PAGERDUTY_API_KEY), plus a second (PAGERDUTY_REGION) if your account is in PagerDuty’s EU region.
Scope of this integration today. ConfigView reads who has PagerDuty and with what role and license, how PagerDuty can reach each person (how many email, phone, SMS and push methods and notification rules, never the numbers themselves), teams and their members, on-call schedules, escalation policies and who is on call now, services and every tool that sends them alerts, every place PagerDuty sends incident data (extensions, webhook subscriptions, Incident Workflow connections), the apps people have authorized against PagerDuty, and the Audit Trail of who changed what. ConfigView only reads. It never creates, changes or deletes anything, and it never reads incidents, alerts, notes, phone numbers, integration keys or webhook secrets.
Step 1: Open the PagerDuty page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/pagerduty
PagerDuty shows an API key once, when you create it, so paste it straight into ConfigView instead of keeping it in a notes file.
Step 2: Check your service region
Look at the address bar when you are signed in to PagerDuty:
If your address ends in
.eu.pagerduty.com, type EU into PAGERDUTY_REGION under Credentials and click the save icon. An EU key sent to the US address is rejected.
Step 3: Create a read-only account API key
Use an account (General Access) key, not a personal one. A personal User API key only sees what that one person can see, can’t read the Audit Trail unless they are an admin, and stops working when they leave.- Sign in to PagerDuty as an Admin or the Account Owner (only they can create account keys)
- Open Integrations → Developer Tools → API Access Keys
- Click Create New API Key
- Description:
ConfigView - Tick Read-only API Key, so the key can only make read (
GET) calls - Click Create Key and copy the key
- Switch to the ConfigView tab, paste it into
PAGERDUTY_API_KEYunder Credentials, and click the save icon
Step 4: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/pagerduty, confirm the credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the key, reads the user list, then reads one record from each kind of data.
- “PagerDuty API key” fails with 401. The key is wrong or was deleted, or your account is in the other region. Check
PAGERDUTY_REGION(Step 2). - “PagerDuty users” fails. The key is valid but can’t list users. Use an account key created by an Admin or the Account Owner (Step 3), not a personal key.
- A check is skipped with “not available”. The feature it names isn’t on your PagerDuty plan, or the key can’t reach it. Everything else still works; that table stays empty.
- “Audit Trail” is skipped. Your plan doesn’t include Audit Trail (PagerDuty answers 402), or the key is a personal key of someone who is not an admin.
Plan requirements
The Account Features table lists what your plan turns on.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column. Every table keeps only the newest run, except pagerduty_audit_records, which keeps every record ever collected.
Things worth knowing
People are joined by PagerDuty user id. Schedules, escalation policies, team members and on-call entries name people by PagerDuty’s user id and name, not email. Join onpagerduty_users.user_id to get the email.
Escalation targets are a person or a schedule. target_type = 'user' pages that person directly; target_type = 'schedule' pages whoever the schedule says is on call. The people in each rotation are in pagerduty_schedule_users.
“Reachable” means a phone, SMS or push method and at least one notification rule. A user with only an email address still gets assigned incidents, but nobody’s phone rings.
Outbound endpoints are stored as hosts. Extensions, webhook subscriptions and workflow connections keep only the host they send to, never the full URL, which can contain a token.
Audit Trail is incremental. The first run reads up to 12 months back (PagerDuty keeps audit records for 12 months). Each later run reads from the newest stored record, in windows of 30 days. Records are never deleted from the table. Only the names of changed fields are kept, not their old and new values.
Large accounts. PagerDuty’s list endpoints stop after 10,000 rows. If a list is cut there, the run summary says TRUNCATED and names it.
Rate limits. An account API key may make 960 requests a minute. ConfigView uses at most a quarter of that, and waits for the reset whenever PagerDuty says the limit is nearly used up.
What isn’t collected
- Phone numbers, email addresses and device names of contact methods. Only how many of each kind
- Calendar feed URLs (they contain a token)
- Integration keys and inbound integration email addresses, which let anyone open incidents
- Extension configuration, webhook signing secrets and custom header values
- Full outbound URLs. Only the host
- Old and new values of changes in the Audit Trail
- Incidents, alerts, notes, status updates and postmortems