TagSpy

How TagSpy works

A published Google Tag Manager web container is a public JavaScript file at https://www.googletagmanager.com/gtm.js?id=GTM-XXXXXXX. The first statement of that file is a JSON object with every tag, trigger condition, rule and variable in the live version. TagSpy downloads it on the server, decodes it and renders the result. Nothing behind a Tag Manager login is touched: no workspaces, drafts, folders, notes, user-given names or permissions.

API

  • GET /api/gtm/GTM-XXXXXXX — normalized JSON: tags, triggers, variables, stats, consent.
  • GET /api/gtm/GTM-XXXXXXX?format=gtm — Tag Manager import file (exportFormatVersion 2).
  • GET /api/gtm/GTM-XXXXXXX?refresh=1 — bypass the 15 minute cache.
  • POST /api/resolve with { "url": "https://example.com" } — list the containers and Google tag IDs a page loads.

What the names mean

Google strips the names you give things in the Tag Manager UI when it publishes. TagSpy rebuilds a name from the entity type and its most identifying parameter, for example GA4 Event — purchase or Page View — URL (HOST) equals example.com. When two entities would get the same name, the numeric ID is appended.

Limits

  • Only web containers. Server, AMP and app containers are not served as gtm.js.
  • Only the published version. Google exposes one version publicly.
  • URL resolution reads the page HTML; containers injected after consent or through a proxy are not found. Paste the ID instead.
  • Consent findings are a checklist. Enforcement can happen outside the container.