---
title: "Read an API Key"
method: GET
path: "/iam/v2/api-keys/{id}"
tags: ["API Keys (iam/v2)"]
---

# Read an API Key

`GET /iam/v2/api-keys/{id}`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to read an API key.

## Path parameters

- `id` string, required

## Response `200`

API Key.

- object — `ApiKey` objects represent access to different parts of Confluent Cloud. Some types of API keys represent access to a single cluster/resource such as a Kafka cluster, Schema Registry cluster or a ksqlDB cluster. Cloud API Keys represent access to resources within an organization that are not tied to a specific cluster, such as the Org API, IAM API, Metrics API or Connect API. Tableflow API keys and Global API keys are not tied to a specific cluster. The API allows you to list, create, update and delete your API Keys. Related guide: [API Keys in Confluent Cloud](https://docs.confluent.io/cloud/current/client-apps/api-keys.html). ## The API Keys Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.ApiKey" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `apikeys_per_org` | API Keys in one Confluent Cloud organization |
  - `api_version` 'iam/v2', required — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'ApiKey', required — Kind defines the object this REST resource represents.
  - `id` string, required — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `spec` object, required — The desired state of the Api Key
    - `secret` string — The API key secret. Only provided in `create` responses, not in `get` or `list`.
    - `display_name` string — A human readable name for the API key
    - `description` string — A human readable description for the API key
    - `expires_at` string, date-time — The date and time at which this API key will expire. It is represented in RFC3339 format and is in UTC.
    - `owner` object, required — The owner to which this belongs. The owner can be one of iam.v2.User, iam.v2.ServiceAccount.
      - `id` string, required — ID of the referred resource
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource
    - `resource` object, nullable — The resource associated with this object. The resource can be one of Kafka Cluster ID (example: lkc-12345), Schema Registry Cluster ID (example: lsrc-12345), ksqlDB Cluster ID (example: lksqlc-12345), or Flink (Environment + Region pair, example: env-abc123.aws.us-east-2). May be null or omitted if not associated with a resource. For creating Cloud API key, resource id should be `CLOUD`, for creating Tableflow API key, resource id should be `TABLEFLOW`, for creating Global API key, resource id should be `GLOBAL`. The resource id is case-insensitive. [Learn more in Authentication](https://docs.confluent.io/cloud/current/api.html#section/Authentication). Note - Flink is in the [Preview lifecycle stage](https://docs.confluent.io/cloud/current/api.html#section/Versioning/API-Lifecycle-Policy)
      - `id` string, required — ID of the referred resource
      - `environment` string — Environment of the referred resource, if env-scoped
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `403` — The access credentials were considered insufficient to grant access
- `404` — Not Found
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
