Per-location contract coverage
One row per location: how many event contracts are declared, whether the daily contract-alert webhook is configured, and when the last alert fired. A location with zero contracts has no event-shape monitoring at all; one with contracts but no webhook finds out about breakage only when someone runs a check by hand.
curl -X GET "https://mythic-analytics.gulp.workers.dev/client/v1/agency/contracts/summary?location_ids=loc_abc123%2Cloc_def456" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://mythic-analytics.gulp.workers.dev/client/v1/agency/contracts/summary?location_ids=loc_abc123%2Cloc_def456"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://mythic-analytics.gulp.workers.dev/client/v1/agency/contracts/summary?location_ids=loc_abc123%2Cloc_def456", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://mythic-analytics.gulp.workers.dev/client/v1/agency/contracts/summary?location_ids=loc_abc123%2Cloc_def456", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://mythic-analytics.gulp.workers.dev/client/v1/agency/contracts/summary?location_ids=loc_abc123%2Cloc_def456')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"success": true,
"data": [
{
"location_id": "loc_abc123",
"name": "Acme Dental",
"contracts_declared": 7,
"alert_webhook_configured": true,
"last_alert_at": "2024-12-25T10:00:00Z"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Unprocessable Entity",
"message": "The request was well-formed but contains semantic errors",
"code": 422,
"details": [
{
"field": "password",
"message": "Password must be at least 8 characters long"
}
]
}
{
"error": "Too Many Requests",
"message": "Rate limit exceeded. Please try again later",
"code": 429,
"retryAfter": 3600
}
/client/v1/agency/contracts/summary
Target server for requests. Edit to use your own host.
Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
Query Parameters
Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
loc_abc123,loc_def456