/arm/{modeId}
curl --request GET \ --url https://api.openalarm.io/v1/alarm/k7m3x9q2f8d4w1b5n6p0r3t7v2x5z9c4/arm/night \ --header 'X-API-Key: oa_m9s346q3d25vt4f5v37e3s3e28jt97kb6cq643dzvmxxqkfbf5kznwj47tan9zt2'Arm the alarm to a specific mode and store it. {modeId} is an armed mode name -
home, away, night, or vacation. Disarmed is not among them:
it is the one mode you reach through disarm rather than by arming to it.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The alarm’s 32-character identifier. The API key gates the call; this names which alarm it acts on.
Example
k7m3x9q2f8d4w1b5n6p0r3t7v2x5z9c4An armed mode name - home, away, night or vacation.
Example
nightResponses
Section titled “Responses”Accepted - the call will be applied, and nothing has been sent at the moment the response
returns. Every endpoint on this API answers 202, so there is no other success code to
handle.
For a trigger, contact waits out the false-alarm cancellation window (optional, set per
mode) - a disarm inside it cancels the trigger before any incident opens. A repeat trigger
while an incident is already open is recorded against it and still returns 202.
202 does not mean an alert went out. A trigger that folds into an open incident, is
cancelled inside the false-alarm window, or lands in test mode is accepted and recorded
without reaching anyone. See the Arming guide.
Check data.environment if your automation depends on being live - a test alarm looks
identical from the outside otherwise.
The four-field envelope on every response. The 401 is the one exception - it returns
only a message and no traceId.
object
The outcome. false on 202, true on 404.
Human-readable, and null on success. On 404 it is generic wording - it never
indicates whether an ID exists but belongs to someone else.
Identifies this one call. Worth logging, and worth quoting if you report a problem. It is not a resource reference and no endpoint accepts one back.
The payload. Carries environment on every 2xx, plus the location the source belongs to when it has one.
object
Whether the trigger ran live or as a test. An alarm runs as a test when its own test
switch is on, or when its whole location’s is - either alone is enough. On a test
trigger the escalation policy still resolves and records, but nobody is alerted.
The location this alarm or panic button belongs to. Renaming a location never changes any ID or URL.
object
The location’s 32-character identifier.
The location’s display name.
Example
{ "error": false, "message": null, "traceId": "8f14e45f-ea0d-4a1b-9f2c-6b3d70c5e881", "data": { "environment": "live", "location": { "id": "2c9wvhrq52k5refhtvmmr0f8yjz5j9e9", "name": "Home" } }}The API key is missing or invalid.
This is the one response that does not use the envelope. It returns only a message -
no traceId, because no call was ever traced.
object
Example
{ "message": "Unauthorized"}The alarm or panic button is not available to fire.
This covers four situations, and they are deliberately indistinguishable from one another:
- The ID does not exist.
- It belongs to another account.
- It is in your account, but your key is not scoped to it.
- Your key can reach it, but the trigger cannot currently fire - you disabled it, or a plan downgrade deactivated it.
Separating them would turn a narrowly-scoped key into a way to discover which IDs are real, so no response ever does.
A trigger that cannot fire is a 404 rather than a 202 on purpose: accepting the call and
quietly doing nothing would tell you your alarm fired when it did not.
The four-field envelope on every response. The 401 is the one exception - it returns
only a message and no traceId.
object
The outcome. false on 202, true on 404.
Human-readable, and null on success. On 404 it is generic wording - it never
indicates whether an ID exists but belongs to someone else.
Identifies this one call. Worth logging, and worth quoting if you report a problem. It is not a resource reference and no endpoint accepts one back.
The payload. Carries environment on every 2xx, plus the location the source belongs to when it has one.
object
Whether the trigger ran live or as a test. An alarm runs as a test when its own test
switch is on, or when its whole location’s is - either alone is enough. On a test
trigger the escalation policy still resolves and records, but nobody is alerted.
The location this alarm or panic button belongs to. Renaming a location never changes any ID or URL.
object
The location’s 32-character identifier.
The location’s display name.
Example
{ "error": true, "message": "Alarm ID not found", "traceId": "8f14e45f-ea0d-4a1b-9f2c-6b3d70c5e881", "data": {}}