Supported platforms
Prerequisites
- A PagerDuty account on any plan.
- A User API Token from My Profile → User Settings → API Access.
Use a User API Token, not a General Access REST API Key. User tokens scope access to what the user can see, providing better security boundaries.
Setup
1
Open PagerDuty
Sign in to your PagerDuty account at app.pagerduty.com.
2
Generate a User API Key
Click your User Icon → My Profile, then scroll to User Settings → API Access and click Create API User Token:
- Description:
cloudthinker - Click Create Key
3
Add the connection in CloudThinker
Navigate to Connections → PagerDuty and enter:
- User API Key: the token you just generated
Connection details
Required permissions
Minimum (read-only)
A user with Observer or Responder role provides:- View incidents, services, and escalation policies
- View on-call schedules
- View teams and users
Recommended (full operations)
A user with Responder or Manager role provides:- All read permissions
- Acknowledge and resolve incidents
- Create incidents and status updates
- Manage on-call overrides
Agent capabilities
Once connected, agents can query and act on PagerDuty data.Verify the connection
Example prompts
Troubleshooting
Authentication failed
Authentication failed
The token is incorrect, expired, or revoked. Verify the User API Token, ensure you are using a User Token (not a REST API Key), and generate a new token if needed.
Permission denied
Permission denied
The user has insufficient role permissions or team-level access restrictions. For write operations, ensure the user has Responder or Manager role.
Missing services or incidents
Missing services or incidents
The user does not have access to the relevant teams. Verify team membership includes the services you want to monitor.
Token revoked
Token revoked
Navigate to My Profile → User Settings in PagerDuty, create a new API User Token, and update the token in CloudThinker connection settings.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- User token — use a User API Token scoped to a dedicated PagerDuty user rather than a General Access REST API Key.
- Team scoping — limit the dedicated user’s team membership to only the services CloudThinker needs to monitor.
Related
ServiceNow Connection
ITSM incident management
Datadog Connection
Observability and monitoring