REST API

Pull your monitoring data — hosts, NGINX metrics, alerts, and website checks — into your own dashboards, reports, and tooling. The API is read-only and returns JSON.

Pro feature
API access is included in the Pro plan and higher. Requests from Free and Starter accounts return 403 with an upgrade pointer.

Authentication

Authenticate with your account API key — the same key your Amplify agents use. Find it on the API Keys settings page. Pass it either as a Bearer token or in an X-Api-Key header:

curl -H "Authorization: Bearer YOUR_API_KEY" \
    https://amplify.getpagespeed.com/api/v2/hosts

# equivalent:
curl -H "X-Api-Key: YOUR_API_KEY" \
    https://amplify.getpagespeed.com/api/v2/hosts
Keep your key secret
The key grants read access to all monitoring data in your account and write access for agent metric uploads. Don't embed it in client-side code or public repositories.

Base URL & conventions

  • Base URL: https://amplify.getpagespeed.com/api/v2
  • All endpoints are GET and return application/json with snake_case keys.
  • Timestamps are RFC 3339 UTC (e.g. 2026-10-07T08:30:00Z).
  • Relative time windows use Nm, Nh, Nd, Nw (e.g. since=4h), clamped to your plan's data retention.

Rate limits

120 requests per minute per API key, with bursts of up to 30 requests. Exceeding the limit returns 429:

{"error": "rate_limited", "message": "rate limit exceeded: 120 requests/minute per API key"}

Errors

StatusCodeMeaning
400bad_requestMissing or invalid parameter
401unauthorizedMissing or invalid API key
403plan_requiredAPI access requires Pro or higher; response includes upgrade_url
404not_foundResource doesn't exist or belongs to another account
429rate_limitedRate limit exceeded — back off and retry

Error bodies always carry a machine-readable error code and a human-readable message.

OpenAPI specification

A machine-readable OpenAPI 3 spec is served at /api/v2/openapi.json — import it into Postman, Insomnia, or an SDK generator like openapi-generator to get a typed client in your language.

Endpoints

EndpointReturns
GET /accountYour plan, limits, usage, and rate limit
GET /hostsAll monitored hosts
GET /hosts/{uuid}One host
GET /hosts/{uuid}/metricsAvailable metric names, grouped by component
GET /hosts/{uuid}/metrics/seriesTime series for one or more metrics
GET /hosts/{uuid}/metrics/{name}/latestLatest value of one metric
GET /hosts/{uuid}/componentsDetected NGINX / PHP-FPM / MySQL / Varnish instances
GET /alertsAlert rules
GET /alerts/recentRecent alert events (site down + threshold firings)
GET /websitesMonitored websites with 24h aggregates
GET /websites/{id}Website summary (uptime, TTFB, TLS, recent checks)
GET /websites/{id}/checksCheck history

List hosts

curl -H "Authorization: Bearer YOUR_API_KEY" \
    https://amplify.getpagespeed.com/api/v2/hosts
{
  "hosts": [
    {
      "uuid": "6b8283f365bc4d9c82289f3ef23e5125",
      "hostname": "web1.example.com",
      "type": "system",
      "agent_version": "1.8.18",
      "last_seen": "2026-10-07T08:29:41Z",
      "online": true,
      "allowed": true,
      "server_kinds": ["nginx"],
      "tags": ["env:production", "client:acme"],
      "created_at": "2026-01-14T10:02:11Z"
    }
  ],
  "total": 1
}

online means the agent reported within the last 3 minutes. allowed is false for hosts beyond your plan's host limit (they keep their place but metrics aren't collected).

Metric time series

Discover metric names with GET /hosts/{uuid}/metrics, then fetch series. names is comma-separated; since is a relative window (default 1h):

curl -H "Authorization: Bearer YOUR_API_KEY" \
    "https://amplify.getpagespeed.com/api/v2/hosts/UUID/metrics/series?names=nginx.http.request.count,system.cpu.user&since=4h"
{
  "host_uuid": "6b8283f365bc4d9c82289f3ef23e5125",
  "since": "2026-10-07T04:30:00Z",
  "interval": 60,
  "series": {
    "nginx.http.request.count": [
      {"timestamp": "2026-10-07T04:30:00Z", "value": 1243},
      {"timestamp": "2026-10-07T04:31:00Z", "value": 1187}
    ],
    "system.cpu.user": [
      {"timestamp": "2026-10-07T04:30:00Z", "value": 12.4},
      {"timestamp": "2026-10-07T04:31:00Z", "value": 11.9}
    ]
  }
}

The sampling interval (seconds) auto-adjusts to the window: 60s up to 4 hours, 2 minutes up to a day, 5 minutes up to 2 days, 15 minutes up to a week, hourly beyond. Gaps return value: null.

Recent alert events

curl -H "Authorization: Bearer YOUR_API_KEY" \
    "https://amplify.getpagespeed.com/api/v2/alerts/recent?limit=50"
{
  "alerts": [
    {
      "type": "website_down",
      "id": 98231,
      "source_id": 42,
      "source_name": "acme.com",
      "message": "HTTP 503",
      "occurred_at": "2026-10-06T22:14:09Z"
    },
    {
      "type": "host_alert",
      "id": 7,
      "source_id": 7,
      "source_name": "High CPU",
      "host_uuid": "6b8283f365bc4d9c82289f3ef23e5125",
      "message": "system.cpu.user > 90 for 5 minutes",
      "occurred_at": "2026-10-06T21:03:55Z"
    }
  ]
}

Website check history

Without parameters: the newest 100 checks, newest first. With since: checks inside the window, oldest first. limit caps at 500:

curl -H "Authorization: Bearer YOUR_API_KEY" \
    "https://amplify.getpagespeed.com/api/v2/websites/42/checks?since=24h&limit=200"
{
  "website_id": 42,
  "total": 2,
  "checks": [
    {
      "id": 998877,
      "success": true,
      "status_code": 200,
      "ttfb_ms": 187,
      "http_version": "3",
      "tls_version": "TLS 1.3",
      "cert_days_remaining": 61,
      "checked_at": "2026-10-07T08:25:00Z",
      "dns_lookup": 4,
      "tls_handshake": 38,
      "security_score": 83,
      "has_hsts": true,
      "has_x_frame_options": true,
      "has_x_content_type_options": true,
      "has_csp": false,
      "has_referrer_policy": true,
      "has_permissions_policy": false,
      "cf_cache_status": "HIT",
      "cf_datacenter": "LIS"
    }
  ]
}

Data retention

Metric series and check history reach back as far as your plan retains data: 30 days on Pro, 90 days on Business. Requests for older windows are silently clamped to the retention boundary.

Need something the API doesn't expose?
Tell us what you're building — read endpoints are cheap to add.