Docs/API REFERENCE/List websites

List websites

GET

List websites

Mobile app: paired via QR code from your account menu → Mobile App.

Returns every website the authenticated account owns or has team access to. Unlike the other v1 endpoints, this one is scoped to an account API key, not a website API key — it has no websiteId to authenticate against yet, since discovering the list of websites is the point.

How It Works

Account API keys are generated from the web app's "Mobile App" page as a QR code, then scanned once by the TrackFox mobile app to pair it. They grant read-only access (GET requests only) to every website the account can see, and are rejected by any endpoint that writes data.

Use Case

Call this first when building against an account API key, to discover which websiteId values are available before calling metadata or the other analytics endpoints.

Endpoint

GET https://trackfox.app/api/v1/websites

Authentication

This endpoint requires an account API key, generated from your account menu → Mobile App.

Authorization: Bearer tf_acct_your_account_api_key

Website-scoped keys (created from a website's Settings → API tab) are rejected with 401 invalid_token.

Response Format

{
  "websites": [
    {
      "id": "your_website_id",
      "name": "Example",
      "domain": "example.com",
      "primaryHostname": "www.example.com",
      "hostnames": ["example.com", "www.example.com"],
      "createdAt": "2026-01-10T12:00:00.000Z",
      "hasReceivedEvents": true,
      "theme": {
        "primaryColor": "#111827",
        "secondaryColor": "#6b7280"
      },
      "goal": {
        "type": "revenue",
        "customEventName": null,
        "property": null,
        "propertyValue": null
      },
      "settings": {
        "hideRevenue": false,
        "excludeAuthVisits": false,
        "excludedCountries": []
      }
    }
  ]
}

Error Responses

401 Unauthorized

The Authorization header is missing, malformed, contains an invalid API token, or contains a website-scoped key instead of an account key.

403 Forbidden

The request used a non-GET method. Account API keys are read-only.

500 Internal Server Error

An unexpected server error occurred.

Example Usage

cURL Request

curl "https://trackfox.app/api/v1/websites" \
  -H "Authorization: Bearer tf_acct_your_account_api_key"

Next Steps

Need help? Contact us for assistance.

Suggest features? We'd love your feedback