ConfigCreate a tag template

Create a tag template

Create a template owned by this location. Only this location can see, edit, delete or assign it. It does nothing until assigned with POST /client/v1/config/tags, so there is no edge rebuild and no kv_sync. Agency key (ak_) or an mcp_ key with tags:write required.

curl -X POST "https://mythic-analytics.gulp.workers.dev/client/v1/config/tag-templates?location_id=example_string" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "name": "Hotjar",
  "type": "url",
  "src": "https://static.hotjar.com/c/hotjar-1234567.js?sv=6",
  "code": "example_string",
  "description": "example_string",
  "trigger_rules": {
    "version": 1,
    "operator": "AND",
    "rules": [
      {
        "type": "url_pattern",
        "operator": "contains",
        "value": "/checkout"
      }
    ]
  }
}'
{
  "success": true,
  "data": {
    "id": "123e4567-e89b-12d3-a456-426614174000",
    "owner": "mythic",
    "managed": true,
    "name": "Hotjar",
    "type": "url",
    "src": "https://static.hotjar.com/c/hotjar-1234567.js?sv=6",
    "code": "example_string",
    "description": "example_string",
    "trigger_rules": {
      "version": 1,
      "operator": "AND",
      "rules": [
        {
          "type": "url_pattern",
          "operator": "contains",
          "value": "/checkout"
        }
      ]
    },
    "created_at": "2024-12-25T10:00:00Z",
    "updated_at": "2024-12-25T10:00:00Z"
  }
}
POST
/client/v1/config/tag-templates
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Agency key (ak_) or location secret key (sk_). Writes require an agency key. Keys are server-side credentials — this surface serves no CORS headers on purpose. Scoped keys (mcp_) are accepted too and need the tags, snippets or transformers family the route belongs to. See Using an mcp_ key over HTTP.

Agency key (ak_) or location secret key (sk_). Writes require an agency key. Keys are server-side credentials — this surface serves no CORS headers on purpose. Scoped keys (mcp_) are accepted too and need the tags, snippets or transformers family the route belongs to. See Using an mcp_ key over HTTP.
query
location_idstring

Location to scope to. Required for ak_ keys (or send the X-Location-Id header); ignored for sk_.

Content-Typestring
Required

The media type of the request body

Options: application/json
namestring
Required
Max length: 200
typestring
Required
Options: url, inline
srcstring

Absolute https URL, loaded as an async script.

codestring

JavaScript run as a <script> body. Not HTML.

Max length: 65536
descriptionstring
Max length: 2000
trigger_rulesobject

Optional page/condition rules controlling where the tag or snippet fires. Omitted or null means everywhere.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Agency key (ak_) or location secret key (sk_). Writes require an agency key. Keys are server-side credentials — this surface serves no CORS headers on purpose. Scoped keys (mcp_) are accepted too and need the tags, snippets or transformers family the route belongs to. See Using an mcp_ key over HTTP.

Query Parameters

location_idstring

Location to scope to. Required for ak_ keys (or send the X-Location-Id header); ignored for sk_.

Body

application/json
namestring
Required
Example:
Hotjar
typestring
Required
Allowed values:urlinline
srcstring

Absolute https URL, loaded as an async script.

Example:
https://static.hotjar.com/c/hotjar-1234567.js?sv=6
codestring

JavaScript run as a \\<script\\> body. Not HTML.

trigger_rulesobject

Optional page/condition rules controlling where the tag or snippet fires. Omitted or null means everywhere.

Example:
{"version":1,"operator":"AND","rules":[{"type":"url_pattern","operator":"contains","value":"/checkout"}]}

Responses