Preview: This endpoint is currently in a preview state and is subject to breaking changes without warning.
Preview endpoint. This endpoint is in preview: its request and response shapes may change without a version increment. A v2 of this API is planned to supersede it, targeting 2026-11.
For a single tool, returns event_count and device_count per distinct command within the time range, ordered by the optional metric parameter (defaults to event_count). Each row is annotated with the highest observed severity for that command in the window.
A tool with no command activity in the window returns 200 with an empty results array; this endpoint does not distinguish an unknown tool_id.
Backed by device_tool_command_hourly (separate from the launcher-grain table), so per-command totals are computed independently of the per-launcher and per-tool views.
Note: device_count here is per command and remains a distinct count, so the per-command values do not sum to the tool's overall device_count - a device that issued more than one command is counted under each.
The optional, mutually exclusive min_severity (floor) and severity (exact match) query parameters filter the underlying hourly rows before aggregation, so the returned counts and per-command severity reflect only that activity. When both are omitted the filter defaults to 0 (informational), which keeps every row.
Required Permissions: ai-visibility:read
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||