---
title: "List Credentials"
method: GET
path: "/api/v1/service_principals/{service_principal_id}/credentials"
tags: ["Service Principal"]
---

# List Credentials

`GET /api/v1/service_principals/{service_principal_id}/credentials`

ListCredentials lists client credentials for a service principal.

## Path parameters

- `service_principal_id` string, required — The service principal ID to list credentials for.

## Response `200`

Successful response

- C1ApiServicePrincipalV1ServicePrincipalServiceListCredentialsResponse — The ServicePrincipalServiceListCredentialsResponse message.
  - `list` C1ApiServicePrincipalV1ServicePrincipalCredential[], nullable — The list field.
    - `allowSourceCidrs` string[], nullable — CIDR restrictions for this credential.
    - `clientId` string — The full client ID in format: ${cutename}@${tenant}.${installation}/spc
    - `createdAt` string, date-time, nullable
    - `displayName` string — The display name of the credential.
    - `expiresAt` string, date-time, nullable
    - `id` string — The unique ID of the credential (cutename format).
    - `lastUsedAt` string, date-time, nullable
    - `requireDpop` boolean — Whether DPoP proof-of-possession is required for this credential.
    - `scopedRoleIds` string[], nullable — Scoped role IDs for this credential (intersection with SP roles at token issuance).
    - `servicePrincipalId` string — The service principal user ID this credential belongs to.
  - `nextPageToken` string — The nextPageToken field.

## Changes

- **2026-08-21** `f2cf3228f366` — 3 breaking
  - the response property `list/items/createdAt` became nullable for the status `200`
  - the response property `list/items/expiresAt` became nullable for the status `200`
  - the response property `list/items/lastUsedAt` became nullable for the status `200`
- **2026-03-10** `7fa698b04b81` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/conductorone/apis/c1-api/changes/api/v1/service_principals/:service_principal_id/credentials/get.md)

---

[API](https://skmtc.dev/conductorone/apis/c1-api.md) · [All operations](https://skmtc.dev/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc.dev/conductorone/apis/c1-api/revisions/f76d07868c0c?raw)
