Monitoring alerts on your phone
Setting this up takes about a minute. The slow part is not the software — it is deciding what to call yourself, because the handle ends up on a poster and cannot be changed afterwards.
What this actually looks like
Email is where alerts go to be read tomorrow. A webhook from your monitoring into a sealed channel puts the failure on the phones of the people carrying it tonight — and this is the one case in this list where the urgent rung is honest, because it is the one people granted it for.
How you would set it up
- Create a private channel for the on-call group and invite only the people on the rota.
- POST from your alerting rules, or forward the webhook you already have.
- Send at Urgent only for what should wake somebody. Anything that can wait until nine goes at Normal, or the permission goes away.
Everything the console does, from your own code
A REST API you can read in an afternoon: one key, one POST, one alert. Credentials carry scopes, so the cron job that sends can be forbidden from deleting a channel, and a key can be bound to a single channel. Webhooks push sends, cancels and subscriptions to your endpoint with a signature you verify, instead of you polling us for something you already know. There is also an MCP server, so an assistant can be connected over OAuth — no pasted keys, revocable per client, and narrowed to the scopes you approve on a consent screen you read first.
Private means sealed, not merely unlisted
A private channel is not one that is simply missing from a directory. It requires an invite code both to subscribe AND to read anything about it, and a request without one gets exactly the same “not found” as a handle that never existed — because a different answer would let anybody confirm that a school’s or an ops team’s channel exists by guessing its name. Invite codes can carry a use limit and can be revoked; revoking is a timestamp and by default removes nobody who already joined.
Three rungs, and each one costs something
Normal is a notification in the shade and needs no permission at all. Important is a heads-up banner with a sound, if the subscriber allowed this channel that. Urgent may take over the screen, override Do Not Disturb and be read aloud — each granted separately, each refusable. The rung is a ceiling rather than an outcome, and it is also a budget: a channel that spends Urgent on a car-park closure loses the permission the same afternoon, from the only people who could have granted it.
Questions, answered plainly
Is there an API?
Yes — the same one the console uses, so anything you can do by hand you can automate. Scoped keys, signed webhooks, and an MCP server if you want an assistant to do it.
Can somebody find my private channel by guessing the name?
No. A sealed channel answers a request without an invite code with exactly the same “not found” that a nonexistent handle gets. There is no response that distinguishes “this exists but you may not see it” from “this does not exist”, because that difference is itself a leak.
When should I use urgent priority?
When somebody needs to act in the next few minutes: an evacuation, a lockdown, a genuine safety instruction. Not for a schedule change, and not for anything that would still be fine to read an hour later. Urgent is granted by subscribers one at a time and withdrawn just as easily, so it behaves like a budget rather than a setting.
Do subscribers need an account?
No. They install the app, subscribe to a handle, and that is the whole of it. Only the person running the channel signs up for anything.
Say it once. Every subscribed phone gets it.
Free up to 100 subscribers, no card to start, and the handle is yours permanently.
Start a channel