StatOSS

Subscribers

People and systems that want to hear about incidents without watching the page.

Email

On Pro the public page ends with a box where visitors leave an email address, and a Get updates link under the headline leads to it. They get a confirmation link, which opens a page with a Confirm button (a mail scanner opening the link subscribes nobody), and from then on one email when a monitor has been down longer than the page's threshold (five minutes unless changed), one when it is back, and one for every incident or maintenance update you post. The emails come from the page by name ("Northwind status"), show its name or logo at the top, and link to the incident's own page. Every email has an unsubscribe link and the List-Unsubscribe header; the link keeps working after the page changes its address. An address that is not confirmed within seven days is dropped. Outlook, Hotmail and other Microsoft mailboxes may put these emails in Junk for now. The box runs Cloudflare Turnstile, a browser check that is invisible unless Cloudflare wants a click, and takes five sign-ups from one visitor in ten minutes and ten an hour across all pages; a page takes as many visitors as come. One address gets at most three confirmation emails an hour. A page holds 1,000 confirmed subscribers; the Subscribers tab sells blocks of 1,000 more and has an overage switch. The same tab lists the addresses and can remove any of them.

Choosing monitors

A page with more than one monitor lets the visitor tick the ones they care about. They then hear about incidents that name any of those, and about incidents on the whole page, and nothing else. Every email, and every Discord and Teams message, has a Change what you get link to a page where the ticks can be changed later, or the updates stopped.

Import and export

The Subscribers tab downloads the page's subscribers as CSV: the address, the kind, the monitors followed and when each joined. A Slack, Discord or Teams channel is listed by its name, since its webhook is the channel's secret. Each download is in the audit log.

The owner or an admin can import addresses from another tool: a CSV with an email column, as Statuspage, Instatus and Better Stack export it, or one address per line, pasted or picked as a file. Read shows how many are new, already on the list, not addresses, or past the allowance; importing asks you to tick that the people asked for this page's updates. They are added confirmed, follow the whole page, and are not emailed. An import fills the allowance and stops there, so it never adds overage; a private page takes only addresses that may see it. Up to 20,000 addresses at a time.

Slack

Next to the email field is an Add to Slack button. Slack asks the visitor which channel to post in, and that channel then gets every incident and maintenance update the visitor's ticks cover. The app asks Slack for one permission, posting to that channel, and cannot read anything. A channel counts as one subscriber. It stops when someone removes the app from the channel, follows the link in the first message, or the owner removes it on the Subscribers tab.

Discord

Add to Discord, next to the email field, sends the visitor to Discord to pick a server and a channel; it takes the Manage Webhooks permission there. The app asks Discord for one thing, a webhook into that channel, and cannot read anything. The channel gets a message saying it is on, then every update the visitor's ticks cover, as embeds that mention nobody.

A channel's webhook can also be pasted under Discord or Teams: in Discord, open the channel's settings, then Integrations, Webhooks, New Webhook, and Copy Webhook URL. The channel then gets a message with a Confirm link, and updates start once someone opens it, as with an email address. A channel counts as one subscriber once it is on. It stops when the webhook is deleted, someone follows Stop these updates in a message, or the owner removes it on the Subscribers tab.

Microsoft Teams

Teams posts from a workflow. In the channel, open More options, then Workflows, pick "Post to a channel when a webhook request is received", choose the team and channel, and copy the URL it shows. Paste it under Discord or Teams on the page, as for Discord: the channel gets a card with a Confirm button first. Updates arrive as Adaptive Cards with a button to the status page. Deleting the workflow ends it.

The owner can also add a Discord or Teams channel on the Subscribers tab, in the field for webhooks; it is on at once, and the channel gets a message saying so. A private page posts to no channel, since a channel's members are not the page's viewers.

Webhook subscribers

The Subscribers tab can also add a URL that receives every incident and maintenance update as JSON. Webhooks are added by the owner only, so the public form cannot be pointed at someone else's server. They can be limited to some monitors like an email subscriber. The body is signed with HMAC-SHA256 using the secret shown next to the URL, sent as X-StatOSS-Signature: sha256=<hex>, with X-StatOSS-Event: incident-update. Answer with any 2xx. Three refusals in a row (a 4xx from the webhook, a 5xx from the mail server) remove the subscriber; a timeout or an outage on our side is not counted.

{
  "event": "incident-update",
  "page": "Northwind",
  "pageUrl": "https://northwind.statoss.com",
  "subject": "Northwind: Elevated API error rate (identified)",
  "heading": "Elevated API error rate",
  "paragraphs": [
    "A bad deploy. Rolling back.",
    "Status: Identified. Posted 15 Sep 09:20 UTC."
  ],
  "url": "https://northwind.statoss.com/incidents/0f3c9a2e",
  "at": 1789456789000
}