Agency RollupsActivity feed across clients

Activity feed across clients

The newest raw events across every client, newest first, in one call. Same columns as GET /client/v1/locations/events plus location_id and location_name. Filters apply before the limit, so exclude_system_events (drops $-prefixed SDK telemetry other than $pageview and $identify) cannot let telemetry crowd real events out. Events stamped more than 5 minutes in the future are left out.

curl -X GET "https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN"
{
  "success": true,
  "data": [
    {
      "location_id": "example_string",
      "location_name": "John Doe",
      "event": "$pageview",
      "distinct_id": "example_string",
      "user_id": "example_string",
      "session_id": "example_string",
      "timestamp": "2026-10-06 01:11:58",
      "uuid": "example_string",
      "properties": "example_string",
      "url": "example_string",
      "referrer": "example_string",
      "browser": "example_string",
      "os": "example_string",
      "device_type": "example_string",
      "utm_source": "example_string",
      "utm_medium": "example_string",
      "utm_campaign": "example_string",
      "country": "USA",
      "is_identified": 123,
      "event_position_in_session": 42,
      "session_event_count": 10,
      "session_start": "example_string",
      "session_duration_seconds": 42
    }
  ]
}
GET
/client/v1/agency/events
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
query
location_idsstring

Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.

query
hours_backinteger

Lookback window in hours (1–720).

Min: 1 • Max: 720
query
limitinteger

Rows to return (1–1000).

Min: 1 • Max: 1000
query
event_typestring

Only these event names, comma separated.

query
exclude_event_typestring

Drop these event names, comma separated.

query
exclude_system_eventsboolean

true drops $-prefixed telemetry except $pageview and $identify.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Query Parameters

location_idsstring

Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.

Example:
loc_abc123,loc_def456
hours_backinteger

Lookback window in hours (1–720).

limitinteger

Rows to return (1–1000).

event_typestring

Only these event names, comma separated.

exclude_event_typestring

Drop these event names, comma separated.

exclude_system_eventsboolean

true drops $-prefixed telemetry except $pageview and $identify.

Responses

successboolean
dataarray