Activity feed across clients
The newest raw events across every client, newest first, in one call. Same columns as GET /client/v1/locations/events plus location_id and location_name. Filters apply before the limit, so exclude_system_events (drops $-prefixed SDK telemetry other than $pageview and $identify) cannot let telemetry crowd real events out. Events stamped more than 5 minutes in the future are left out.
curl -X GET "https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://mythic-analytics.gulp.workers.dev/client/v1/agency/events?location_ids=loc_abc123%2Cloc_def456&hours_back=24&limit=100&event_type=example_string&exclude_event_type=example_string&exclude_system_events=true')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"success": true,
"data": [
{
"location_id": "example_string",
"location_name": "John Doe",
"event": "$pageview",
"distinct_id": "example_string",
"user_id": "example_string",
"session_id": "example_string",
"timestamp": "2026-10-06 01:11:58",
"uuid": "example_string",
"properties": "example_string",
"url": "example_string",
"referrer": "example_string",
"browser": "example_string",
"os": "example_string",
"device_type": "example_string",
"utm_source": "example_string",
"utm_medium": "example_string",
"utm_campaign": "example_string",
"country": "USA",
"is_identified": 123,
"event_position_in_session": 42,
"session_event_count": 10,
"session_start": "example_string",
"session_duration_seconds": 42
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Too Many Requests",
"message": "Rate limit exceeded. Please try again later",
"code": 429,
"retryAfter": 3600
}
{
"error": "Error",
"message": "`stats_failed`, `health_failed`, or `usage_failed` — the upstream analytics query failed. Retry.",
"code": 502
}
/client/v1/agency/events
Target server for requests. Edit to use your own host.
Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
Lookback window in hours (1–720).
Rows to return (1–1000).
Only these event names, comma separated.
Drop these event names, comma separated.
true drops $-prefixed telemetry except $pageview and $identify.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
Query Parameters
Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
loc_abc123,loc_def456Lookback window in hours (1–720).
Rows to return (1–1000).
Only these event names, comma separated.
Drop these event names, comma separated.
true drops $-prefixed telemetry except $pageview and $identify.