Statistics of the last 24 hours
const url = 'https://example.com/api/v1/stats';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/stats \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3EProcesses per state, agreements, evidence entries and the data plane’s requests of the last 24 hours (per hour, errors, refusals, p50 and p95), with the health of the components and the last heartbeat to the authority. The dashboard shows it.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
/api/v1/stats: documents the JSON built in [collect_stats] and [stats].
object
Negotiations per state.
object
Transfers per state.
object
The last 24 hours, per hour.
Requests in one period (an hour or a minute).
object
object
Answers with status 4xx or 5xx, including what the data plane refused itself.
Hours with requests: hour, count.
object
As in /healthz.
object
Example generated
{ "negotiations": { "additionalProperty": 1 }, "transfers": { "additionalProperty": 1 }, "agreements": 1, "evidence_entries": 1, "dataplane_series": [ { "at": "2026-04-15T12:00:00Z", "requests": 1, "errors": 1 } ], "dataplane": { "requests_24h": 1, "errors_24h": 1, "refused_24h": 1, "p50_ms": 1, "p95_ms": 1, "last_request_at": "2026-04-15T12:00:00Z", "series": [ {} ] }, "health": { "additionalProperty": "example" }, "last_heartbeat_at": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}