigationEnd is returned.
The same numbers are returned by the MCP server’s get_investigation tool as mttr_metrics, in snake_case (first_hypothesis, converged_rca, investigation_end, each with at and elapsed_seconds, plus measured). Connected agents get them without any extra call.

