TagSpy

GTM · GA4 · Firebase, from the files Google already publishes

See inside any Google tag setup.

Paste a Tag Manager container, a GA4 measurement ID, a Firebase App ID or a website URL. TagSpy reads the public configuration every browser and app downloads and turns it into a readable audit. No login, no Google API, nothing stored.

A Tag Manager container: tags, triggers, variables, vendors.

  • Read-only, public data
  • Results in about a second
  • JSON and GTM export
Live sample
GTM-WDC8G6read live from Google
Open the full report

How it works

  1. 1
    You paste an ID or a URL

    A GTM-, G-, GT- or Firebase App ID. A URL is scanned for the IDs it loads.

  2. 2
    We fetch what Google serves

    gtm.js, gtag/js or the app-measurement.com config. The same bytes every visitor gets.

  3. 3
    You read the decoded setup

    Names rebuilt, links resolved, vendors and IDs surfaced, consent made visible.

What you get

GTM: every tag, trigger and variable

Names rebuilt from types and identifiers, firing and exception triggers linked both ways, vendors and published IDs.

See an example →
GA4: the published stream settings

Key events, enhanced measurement, created and modified events, session timeout, cross-domain, signals, DMA and redaction.

See an example →
Firebase: the app's analytics config

Key events, quotas, consent per Google service, server-side tagging and the linked GA4 property.

See an example →
Consent visibility

Consent requirements per tag, the consent types each configuration references, and which custom scripts run ungated.

Stats and destinations

Which vendors receive data, what is paused, unused or custom code, and every published account ID.

Code and raw data

Custom HTML with copy, decoded parameters, a Tag Manager import file and JSON for every report.

Questions people ask

Is this legal?+

Yes. A published web container, a Google tag loader and a Firebase app config are public files that Google's own scripts download on every visit or app start. TagSpy automates reading them and touches nothing behind a login.

Can you see unpublished changes or names?+

No. Only the live published version is public, and Google strips the names you typed in the interface. Names here are rebuilt from types and identifiers.

Why did a URL find nothing?+

Some sites load Tag Manager after consent, through a proxy, or from a script we do not execute. Paste the ID directly; it is in the page source.

Do you store what I look up?+

Results are cached in memory for fifteen minutes to avoid re-downloading from Google, then dropped. Your recent IDs live only in your browser.

Which containers cannot be read?+

Server-side, AMP and mobile GTM containers are not served as gtm.js. Firebase apps without Analytics enabled have no published config.

Are you affiliated with Google?+

No. Google Analytics, Firebase and Google Tag Manager are trademarks of Google LLC.

Try it on a real container

Datadog's public container has 115 tags, 93 triggers and 26 vendors. See what an audit looks like before you paste your own.

Open GTM-WDC8G6