Prerequisites
- A FireHydrant account with the Owner role, because FireHydrant requires Owner permissions to create API keys.
- A key created only for CloudThinker, so you can delete it without breaking another integration.
Setup
1
Open FireHydrant
Sign in to FireHydrant as an Owner and go to Settings → API Keys.
2
Create an API key
Click + Create API key and fill in:
- Name:
cloudthinker - Description: what the key is for
3
Add the connection in CloudThinker
Navigate to Connections → FireHydrant and enter:
- API Key: the token you just copied
Connection details
There is no region or URL to enter. When the key is valid, CloudThinker shows the organization name it belongs to, for example
FireHydrant read-only connection verified (Example Org).Required permissions
FireHydrant gives an API key Owner permissions by default, and you must be an Owner to create one. Agents use only read access, and CloudThinker sends no request that changes FireHydrant.Agent capabilities
Once connected, agents read your FireHydrant incident and alert data. If you ask for a change, an agent tells you it cannot make it and points you to the right FireHydrant page.Verify the connection
Example prompts
Troubleshooting
FireHydrant rejected the API key
FireHydrant rejected the API key
CloudThinker shows this when FireHydrant answers
401. The key was copied incompletely or is no longer valid. Create a new key in Settings → API Keys and update the connection.FireHydrant accepted the key but refused the request
FireHydrant accepted the key but refused the request
CloudThinker shows this when FireHydrant answers
403. Check that the key is still active and that your FireHydrant organization is not suspended.FireHydrant rate-limited the test
FireHydrant rate-limited the test
CloudThinker shows this when FireHydrant answers
429. FireHydrant documents its limit as at least 50 requests every 10 seconds per account, shared across the account’s tokens, so another integration can use it up. Wait a minute and test again.Could not reach the FireHydrant API
Could not reach the FireHydrant API
CloudThinker could not connect to FireHydrant at all. Check that your network allows outbound access, then connect again.
A filtered question returns nothing
A filtered question returns nothing
A severity, priority, or team name that does not match your account looks the same as a quiet week. Ask the agent to run discovery, use the names it returns, and repeat the question without the filter first.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Owner-level key — create a dedicated key for CloudThinker and delete it when you remove the connection.
- One shared rate limit — keep the number of integrations calling FireHydrant in mind when agents run many reads.
Related
Jira Service Management Connection
Alert triage, on-call visibility, and incident sync
Rootly Connection
Incident triage and alert review