List a project's access tokens
Changed onLists the project's access tokens, newest first. Secrets are never returned: only a hash is stored, so a token's value exists solely in the response to the create call.
Only tokens that can still authenticate are returned by default, so revoked and expired ones are hidden. Pass include_revoked=true to see them, which is how you find out what a key did before it stopped working.
Requires a platform token. A project access token cannot manage project access tokens, so a leaked credential cannot enumerate or replace itself.
Request
- Base URL: https://api.volcano.dev
- URL: https://api.volcano.dev/projects/{id}/access-tokens
- Auth: HTTP bearer
Path parameters
Project ID
Query parameters
Page number (1-indexed) for offset pagination. Declares no schema default so the request validator does not inject one: handlers that omit page see it unset (nil) and default to 1 in code, while cursor-first endpoints (e.g. the project deployments feed) can detect its absence to stay in keyset/search mode. Supplying page selects offset pagination.
Number of items per page (max 100)
Case-insensitive substring match on the resource name. See the endpoint description for supported pagination modes.
Include tokens that can no longer authenticate — both revoked and expired ones.
Response
Successful response
Changes
- ○
endpoint added
- ○