/sites/{siteId}/gtmRead the connected Tag Manager inventory
The containers connected to this site, whether we can write to each, and the container's tags as our last scan read them.
Auth header
Authorization: Bearer tsk_live_…The key needsgtm:read
Parameters
siteIdstringin pathrequiredThe site id, from GET /v1/sites.
Example request
curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/gtm" \ -H "Authorization: Bearer tsk_live_…"Response 200
containersarray of objectrequiredOne entry per live container, the one shown first first. Disconnected containers are left out.
containers[].connectionIdstringrequiredcontainers[].gtmContainerPublicIdstringrequiredcontainers[].containerNamestringrequiredcontainers[].statestringrequiredcontainers[].accessLevelstringrequiredcontainers[].canWritebooleanrequiredcontainers[].readAtstring | nullrequiredWhen our last scan read this container. Null if never.
primarystring | nullrequiredThe public id of the container shown first, or null. Kept for clients written before
containers.connectionsarray of objectrequiredconnections[].idstringrequiredconnections[].isPrimarybooleanrequiredconnections[].statestringrequiredconnections[].containerNamestringrequiredconnections[].gtmContainerPublicIdstringrequiredconnections[].accessLevelstringrequiredconnections[].canWritebooleanrequiredconnections[].lastScanAtstring | nullrequiredtagsarray of objectrequiredThe container's tags as our last scan read them, not a live read of Google.
tags[].idstringrequiredtags[].displayNamestringrequiredtags[].gtmContainerPublicIdstring | nullrequiredtags[].gtmTagIdstring | nullrequiredtags[].gtmTagTypestring | nullrequiredtags[].vendorDomainstring | nullrequiredtags[].lastSeenAtstringrequiredISO-8601 timestamp, UTC.
readAtstring | nullrequiredWhen a scan last read the primary container. Null if never.
Example response
{ "containers": [ { "connectionId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "gtmContainerPublicId": "GTM-ABC1234", "containerName": "…", "state": "…", "accessLevel": "…", "canWrite": false, "readAt": "2026-09-26T14:02:00.000Z" } ], "primary": "…", "connections": [ { "id": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "isPrimary": false, "state": "…", "containerName": "…", "gtmContainerPublicId": "GTM-ABC1234", "accessLevel": "…", "canWrite": false, "lastScanAt": "2026-09-26T14:02:00.000Z" } ], "tags": [ { "id": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "displayName": "Silverpine Supply", "gtmContainerPublicId": "GTM-ABC1234", "gtmTagId": "12", "gtmTagType": "…", "vendorDomain": "silverpine.example", "lastSeenAt": "2026-09-26T14:02:00.000Z" } ], "readAt": "2026-09-26T14:02:00.000Z"}More about this endpoint
Served from what we stored, never a live call to Google: the Tag Manager API quota is shared by every customer.
READ ONLY. This version of the API has no Tag Manager write: gtm:write is a scope with no endpoint yet. Container changes go through the dashboard, where a person approves them.
Errors401 · 403 · 404 · 429 · 500
401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.429A rate limit or quota was exceeded. The body names WHICH one.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI