How TagSpy works
A published Google Tag Manager web container is a public JavaScript file at https://www.googletagmanager.com/gtm.js?id=GTM-XXXXXXX. The first statement of that file is a JSON object with every tag, trigger condition, rule and variable in the live version. TagSpy downloads it on the server, decodes it and renders the result. Nothing behind a Tag Manager login is touched: no workspaces, drafts, folders, notes, user-given names or permissions.
API
GET /api/gtm/GTM-XXXXXXX— normalized JSON: tags, triggers, variables, stats, consent.GET /api/gtm/GTM-XXXXXXX?format=gtm— Tag Manager import file (exportFormatVersion 2).GET /api/gtm/GTM-XXXXXXX?refresh=1— bypass the 15 minute cache.POST /api/resolvewith{ "url": "https://example.com" }— list the containers and Google tag IDs a page loads.
What the names mean
Google strips the names you give things in the Tag Manager UI when it publishes. TagSpy rebuilds a name from the entity type and its most identifying parameter, for example GA4 Event — purchase or Page View — URL (HOST) equals example.com. When two entities would get the same name, the numeric ID is appended.
Limits
- Only web containers. Server, AMP and app containers are not served as gtm.js.
- Only the published version. Google exposes one version publicly.
- URL resolution reads the page HTML; containers injected after consent or through a proxy are not found. Paste the ID instead.
- Consent findings are a checklist. Enforcement can happen outside the container.