Preview - List commands active within a time range

Preview: This endpoint is currently in a preview state and is subject to breaking changes without warning.

Preview endpoint. This endpoint is in preview: its request and response shapes may change without a version increment. A v2 of this API is planned to supersede it, targeting 2026-11.

Returns the commands that recorded any activity in the time range across all tools, each annotated with its event_count, device_count, and the highest observed severity over the range, ordered by the optional metric parameter (defaults to event_count).
Backed by device_tool_command_hourly. A window with no command activity returns 200 with an empty commands array.
The optional, mutually exclusive min_severity (floor) and severity (exact match) query parameters filter the underlying hourly rows before aggregation, so the returned counts and severity reflect only that activity.
Note: device_count is a distinct count and is NOT additive: it does not sum across commands (a device that ran more than one command is counted under each).

Required Permissions: ai-visibility:read

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
date-time

Absolute inclusive UTC start timestamp (RFC3339). Must be paired with end; cannot be combined with range.

date-time

Absolute exclusive UTC end timestamp (RFC3339). Must be paired with start; cannot be combined with range.

string
^\s*(?:\d+w)?\s*(?:\d+d)?\s*(?:\d+h)?\s*$

Relative look-back duration composed of optional weeks (w), days (d), and hours (h) segments, in that order (e.g. 24h, 7d, 1w, 1w2d3h). Resolved server-side to [now-range, now). Mutually exclusive with start/end. Defaults to 24h when no time parameters are supplied.

string
Defaults to UTC

IANA timezone name (e.g. America/New_York, Europe/Paris) used to express the resolved range. For the stats endpoints it aligns day and week bin boundaries to that timezone's local midnight / start-of-week before the window is normalized to UTC for querying. Has no effect on endpoints that do not bucket by time. Defaults to UTC when omitted.

string
enum
Defaults to event_count

Single metric to order the grouped results by. Allowed values: event_count, device_count. Defaults to event_count. Both metrics are always returned on each row regardless of this value.

Allowed:
integer
≥ 1
Defaults to 50

Max number of grouped rows to return (top-N by the ordering metric). Defaults to 50 when omitted.

integer
≥ 1
Defaults to 1

1-indexed page number used together with limit to page through results. The row offset is computed as (page - 1) * limit. Defaults to 1 when omitted. A page past the end of the result set returns an empty list.

string
enum
Defaults to desc

Sort direction for grouped results by the metric.

Allowed:
integer
enum

Keep only command rows whose own severity is at least this value before aggregation (0=informational, 1=low, 2=medium, 3=high). The filter is applied to the underlying hourly rows, so the reported severity (MAX over the surviving rows) and the event_count / device_count totals reflect only activity at or above this level. Mutually exclusive with severity.

Allowed:
integer
enum

Keep only command rows whose own severity is exactly this value before aggregation (0=informational, 1=low, 2=medium, 3=high). Unlike min_severity, this is an equality match rather than a floor. The filter is applied to the underlying hourly rows, so the reported severity and the event_count / device_count totals reflect only activity at exactly this level. Mutually exclusive with min_severity.

Allowed:
Headers
uuid
required
^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$

The environment UUID identifier.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
OAuth2
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json