Skip to main content
Connect your FireHydrant organization to let CloudThinker agents review open and recent incidents, read Signals alerts and whether each became an incident, and look up which team owns a service. FireHydrant authenticates with an API key, and agents only read: they never declare, update, page, or publish anything in FireHydrant.

Prerequisites

  • A FireHydrant account with the Owner role, because FireHydrant requires Owner permissions to create API keys.
  • A key created only for CloudThinker, so you can delete it without breaking another integration.
FireHydrant documents that an API key has Owner permissions by default. Treat the key like an Owner credential even though CloudThinker only reads with it.

Setup

1

Open FireHydrant

Sign in to FireHydrant as an Owner and go to Settings → API Keys.
2

Create an API key

Click + Create API key and fill in:
  • Name: cloudthinker
  • Description: what the key is for
The name and description are for your reference only. Click Save. FireHydrant returns you to the API keys page, where the token appears. Copy it right away: FireHydrant displays it only once, so a lost token means creating a new key.
3

Add the connection in CloudThinker

Navigate to Connections → FireHydrant and enter:
  • API Key: the token you just copied
Click Connect. CloudThinker verifies the key and shows a Connected status.

Connection details

There is no region or URL to enter. When the key is valid, CloudThinker shows the organization name it belongs to, for example FireHydrant read-only connection verified (Example Org).

Required permissions

FireHydrant gives an API key Owner permissions by default, and you must be an Owner to create one. Agents use only read access, and CloudThinker sends no request that changes FireHydrant.
Follow least privilege where FireHydrant allows it. Create a dedicated key for CloudThinker, name it clearly, and delete it when you disconnect.

Agent capabilities

Once connected, agents read your FireHydrant incident and alert data. If you ask for a change, an agent tells you it cannot make it and points you to the right FireHydrant page.

Verify the connection

Example prompts

Agents cap every read and report the total FireHydrant matched. Ask for a narrower time window when a run returns fewer rows than the total.

Troubleshooting

CloudThinker shows this when FireHydrant answers 401. The key was copied incompletely or is no longer valid. Create a new key in Settings → API Keys and update the connection.
CloudThinker shows this when FireHydrant answers 403. Check that the key is still active and that your FireHydrant organization is not suspended.
CloudThinker shows this when FireHydrant answers 429. FireHydrant documents its limit as at least 50 requests every 10 seconds per account, shared across the account’s tokens, so another integration can use it up. Wait a minute and test again.
CloudThinker could not connect to FireHydrant at all. Check that your network allows outbound access, then connect again.
A severity, priority, or team name that does not match your account looks the same as a quiet week. Ask the agent to run discovery, use the names it returns, and repeat the question without the filter first.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Owner-level key — create a dedicated key for CloudThinker and delete it when you remove the connection.
  • One shared rate limit — keep the number of integrations calling FireHydrant in mind when agents run many reads.

Jira Service Management Connection

Alert triage, on-call visibility, and incident sync

Rootly Connection

Incident triage and alert review