# Public

> Public endpoints of the StatusTick REST API: a public status page, open a password-protected status page, count a view of a status page, the page's logo.

## A public status page

`GET /v1/pages/{slug}`

The page as its visitors see it, by the slug in its address. Answers `404` for a page that is not public. A password-protected page answers `401` with its name only, unless `X-Page-Access` holds a valid access token from `POST /v1/pages/{slug}/access`; an answer to a call with that header is never stored by caches.

## Open a password-protected status page

`POST /v1/pages/{slug}/access`

Checks the page's password and answers with an access token for `X-Page-Access`, valid for 12 hours or until the page's password changes. At most 5 tries a minute per client IP and page, then `429` with `Retry-After`. Feeds, badges, the widget and subscriptions of a password-protected page answer `404`.

## Count a view of a status page

`POST /v1/pages/{slug}/view`

Sent by the public or password-protected page from the visitor's browser (for example with `navigator.sendBeacon`), so cached pages are counted too; no body. Bots are not counted. No cookie is set and the visitor's IP and user agent are not kept. Rate limited per client IP.

## The page's logo

`GET /v1/pages/{slug}/logo`

PNG, JPEG or SVG. Use the page's `logoURL`; with its `v` the image is cached for a day.

## The page's favicon

`GET /v1/pages/{slug}/favicon`

PNG, ICO or SVG. Use the page's `faviconURL`; with its `v` the image is cached for a day.

## The page's incidents as an RSS feed

`GET /v1/pages/{slug}/feed.rss`

## The page's incidents as an Atom feed

`GET /v1/pages/{slug}/feed.atom`

## The page's incidents as a JSON Feed

`GET /v1/pages/{slug}/feed.json`

## A badge with the page's status

`GET /v1/pages/{slug}/badge.svg`

## A badge with one component's status

`GET /v1/pages/{slug}/components/{componentId}/badge.svg`

## A script that shows the page's status on your site

`GET /v1/pages/{slug}/widget.js`

Add `<script src="https://api.statustick.com/v1/pages/{slug}/widget.js" async></script>` where the status should show.

## Status of the third-party services StatusTick follows

`GET /v1/vendors`

## One vendor with 90 days of incidents

`GET /v1/vendors/{vendorId}`

## Addresses and User-Agent of StatusTick's checks

`GET /v1/drone-ips`

Allow these in your firewall or WAF so checks are not blocked.

## Is my app production ready? (free check)

`POST /v1/readiness-checks`

Checks a public web address from up to 5 regions at once and answers within about 25 seconds: reachability and response time per region, the HTTPS certificate (trust and days to expiry), whether http:// redirects to https://, a health endpoint (`/health`, `/healthz`, `/api/health`, `/status`), a status page (`status.<domain>` or a `/status` link on the home page) and security headers, each with a fix in plain words. No key and no account. Private, loopback, link-local, metadata and other internal addresses are refused, also after DNS resolution and on redirects. Nothing is stored. At most 5 checks per client IP in 10 minutes and 30 a minute in total, then `429` with `Retry-After`; browsers may call it only from the StatusTick site.

## Check a domain's SSL certificate (free check)

`POST /v1/ssl-checks`

Reads the certificate on port 443 from one region: the chain, issuer, expiry and days left, whether it matches the domain and is trusted, and the TLS versions the server accepts. `host` is a domain name; a pasted address such as `https://myapp.com/login` is read as its domain. No key and no account. Domains that resolve to private, loopback, link-local, metadata or other internal addresses are refused. Answers are kept 5 minutes per domain, and nothing is stored. SSL and DNS checks share a limit of 20 per client IP in 10 minutes and 120 a minute in total, then `429` with `Retry-After`; browsers may call it only from the StatusTick site.

## Look up a domain's DNS records from three regions (free check)

`POST /v1/dns-checks`

Resolves A, AAAA, CNAME, MX, TXT, NS and CAA records from 3 regions at once and marks where regions disagree. A domain without an address (only MX or TXT records, for example) is checked too. Domains that resolve to private or internal addresses are refused, and so is any answer that points to one. Answers are kept 5 minutes per domain, and nothing is stored. Shares its limits with `POST /v1/ssl-checks`.
