Skip to content

Browse cached entries

GET
/domains/{domain}/cache/keys
curl --request GET \
--url 'https://api.nsin.cloud/domains/example.com/cache/keys?limit=100&offset=0&sort=size&dir=asc' \
--header 'Authorization: Bearer <token>'

A page of the domain’s individual cached objects.

Note the two host/path pairs on each row: host and path are the human-readable request URL, while hostname (the storage namespace) and store_path are the stored identity you must echo back when purging a specific row. Requires domain.view.

domain
required
string

The domain name (for example example.com) — not a numeric id.

Example
example.com
limit
integer
default: 100 >= 1 <= 500
offset
integer
0
sort
string
Allowed values: size host hostname path expires_at cached_at

Sort column. Anything else falls back to cached_at.

dir
string
Allowed values: asc desc
hostname
string

Exact match on the storage namespace host.

host
string

Match on the request host — substring, or a * wildcard.

node
string

Edge node that cached the entry. Case-sensitive as stored.

path
string

Match on the request path — substring, or a * wildcard.

A page of cached entries.

Media type application/json
object
rows
Array<object>

One cached object. host/path/query are the readable request URL; hostname/store_path/key_hash/node are the stored identity to echo back when purging this specific row.

object
domain_id
integer
domain
string
host

Exact request host, e.g. sub.example.com.

string
path

Exact request path, e.g. /assets/app.js.

string
query

Raw query string, without the leading ?.

string
variant

Cache-key suffix separating this entry from other variants of the same URL (device, image format, CORS origin, …). Empty for the plain variant.

string
method
string
node

Edge node that cached it.

string
hostname

Storage namespace host — *.example.com for a wildcard record.

string
store_path

Raw stored path. Needed for purging; not for display.

string
key_hash
string
cache_key
string
l2_key

Reconstructed storage key, for debugging.

string
size

Bytes.

integer
cached_at
string format: date-time
expires_at
string format: date-time
total
integer
limit
integer
offset
integer
Example generated
{
"rows": [
{
"domain_id": 1,
"domain": "example",
"host": "example",
"path": "example",
"query": "example",
"variant": "example",
"method": "example",
"node": "example",
"hostname": "example",
"store_path": "example",
"key_hash": "example",
"cache_key": "example",
"l2_key": "example",
"size": 1,
"cached_at": "2026-04-15T12:00:00Z",
"expires_at": "2026-04-15T12:00:00Z"
}
],
"total": 1,
"limit": 1,
"offset": 1
}

Missing, malformed, revoked or expired API key, or a key whose owning user row is gone. A key whose owning account has merely been deactivated is not this: that is 403 with code: account_suspended, because the credential itself is intact and re-issuing it changes nothing.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example invalidKey
{
"error": "invalid API key"
}

No such domain, or it is not visible to this account. Domains you cannot access are reported as not found rather than forbidden.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Example
{
"error": "read-only API key"
}

The key exceeded its request budget (300 requests per minute by default).

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example limited
{
"error": "rate limit exceeded"
}

The cache registry is temporarily unreachable.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Example
{
"error": "read-only API key"
}