Auth header
Authorization: Bearer tsk_live_…The key needssites:read
Parameters
includeArchivedstringin queryoptionalInclude archived sites. Defaults to false.
One of
true,false
Example request
curl "https://app.tagsentry.ai/api/v1/sites" \ -H "Authorization: Bearer tsk_live_…"Response 200
dataarray of objectrequireddata[].idstringrequiredThe site's id. This is what every /v1/sites/{siteId} path takes.
data[].accountIdstringrequireddata[].domainstringrequireddata[].displayNamestringrequireddata[].regionstringrequiredWhere this site's consent records and tag events are stored. Fixed at creation and never editable -- data residency is not a setting you can flip.
One of
EU,USdata[].statusstringrequiredOne of
pending,active,archiveddata[].archivedAtstring | nullrequireddata[].createdAtstringrequiredISO-8601 timestamp, UTC.
data[].updatedAtstringrequiredISO-8601 timestamp, UTC.
limitintegerrequiredThe row cap applied to the underlying read.
truncatedbooleanrequiredTrue when the read came back at its cap. When true, this page is NOT the whole answer -- narrow the window. An account's site list has no read cap --
truncatedis always false here, and is present so the envelope's shape never varies by endpoint.truncationHintstringoptional
Example response
{ "data": [ { "id": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "accountId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "domain": "silverpine.example", "displayName": "Silverpine Supply", "region": "EU", "status": "pending", "archivedAt": "2026-09-26T14:02:00.000Z", "createdAt": "2026-09-26T14:02:00.000Z", "updatedAt": "2026-09-26T14:02:00.000Z" } ], "limit": 50, "truncated": false, "truncationHint": "…"}More about this endpoint
Archived sites are excluded unless you ask for them.
Errors401 · 403 · 500
401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI