config_config) from every core server, one row per key and server, and says whether the servers agree on each key.include-secrets=yes requires Super User.config_config is held by each core server and kept in step over the service bus (SBUS), so the useful question is whether the servers agree. Every row carries config-server, and one row comes back per key and server. A server that does not answer within 3 seconds is left out. Send local-only=yes to read only the server that takes the request; GET /nsconfigs has the opposite default.limit and start apply to each server, so a cluster of 3 servers can return up to 3 times limit rows. The response is grouped by key, then server. For names without values, append /list; for one server's total, append /count.config-in-sync compares the servers in this response:yes: every expected server answered and all hold the key with the same value. Compare config-servers-reporting with config-servers-expected. A cluster whose inventory holds exactly one server gives yes when that server answers.no: the values differ, or some servers hold the key and others do not, and the difference is visible in this response. A deliberate config-server override looks the same as drift.unknown: agreement cannot be shown. A server did not answer, local-only=yes was sent, an inventory entry is not a valid hostname, the values are masked, one server masked the value and another did not, the values differ only as text (1.10 and 1.1), or a key is missing from a server whose page was full or started past start=0.not-expected: the key describes the server rather than the platform and is meant to differ. NsNmsconfigPerServer lists these keys; by default SystemStartTime, NatWanIP, and Send503ToAll.include-secrets=yes compares the stored values instead of masks, so masked keys get a definite answer.password, secret, key, token, auth, smtp, license, cert, or a similar keyword is masked and carries config-value-redacted: yes. A value of 8 characters or fewer becomes the same number of asterisks (at least 4); a longer one keeps its first 2 and last 2 characters. Two settings narrow the match:NsNmsconfigMaskExempt names keys that are never masked. By default it covers SMTP_HOST, SMTP_PORT, SMTP_UID, SMTP_USER, and SMTP_USERNAME, so SMTP_PWD is the SMTP setting that stays hidden.NsNmsconfigMaskMinLength (default 4) returns shorter values in the clear, so a yes or no under a key that only matches by accident stays readable.config-value is returned exactly as stored, so a leading or trailing zero survives.GET /nmsconfig/servers.Authorization: Bearer ********************curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/nmsconfig?config-name=SMTP_HOST&config-geo=no&local-only=yes&include-secrets=yes&limit=100&start=undefined&sort=config-timestamp-datetime%20DESC&config-value=0123456' \
--header 'Authorization: Bearer <token>'CleanUpDayOfWeek agrees; SMTP_PWD is masked, so agreement cannot be shown.[
{
"config-name": "CleanUpDayOfWeek",
"config-value": "0123456",
"config-geo": "no",
"config-timestamp-datetime": "2026-09-01T14:30:00+00:00",
"config-server": "core1.example.com",
"config-in-sync": "yes",
"config-servers-reporting": 2,
"config-servers-expected": 2
},
{
"config-name": "CleanUpDayOfWeek",
"config-value": "0123456",
"config-geo": "no",
"config-timestamp-datetime": "2026-09-01T14:30:02+00:00",
"config-server": "core2.example.com",
"config-in-sync": "yes",
"config-servers-reporting": 2,
"config-servers-expected": 2
},
{
"config-name": "SMTP_PWD",
"config-value": "Ex*********01",
"config-geo": "no",
"config-timestamp-datetime": "2026-08-20T09:15:00+00:00",
"config-server": "core1.example.com",
"config-value-redacted": "yes",
"config-in-sync": "unknown",
"config-servers-reporting": 2,
"config-servers-expected": 2
},
{
"config-name": "SMTP_PWD",
"config-value": "Ex*********01",
"config-geo": "no",
"config-timestamp-datetime": "2026-08-20T09:15:01+00:00",
"config-server": "core2.example.com",
"config-value-redacted": "yes",
"config-in-sync": "unknown",
"config-servers-reporting": 2,
"config-servers-expected": 2
}
]