Open data API
1. Get a key
Free, and it lands in your inbox. Keys start with alinganil_.
Get an API key →2. Make a request
Send the key in the Authorization header on every request:
curl -H "Authorization: Bearer alinganil_YOUR_KEY" https://alinganil.com/api/v1/down
const res = await fetch("https://alinganil.com/api/v1/down", {
headers: { Authorization: `Bearer ${process.env.ALINGANIL_API_KEY}` },
})
const data = await res.json()Keep the key on a server or in an environment variable, not in public frontend code.
Endpoints
GET /api/v1/down
Live status of GitHub, OpenAI, Cloudflare, Vercel and more, from their official status pages.
Fresh every minute
GET /api/v1/cves
The worst exploited vulnerability of each week for the last ~6 months, in plain English, with my take when there is one.
Fresh every hour
GET /api/v1/posts
Everything I've published (guides and short posts), newest first.
Fresh every 5 minutes
GET /api/v1/status
What I'm up to right now. Never includes meeting names.
Fresh every minute
Rate limits
60 requests a minute and 5,000 a day, per key. Every response tells you where you stand:
X-RateLimit-Limit: 60 X-RateLimit-Remaining: 57 X-RateLimit-Reset: 42 # seconds until it resets
Hit the limit and you get a 429 with a Retry-After header. Cache responses on your side; the data doesn't change faster than the times above.
Errors
Errors are always JSON in the same shape:
{ "error": { "code": "rate_limited", "message": "...", "docs": "https://alinganil.com/open-data" } }| Status | Code | Meaning |
|---|---|---|
| 401 | missing_key / invalid_key | No key, or a key that doesn't exist. |
| 403 | key_revoked | The key was shut off. Email me if you think that's a mistake. |
| 429 | rate_limited | Too many requests. Wait the number of seconds in Retry-After. |
| 503 | upstream_unavailable | The data source didn't answer. Try again shortly. |
RSS (no key needed)
https://alinganil.com/feed.xml
Versioning and fair use
Everything here is v1. Fields can be added any time, but nothing gets removed or renamed in v1. A breaking change would go to /api/v2, announced at least 30 days ahead to everyone with a key.
Credit alinganil.com if you show the data publicly. Don't resell it, don't share your key, and don't try to get around the limits. Keys that break these rules get revoked.
The outage and vulnerability data come from the companies' own status pages, NIST and CISA. If they're wrong, this is wrong too. It's provided as is, with no uptime guarantee.
Questions or need higher limits? contact@alinganil.com