> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Network request attribution by connection

> Aggregates the tenant's per-request network rows (network_requests_hourly) over the range, joined to the connection each request ran on, into a tree: each client service with its own sums; under it, the server services it reached, each with its own sums; and under each server, its locality rows, one per locality between one client zone and one server zone (client_az, server_az; empty when unknown), each with its own sums. A service seen in two zones is still one client or server row. Captured tag key/value pairs are aggregated at the client, at each server and at each locality row; aggregates of different keys overlap, since a request carrying two tag keys counts under both. Endpoints resolve to service names, and endpoints of one service merge into one row. group_by picks the tag keys aggregated (tag:<key>; empty means every key), group narrows to requests carrying exact tag key/value pairs, and filters (tag:<key>, dst_port, proto) are AND across dimensions and OR within one. Every node carries its previous-window sums and cost change. Limit and offset page the clients. Totals cover the same requests as the tree: those with a connection that carry a shown tag (one of the group_by keys, or any key when group_by is empty), so they equal the sum of every client



## OpenAPI

````yaml /api-reference/costgraph/openapi.json post /api/v1/tenant/network/requests/connections
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/tenant/network/requests/connections:
    post:
      tags:
        - network-requests
      summary: Network request attribution by connection
      description: >-
        Aggregates the tenant's per-request network rows
        (network_requests_hourly) over the range, joined to the connection each
        request ran on, into a tree: each client service with its own sums;
        under it, the server services it reached, each with its own sums; and
        under each server, its locality rows, one per locality between one
        client zone and one server zone (client_az, server_az; empty when
        unknown), each with its own sums. A service seen in two zones is still
        one client or server row. Captured tag key/value pairs are aggregated at
        the client, at each server and at each locality row; aggregates of
        different keys overlap, since a request carrying two tag keys counts
        under both. Endpoints resolve to service names, and endpoints of one
        service merge into one row. group_by picks the tag keys aggregated
        (tag:<key>; empty means every key), group narrows to requests carrying
        exact tag key/value pairs, and filters (tag:<key>, dst_port, proto) are
        AND across dimensions and OR within one. Every node carries its
        previous-window sums and cost change. Limit and offset page the clients.
        Totals cover the same requests as the tree: those with a connection that
        carry a shown tag (one of the group_by keys, or any key when group_by is
        empty), so they equal the sum of every client
      parameters:
        - description: Tenant ID
          name: X-CostGraph-Tenant-ID
          in: header
          required: true
          schema:
            type: string
        - description: Cost period; defaults to month_to_date
          name: period
          in: query
          schema:
            type: string
            enum:
              - month_to_date
              - last_7d
              - last_30d
              - calendar_month
              - custom
        - description: >-
            Closed calendar month in YYYY-MM format; required when
            period=calendar_month
          name: month
          in: query
          schema:
            type: string
        - description: Window start in RFC3339 format; required when period=custom
          name: start
          in: query
          schema:
            type: string
        - description: Window end in RFC3339 format; required when period=custom
          name: end
          in: query
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/networkrequests.ConnectionsQueryRequest'
        description: >-
          Tag keys to aggregate (group_by, tag:<key>), exact tag pairs to narrow
          to (group, bare keys), filters as dimension -> values, sort_by
          (cost|bytes), and client paging via limit (capped) and offset. A
          negative limit is unpaged. Every field is optional
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/responses.SuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: >-
                          #/components/schemas/networkrequests.ConnectionsQueryResult
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    networkrequests.ConnectionsQueryRequest:
      type: object
      properties:
        filter:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
        group:
          type: object
          additionalProperties:
            type: string
        group_by:
          type: array
          items:
            type: string
        limit:
          type: integer
          nullable: true
        offset:
          type: integer
          nullable: true
        sort_by:
          type: string
          enum:
            - cost
            - bytes
    responses.SuccessResponse:
      type: object
      required:
        - message
        - status
      properties:
        data: {}
        message:
          type: string
          example: some message
        status:
          type: string
          example: success
    networkrequests.ConnectionsQueryResult:
      type: object
      properties:
        changePct:
          type: number
        previous:
          $ref: '#/components/schemas/networkrequests.Totals'
        range:
          $ref: '#/components/schemas/networkrequests.Range'
        rows:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.Connection'
        totals:
          $ref: '#/components/schemas/networkrequests.Totals'
    responses.ErrorResponse:
      type: object
      required:
        - message
        - status
      properties:
        message:
          type: string
          example: some message
        status:
          type: string
          example: error
    networkrequests.Totals:
      type: object
      properties:
        attributed_cost_monthly:
          type: number
        req_bytes:
          type: number
        resp_bytes:
          type: number
    networkrequests.Range:
      type: object
      properties:
        end:
          type: string
        start:
          type: string
    networkrequests.Connection:
      type: object
      properties:
        changePct:
          type: number
        client:
          type: string
        previous:
          $ref: '#/components/schemas/networkrequests.Totals'
        servers:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.Server'
        tags:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.TagAggregate'
        totals:
          description: 'The client''s own sums: every request it made, each counted once.'
          allOf:
            - $ref: '#/components/schemas/networkrequests.Totals'
    networkrequests.Server:
      type: object
      properties:
        changePct:
          type: number
        localities:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.Locality'
        previous:
          $ref: '#/components/schemas/networkrequests.Totals'
        server:
          type: string
        tags:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.TagAggregate'
        totals:
          $ref: '#/components/schemas/networkrequests.Totals'
    networkrequests.TagAggregate:
      type: object
      properties:
        changePct:
          type: number
        key:
          type: string
        previous:
          $ref: '#/components/schemas/networkrequests.Totals'
        totals:
          $ref: '#/components/schemas/networkrequests.Totals'
        value:
          type: string
    networkrequests.Locality:
      type: object
      properties:
        changePct:
          type: number
        client_az:
          type: string
        locality:
          type: string
        previous:
          $ref: '#/components/schemas/networkrequests.Totals'
        server_az:
          type: string
        tags:
          type: array
          items:
            $ref: '#/components/schemas/networkrequests.TagAggregate'
        totals:
          $ref: '#/components/schemas/networkrequests.Totals'
  securitySchemes:
    BearerAuth:
      description: Enter "Bearer {token}"
      type: apiKey
      name: Authorization
      in: header

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.