> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# FireHydrant

> Connect FireHydrant to CloudThinker to review open incidents, severity, Signals alerts, and the service and team catalog

Connect your FireHydrant organization to let CloudThinker agents review open and recent incidents, read Signals alerts and whether each became an incident, and look up which team owns a service. FireHydrant authenticates with an **API key**, and agents only read: they never declare, update, page, or publish anything in FireHydrant.

## Prerequisites

* A **FireHydrant account** with the **Owner** role, because FireHydrant requires Owner permissions to create API keys.
* A key created only for CloudThinker, so you can delete it without breaking another integration.

<Warning>
  FireHydrant documents that an API key has Owner permissions by default. Treat the key like an Owner credential even though CloudThinker only reads with it.
</Warning>

## Setup

<Steps>
  <Step title="Open FireHydrant">
    Sign in to FireHydrant as an Owner and go to **Settings → API Keys**.
  </Step>

  <Step title="Create an API key">
    Click **+ Create API key** and fill in:

    * **Name**: `cloudthinker`
    * **Description**: what the key is for

    The name and description are for your reference only. Click **Save**. FireHydrant returns you to the API keys page, where the token appears. Copy it right away: FireHydrant displays it only once, so a lost token means creating a new key.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → FireHydrant** and enter:

    * **API Key**: the token you just copied

    Click **Connect**. CloudThinker verifies the key and shows a **Connected** status.
  </Step>
</Steps>

## Connection details

| Field | Description | Example |
| - | - | - |
| **API Key** | The FireHydrant API key | `<your-api-key>` |

<Note>
  There is no region or URL to enter. When the key is valid, CloudThinker shows the organization name it belongs to, for example `FireHydrant read-only connection verified (Example Org)`.
</Note>

## Required permissions

FireHydrant gives an API key Owner permissions by default, and you must be an Owner to create one. Agents use only read access, and CloudThinker sends no request that changes FireHydrant.

<Tip>
  Follow least privilege where FireHydrant allows it. Create a dedicated key for CloudThinker, name it clearly, and delete it when you disconnect.
</Tip>

## Agent capabilities

Once connected, agents read your FireHydrant incident and alert data. If you ask for a change, an agent tells you it cannot make it and points you to the right FireHydrant page.

| Capability | Description |
| - | - |
| **Discovery** | Read the organization, services with their owning and responding teams, teams, and the severity, priority, and milestone names your account uses |
| **Incident review** | List open or recent incidents with milestone, severity, priority, timestamps, impacted services, assigned teams, and a link |
| **Alert review** | List Signals alerts with status, priority, integration, owning team, how many incidents each created, and FireHydrant's noise flag |
| **Service health** | Show the number of active incidents per service |

### Verify the connection

```text theme={null}
Run FireHydrant discovery and summarize the organization, the severity names this account uses, and how many services and teams it can read
```

### Example prompts

```text theme={null}
List the FireHydrant incidents that are still open, with severity and impacted services
Which Signals alerts fired in the last 24 hours and never became an incident?
Which team owns the checkout service in FireHydrant?
```

Agents cap every read and report the total FireHydrant matched. Ask for a narrower time window when a run returns fewer rows than the total.

## Troubleshooting

<Accordion title="FireHydrant rejected the API key">
  CloudThinker shows this when FireHydrant answers `401`. The key was copied incompletely or is no longer valid. Create a new key in **Settings → API Keys** and update the connection.
</Accordion>

<Accordion title="FireHydrant accepted the key but refused the request">
  CloudThinker shows this when FireHydrant answers `403`. Check that the key is still active and that your FireHydrant organization is not suspended.
</Accordion>

<Accordion title="FireHydrant rate-limited the test">
  CloudThinker shows this when FireHydrant answers `429`. FireHydrant documents its limit as at least 50 requests every 10 seconds per account, shared across the account's tokens, so another integration can use it up. Wait a minute and test again.
</Accordion>

<Accordion title="Could not reach the FireHydrant API">
  CloudThinker could not connect to FireHydrant at all. Check that your network allows outbound access, then connect again.
</Accordion>

<Accordion title="A filtered question returns nothing">
  A severity, priority, or team name that does not match your account looks the same as a quiet week. Ask the agent to run discovery, use the names it returns, and repeat the question without the filter first.
</Accordion>

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Owner-level key** — create a dedicated key for CloudThinker and delete it when you remove the connection.
- **One shared rate limit** — keep the number of integrations calling FireHydrant in mind when agents run many reads.

## Related

<CardGroup cols={2}>
  <Card title="Jira Service Management Connection" icon="https://mintcdn.com/cloudthinker/fJM2cOggET3WD6Z_/images/icons/jsm.svg?fit=max&auto=format&n=fJM2cOggET3WD6Z_&q=85&s=37875ebadc8c2370ac9a58b6c701630a" href="/guide/connections/jsm" width="24" height="24" data-path="images/icons/jsm.svg">
    Alert triage, on-call visibility, and incident sync
  </Card>

  <Card title="Rootly Connection" icon="https://mintcdn.com/cloudthinker/6kGAil0P51KlEpCK/images/icons/rootly.svg?fit=max&auto=format&n=6kGAil0P51KlEpCK&q=85&s=925e926caae56327843e070470d78f85" href="/guide/connections/rootly" width="32" height="32" data-path="images/icons/rootly.svg">
    Incident triage and alert review
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.