---
title: "List API keys"
method: GET
path: "/api-keys"
tags: ["API Keys"]
---

# List API keys

`GET /api-keys`

List API keys

## Query parameters

- `status` 'ACTIVE' | 'REVOKED' — Filter by status (ACTIVE or REVOKED).
- `cursor` string — Cursor from the previous page.
- `limit` integer — Maximum results per page.

## Headers

- `X-Instance-ID` string, nullable

## Response `200`

Successful Response

- object
  - `data` object[], required
    - `type` 'apiKey', required
    - `id` string, required — API key ID (apy_*).
    - `attributes` object, required
      - `apiKeyPrefix` string, required — Non-secret prefix of the API key, e.g. `sk_ntl_prod_abc123`.
      - `name` string, required — API key name.
      - `scopes` string[], required — Authorized scopes.
      - `environment` 'sandbox' | 'prod', required — Environment.
      - `status` 'ACTIVE' | 'REVOKED' | 'UNKNOWN', required — API key status.
      - `createdAt` string, date-time, required — When this key was created.
      - `lastUsedAt` string, date-time, nullable, required — When this key was last used.
      - `revokedAt` string, date-time, nullable, required — When this key was revoked.
      - `createdBy` string, nullable, required — User who created this key (usr_*).
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*).
      - `tags` object, required — Metadata visible to anyone who can read the resource.
    - `relationships` object, required
      - `party` object, required — Party that owns the API key.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required
  - `meta` object, required
    - `pagination` object, required
      - `hasMore` boolean, required — Whether more results are available.
      - `nextCursor` string, nullable, required — Cursor for the next page, or null when there are no more results.

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 info
  - `header` request parameter `X-Agent-ID` was deprecated
- **2026-08-14** `7271de071ca5` — 1 info
  - added the required property `data/items/attributes/tags` to the response with the `200` status
- **2026-07-26** `270e233e401c` — 2 warning
  - for the `query` request parameter `cursor`, the maxLength was set to `1024`
  - added the new `UNKNOWN` enum value to the `data/items/attributes/status` response property for the response status `200`

[Change history](https://skmtc.dev/natural/apis/natural-api/changes/api-keys/get.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/25b811746e7a/schema)
