Skip to main content

Open data API

1. Get a key

Free, and it lands in your inbox. Keys start with alinganil_.

Get an API key →

2. Make a request

Send the key in the Authorization header on every request:

curl -H "Authorization: Bearer alinganil_YOUR_KEY" https://alinganil.com/api/v1/down
const res = await fetch("https://alinganil.com/api/v1/down", {
  headers: { Authorization: `Bearer ${process.env.ALINGANIL_API_KEY}` },
})
const data = await res.json()

Keep the key on a server or in an environment variable, not in public frontend code.

Endpoints

  • GET /api/v1/down

    Live status of GitHub, OpenAI, Cloudflare, Vercel and more, from their official status pages.

    Fresh every minute

  • GET /api/v1/cves

    The worst exploited vulnerability of each week for the last ~6 months, in plain English, with my take when there is one.

    Fresh every hour

  • GET /api/v1/posts

    Everything I've published (guides and short posts), newest first.

    Fresh every 5 minutes

  • GET /api/v1/status

    What I'm up to right now. Never includes meeting names.

    Fresh every minute

Rate limits

60 requests a minute and 5,000 a day, per key. Every response tells you where you stand:

X-RateLimit-Limit: 60
X-RateLimit-Remaining: 57
X-RateLimit-Reset: 42        # seconds until it resets

Hit the limit and you get a 429 with a Retry-After header. Cache responses on your side; the data doesn't change faster than the times above.

Errors

Errors are always JSON in the same shape:

{ "error": { "code": "rate_limited", "message": "...", "docs": "https://alinganil.com/open-data" } }
StatusCodeMeaning
401missing_key / invalid_keyNo key, or a key that doesn't exist.
403key_revokedThe key was shut off. Email me if you think that's a mistake.
429rate_limitedToo many requests. Wait the number of seconds in Retry-After.
503upstream_unavailableThe data source didn't answer. Try again shortly.

RSS (no key needed)

https://alinganil.com/feed.xml

Versioning and fair use

Everything here is v1. Fields can be added any time, but nothing gets removed or renamed in v1. A breaking change would go to /api/v2, announced at least 30 days ahead to everyone with a key.

Credit alinganil.com if you show the data publicly. Don't resell it, don't share your key, and don't try to get around the limits. Keys that break these rules get revoked.

The outage and vulnerability data come from the companies' own status pages, NIST and CISA. If they're wrong, this is wrong too. It's provided as is, with no uptime guarantee.

Questions or need higher limits? contact@alinganil.com