Audit trail snapshot
incident_snapshotReturns the incidents that were active at a specific point in time. Recent datetimes are reconstructed from live and lifecycle data. Datetimes before 2026-04-08 are reconstructed from the historical archive (4.8M+ records) and are gated by the same tier lookback as /incidents/history (free has no archive access; Starter 1 year, Developer and Business 5 years, Pro and Enterprise unlimited). Archive (pre-2026-04-08) snapshots require a state filter, and meta.source indicates whether the result came from "live" or "archive".
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max results (default 500) | |
| state | No | Filter by state code. Required for archive (pre-2026-04-08) snapshots. | |
| datetime | Yes | ISO 8601 datetime to query (cannot be in the future) | |
| event_type | No | Filter by event type |