> ## Documentation Index
> Fetch the complete documentation index at: https://docs.telemax.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# List alerts

> List recent alerts for a company.

### Overview

Returns up to `num` alert records across alert record types, after `from` (UTC), for alerts belonging to companies in the caller’s tree when `compId` matches an allowed company.

<Note>
  A V2 version of this endpoint is available: [Alert records](/v2/api-reference/get-companies-id-alert-records). New integrations should prefer V2.
</Note>

### Endpoint

`POST /api/GetAlerts`

### Query parameters

<ParamField query="compId" type="integer" required>
  Company id to scope alerts.
</ParamField>

<ParamField query="from" type="string (datetime)" required>
  Only alerts **after** this UTC instant.
</ParamField>

<ParamField query="num" type="integer" required>
  Maximum alerts to return (applied per type and globally after merge).
</ParamField>

### Response

**200 OK** — `AlertDto[]`

| Field             | Type             | Description                 |
| ----------------- | ---------------- | --------------------------- |
| Id                | integer          | Alert definition id         |
| UtcTime           | datetime \| null | When triggered              |
| UserTime          | datetime \| null | Localized                   |
| UserTimeFormatted | string           | Formatted with user pattern |
| AlertType         | integer          | Alert type discriminator    |
| Description       | string           | From latest snapshot        |
| VehicleId         | integer          | Internal vehicle id         |
| VehicleName       | string           | Resolved name               |
| Address           | string           | Reverse geocoded            |
| Lat               | number           | Latitude                    |
| Lng               | number           | Longitude                   |
| IsRead            | boolean          | Read state                  |

### Error responses

| Status | Meaning                                     |
| ------ | ------------------------------------------- |
| 401    | Missing company or user id claim            |
| 404    | `{ "error": "Company {compId} not found" }` |


