Project Access Tokens

List a project's access tokens

Changed on

Lists the project's access tokens, newest first. Secrets are never returned: only a hash is stored, so a token's value exists solely in the response to the create call.

Only tokens that can still authenticate are returned by default, so revoked and expired ones are hidden. Pass include_revoked=true to see them, which is how you find out what a key did before it stopped working.

Requires a platform token. A project access token cannot manage project access tokens, so a leaked credential cannot enumerate or replace itself.

get/projects/{id}/access-tokens

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/projects/{id}/access-tokens
  • Auth: HTTP bearer

Path parameters

idstring uuid required

Project ID

Query parameters

pageinteger

Page number (1-indexed) for offset pagination. Declares no schema default so the request validator does not inject one: handlers that omit page see it unset (nil) and default to 1 in code, while cursor-first endpoints (e.g. the project deployments feed) can detect its absence to stay in keyset/search mode. Supplying page selects offset pagination.

limitinteger

Number of items per page (max 100)

searchstring

Case-insensitive substring match on the resource name. See the endpoint description for supported pagination modes.

include_revokedboolean

Include tokens that can no longer authenticate — both revoked and expired ones.

Response

Successful response

pageinteger required
limitinteger required
totalinteger required
has_moreboolean required
nextstring

Changes