GET /api/hotspots-risk-events

Read-only access to the top hotspots from each repository analyzed on hotspots.dev: the highest-risk files from the analysis behind each post, with their risk score, tier and detected patterns. Public — it only exposes already-published analysis data. Want trend history and change alerts? Join the waitlist.

What's in the data

Request

GET /api/hotspots-risk-events?repo=&since=&risk_tier=&limit=&cursor=
paramtypenotes
repostringe.g. vuejs/core. Required.
sincestringISO 8601 timestamp
risk_tierenumlow | moderate | high | critical
limitintpage size, 1–200 (default 50)
cursorstringopaque, from next_cursor

Response

{
  "events": [
    {
      "event_id": "evt_01h...",
      "repo": "vuejs/core",
      "file": "src/reactivity/effect.ts",
      "commit_sha": "a1b2c3d",
      "risk_score": 26.78,
      "risk_tier": "high",
      "delta": null,
      "patterns": ["god_function"],
      "collected_at": "2026-09-15T02:10:55Z",
      "timestamp": "2026-09-15T02:11:00Z"
    }
  ],
  "next_cursor": "...",
  "waitlist_url": "https://hotspots.dev/api-access",
  "notice": "Trend history, change alerts and on-demand repos are coming — join the waitlist."
}

Not yet included

Rate limits

Public and unauthenticated — no signup required — but rate-limited in two tiers: 30 requests/minute per IP by default, or 300 requests/minute per API key for a free account. Get a key with POST /api/signup ({ "email": "you@example.com" }) and send it back as Authorization: Bearer <api_key>. An invalid or missing key falls back to the per-IP tier rather than being rejected — this is a rate-limit tier, not an access boundary, since the underlying data is public either way.

Requests are logged (endpoint, query parameters, country, user agent, and hashed key/IP identifiers) to monitor usage and abuse.

Errors

Validation failures return 400 with { "error": "invalid_parameter", "message", "field", "docs" }. A misconfigured or unreachable query backend returns 502/503. Exceeding the rate limit returns 429.

Questions: stephen@stephencollins.tech