---
title: "Get an API key"
method: GET
path: "/v1/api-keys/{label}"
tags: ["API Keys"]
---

# Get an API key

`GET /v1/api-keys/{label}`

Returns one live (ACTIVE or EXPIRED) key's metadata — scopes, status, expiry, who minted it. The secret is never returned. Revoked keys are not addressable by label; list with `?status=REVOKED` instead.

## Path parameters

- `label` string, required — Label of the API key.

## Response `200`

The API key (metadata only)

- ApiKey
  - `label` string, required — Human-readable label. Unique per workspace.
  - `keyPrefix` string, required — Display prefix of the key (e.g. "monid_test_a1b2c3d4...").
  - `owner` string, required — User id the key belongs to (bills to, listed under). Always a user; a child key inherits its parent's owner.
  - `createdBy` string, required — Who minted the key — `USER#<id>` (dashboard), `API_KEY#<fingerprint>` (another key), `AEP#<did>` (AEP grant) — an actor id: `USER#<userId>` (dashboard), `API_KEY#<fingerprint>` (another key), `AEP#<did>` (an enrolled agent), `CLERK`, `SYSTEM`.
  - `scopes` string[], required — Scope grants: `{resource}:{action}` over runs, resources, wallet, topups, controls and api_keys with read/create/update/delete, plus `{resource}:*` and `*`. Catalog reads need no scope. Fixed at creation.
  - `status` 'ACTIVE' | 'EXPIRED' | 'REVOKED', required — ACTIVE, EXPIRED (derived from expiresAt) or REVOKED. Only ACTIVE keys authenticate.
  - `origin` 'DASHBOARD' | 'API' | 'AEP' | 'SYSTEM', required — Channel the key was minted through — derived from `createdBy`: DASHBOARD, API, AEP or SYSTEM.
  - `expiresAt` string, date-time — Expiry (ISO 8601). Absent ⇒ never expires.
  - `revokedAt` string, date-time — When the key was revoked. Present only when REVOKED.
  - `revokedBy` string — Who revoked the key (present only when REVOKED) — an actor id: `USER#<userId>` (dashboard), `API_KEY#<fingerprint>` (another key), `AEP#<did>` (an enrolled agent), `CLERK`, `SYSTEM`.
  - `createdAt` string, date-time, required — Creation time (ISO 8601).
  - `lastUsedAt` string, date-time — Last time the key authenticated a request. Absent if never used.

## Other responses

- `400` — Bad request — input failed validation
- `401` — Unauthorized — missing or invalid credentials
- `403` — Forbidden — caller has no workspace or no access
- `404` — API key not found in this workspace
- `500` — Internal server error

## Changes

- **2026-09-25** `5abada71ceae` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/monid/apis/monid-api/changes/v1/api-keys/:label/get.md)

---

[API](https://skmtc.dev/monid/apis/monid-api.md) · [All operations](https://skmtc.dev/monid/apis/monid-api/llms.txt) · [OpenAPI document](https://skmtc.dev/monid/apis/monid-api/revisions/5abada71ceae?raw)
