Endpoint referenceScripts
Script inventory
GET
bearerAuthheader
AuthorizationBearer <token>API token created in Settings → API. Scopes are attached to the token; each operation lists its required scope in x-scope.
org_id?stringPartners only (orgs:manage): act on this child organization. May also be sent as org_id in JSON bodies.
Format
uuidstore_id?stringFilter by store
Format
uuidstatus?stringValue in
"trusted""needs_review""suspicious""malicious""authorized""blocked"type?stringValue in
"first_party""known_third""unknown"integrity_status?stringValue in
"match""mismatch""pending""monitored""blocked"category?stringlimit?integerRange
1 <= value <= 100Default
50cursor?stringOpaque cursor from next_cursor
Scripts ordered by first_seen_at desc
application/json- response
data?array<>next_cursor?string|nullcurl -X GET "https://example.com/scripts"{ "data": [ { "id": "b1c2d3e4-5555-4666-8777-888899990000", "store_id": "0c1d2e3f-1111-4222-8333-444455556666", "src": "https://www.googletagmanager.com/gtm.js?id=GTM-ABC1234", "type": "known_third", "category": "tag_manager", "status": "needs_review", "integrity_status": "monitored", "current_hash": null, "authorized_hash": null, "hash_source": "none", "sri_hash": null, "integrity_attr": false, "size_bytes": null, "vendor_id": "googletagmanager.com", "gtm_container": "GTM-ABC1234", "authorization_method": null, "authorized_by": null, "justification": null, "policy_id": null, "policy_version": null, "reviewed_at": null, "expires_at": null, "review_due_at": null, "first_seen_at": "2026-09-20T08:00:00.000Z", "last_seen_at": "2026-09-27T09:58:00.000Z", "last_verified_at": null, "last_hash_change_at": null } ], "next_cursor": null}