## OpenAPI

````yaml openapi.yaml POST /api/GetAlerts
openapi: 3.1.0
info:
  title: Telemax External API (V1)
  version: '2026-04-14'
  description: >
    Telemax External API — fleet telemetry, vehicle commands, and integrations.


    **Base URL:** `https://api.telemax.com.au`


    **Authentication:** All routes require a `Bearer` JWT unless marked
    `[AllowAnonymous]`.

    Obtain tokens via `/api/Authentication/token/api-key` or
    `/api/Authentication/token/user`.


    **POST-first architecture:** Almost all data endpoints use `POST` with
    query-string parameters.

    The two exceptions using `GET` are `GetDeviceId` and `GET
    /api/devices/{id}/dtc-codes`.


    **API versioning:** All responses will include an `X-API-Version` header
    containing the

    date-based version string (e.g. `2026-04-14`). See the
    [Changelog](/v1/changelog) for

    the deprecation policy and version history.


    For full documentation including error handling, pagination, and known field
    quirks, see [docs.telemax.com.au](https://docs.telemax.com.au).
servers:
  - url: https://api.telemax.com.au
security:
  - BearerAuth: []
paths:
  /api/GetAlerts:
    parameters: []
    post:
      summary: List Alerts
      description: Get alerts for the given company ID, starting from the specified date.
      parameters:
        - name: compId
          description: Company ID.
          in: query
          required: true
          example: 85
          schema:
            type: integer
        - name: from
          description: Starting date.
          in: query
          required: true
          example: '2025-07-21T10:00:00Z'
          schema:
            type: string
        - name: num
          description: >
            Maximum number of alerts to return (legacy max-count parameter).
            Results are ordered by date descending. There is no total count or
            page cursor — pagination will be added in a future release.
            Recommended maximum: 100.
          in: query
          required: true
          example: 50
          schema:
            type: integer
            maximum: 100
        - name: Content-Type
          in: header
          required: false
          description: Standard and must keep as it is.
          example: application/x-www-form-urlencoded
          schema:
            type: string
        - name: Authorization
          in: header
          required: true
          description: Bearer your_token
          example: Bearer {token}
          schema:
            type: string
      responses:
        '200':
          description: Successful response with array of alert records
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  properties:
                    Id:
                      type: integer
                      description: Alert ID
                      example: 101
                    UtcTime:
                      type: string
                      format: date-time
                      nullable: true
                      description: Time in UTC
                      example: '2024-01-15T10:30:00Z'
                    UserTime:
                      type: string
                      format: date-time
                      nullable: true
                      description: Time in user timezone
                      example: '2024-01-15T12:30:00+02:00'
                    UserTimeFormated:
                      type: string
                      description: >
                        Timestamp in the user's configured date-time format
                        (e.g. "15/01/2024 12:30:00"). **Note:** The field name
                        is intentionally misspelled (`UserTimeFormated`, single
                        't') to preserve backward compatibility.
                      x-legacy-note: >-
                        Intentional misspelling preserved for backward
                        compatibility.
                      example: 15/01/2024 12:30:00
                    AlertType:
                      type: string
                      description: Alert type
                      example: Overspeed
                    Description:
                      type: string
                      description: Description of the alert
                      example: Vehicle exceeded speed limit by 25 km/h
                    VehicleId:
                      type: integer
                      description: Vehicle ID
                      example: 12345
                    VehicleName:
                      type: string
                      description: Name of the vehicle
                      example: Fleet Vehicle 002
                    Address:
                      type: string
                      description: Address where the alert occurred
                      example: 456 Broadway, New York, NY 10012
                    Lat:
                      type: number
                      format: double
                      description: Latitude
                      example: 40.7218
                    Lng:
                      type: number
                      format: double
                      description: Longitude
                      example: -73.999
                    IsRead:
                      type: boolean
                      description: Whether the alert has been read
                      example: false
              example:
                - id: 101
                  utcTime: '2024-01-15T10:30:00Z'
                  userTime: '2024-01-15T12:30:00+02:00'
                  userTimeFormatted: 15/01/2024 12:30:00
                  alertType: Overspeed
                  description: Vehicle exceeded speed limit by 25 km/h
                  vehicleId: 12345
                  vehicleName: Fleet Vehicle 002
                  address: 456 Broadway, New York, NY 10012
                  lat: 40.7218
                  lng: -73.999
                  isRead: false
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  responses:
    Unauthorized:
      description: >
        **401 Unauthorized** — JWT is missing, expired, or malformed.

        The JWT bearer middleware rejects the request before it reaches the
        controller.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: AUTHENTICATION
            code: TOKEN_EXPIRED
            description: >-
              The access token has expired. Request a new token using
              /api/authentication/token/user or
              /api/authentication/token/api-key.
            requestId: req_7f3a2b1c
            docUrl: https://docs.telemax.com.au/errors#token-expired
    Forbidden:
      description: >
        **403 Forbidden** — Token is valid but the caller does not have access
        to the requested company or vehicle.

        Tokens issued for one company cannot access resources scoped to a
        different company in the hierarchy.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: AUTHORIZATION
            code: COMPANY_ACCESS_DENIED
            description: >-
              Your token does not grant access to company 99. Ensure you are
              using a token issued for this company.
            requestId: req_4a1d9e2f
            docUrl: https://docs.telemax.com.au/errors#company-access-denied
    NotFound:
      description: >
        **404 Not Found** — The requested vehicle ID, company ID, or IMEI does
        not exist or is not accessible.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: NOT_FOUND
            code: VEHICLE_NOT_FOUND
            description: Vehicle with ID 9999 was not found.
            requestId: req_2b8c1a5d
            docUrl: https://docs.telemax.com.au/errors#not-found
    UnprocessableEntity:
      description: >
        **422 Unprocessable Entity** — A parameter is present but has an invalid
        format (e.g. negative vehicle ID, malformed ISO 8601 date string).
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: VALIDATION
            code: INVALID_DATE_FORMAT
            description: >-
              The 'from' parameter '2025-13-45' is not a valid ISO 8601
              date-time string.
            requestId: req_9f3e7c1b
            docUrl: https://docs.telemax.com.au/errors#invalid-parameter
    TooManyRequests:
      description: >
        **429 Too Many Requests** — Rate limit exceeded. Check the Retry-After
        header for the number of seconds to wait before retrying.

        Use exponential backoff: wait Retry-After seconds, then double the
        interval on each subsequent 429.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: RATE_LIMIT
            code: RATE_LIMIT_EXCEEDED
            description: Too many requests. Wait 30 seconds before retrying.
            requestId: req_6d2f8b4a
            docUrl: https://docs.telemax.com.au/errors#rate-limit
    InternalServerError:
      description: >
        **500 Internal Server Error** — An unexpected error occurred. Include
        the requestId when contacting support.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: SERVER_ERROR
            code: INTERNAL_ERROR
            description: >-
              An unexpected error occurred. Please try again or contact support
              with the requestId.
            requestId: req_1e5a3c7d
            docUrl: https://docs.telemax.com.au/errors#server-error
  headers:
    X-RateLimit-Limit:
      description: Maximum number of requests allowed per minute for this token.
      schema:
        type: integer
        example: 60
    X-RateLimit-Remaining:
      description: Number of requests remaining in the current rate limit window.
      schema:
        type: integer
        example: 47
    X-RateLimit-Reset:
      description: Unix timestamp (seconds) at which the current rate limit window resets.
      schema:
        type: integer
        example: 1746000060
    Retry-After:
      description: Number of seconds to wait before retrying after a 429 response.
      schema:
        type: integer
        example: 30
  schemas:
    ApiError:
      type: object
      description: Standard error response returned by all API endpoints.
      properties:
        type:
          type: string
          description: >-
            Error category (e.g. AUTHENTICATION, AUTHORIZATION, NOT_FOUND,
            VALIDATION, RATE_LIMIT, SERVER_ERROR).
          example: AUTHENTICATION
        code:
          type: string
          description: Machine-readable error code within the category.
          example: TOKEN_EXPIRED
        description:
          type: string
          description: Human-readable explanation of the error and how to resolve it.
          example: The access token has expired. Request a new token.
        requestId:
          type: string
          description: Unique request identifier for support correlation.
          example: req_7f3a2b1c
        docUrl:
          type: string
          format: uri
          description: Link to the relevant error documentation page.
          example: https://docs.telemax.com.au/errors#token-expired
      required:
        - type
        - code
        - description
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        JWT Bearer token obtained from `POST /api/authentication/token/user` or
        `POST /api/authentication/token/api-key`.


        **Lifetime:** ~24 hours (86,399 seconds). Cache the token and reuse it.
        Re-authenticate 5 minutes before expiry.


        **Scoping:**

        - User tokens are scoped to a single company.

        - API key tokens may restrict access to a vehicle allowlist and/or
        action set (see token claims).


        **No refresh endpoint** — re-authenticate with your credentials when the
        token expires.

````