hosting

GET /v1/sites/{siteId}/apm

Ranked transactions, ranked hotspots and the hourly timeline for a site.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/apm \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Stored, aggregated PHP profiling: which **pages** cost the most server time, which **plugin, PHP function or SQL query** is eating it, and how the site's PHP execution time has moved hour by hour. ⭐ Read from rows, not from the machine. The sibling `…/performance/slow-requests` surface opens an SSH session to the worker box on every call; this one is a database query, which is why it can be rendered on a customer-facing tab without a §2.16 problem. ⛔ **An empty payload is a `200` WITH A REASON.** `enrolment_state` says which of four things happened — `unknown` (not collected yet), `enrolled` (collected, and the site was genuinely quiet), `refused` (the server would not start tracing), `unsupported` (hosting that cannot trace). A surface that cannot tell a quiet site from a feature that is switched off was the live state of the fleet on 2026-09-03: one of two boxes had zero sites enrolled and every screen said "nothing traced yet". Requires `sites.view` and the `request_profiling` entitlement, which is included on every product line. No visitor IP addresses appear in the response — the field does not exist at any layer beneath this one.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).
hours (query)integerNoHow far back to aggregate (1–2160, default 24). Clamped rather than refused: a junk value answers the question that was asked with the default period.
limit (query)integerNoHow many ranked rows per table (1–50, default 10).

Response

NameTypeRequiredWhat it is
tracingbooleanYesWhether the server is currently profiling this site.
enrolment_statestring<unknown, enrolled, refused, unsupported>YesWhy there may be no data. `unknown` — not collected yet. `enrolled` — collected, and the site was genuinely quiet. `refused` — the server would not start profiling. `unsupported…
enrolment_detailstringYesThe server's own sentence when it refused; empty otherwise.
last_collected_atstringYesWhen we last harvested this site, or null if never.
window_hoursintegerYesThe period these aggregates cover.
p95_duration_msintegerYesThe 95th percentile of PHP time across EVERY request traced for this site in the window, in milliseconds. ⚠️ This is the customer's OWN traffic. It is a different quantity from…
p95_sample_countintegerYesHow many requests `p95_duration_ms` was computed over. Shipped WITH it, always: a p95 over 30 requests and one over 30,000 are indistinguishable on screen otherwise (§2.44).
transactionsSiteApmTransaction[]YesPages ranked by total PHP time, heaviest first.
hotspotsSiteApmHotspot[]YesPlugins, functions and queries ranked by total PHP time.
timelineSiteApmTimelinePoint[]YesPHP execution time by hour, oldest first.

Errors this endpoint can return

401 · 403 · 404 · 422 · 429