---
title: "List API keys"
method: GET
path: "/api-keys"
tags: ["API Keys"]
---

# List API keys

`GET /api-keys`

Get API keys for the user's party.

## Query parameters

- `status` 'ACTIVE' | 'REVOKED' — Filter by status (ACTIVE or REVOKED)
- `cursor` string — Cursor for pagination
- `limit` integer — Max items per page

## Headers

- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Response `200`

Successful Response

- object
  - `data` object[], required
    - `type` 'apiKey', required — Resource type
    - `id` string, required — Resource ID
    - `attributes` object, required — Resource attributes
      - `apiKeyPrefix` string, required — Non-secret prefix of the API key, e.g. `sk_ntl_live_abc123`. The final segment is random.
      - `name` string, required — Human-readable name
      - `scopes` string[], required — Authorized scopes
      - `environment` 'sandbox' | 'prod', required — Environment
      - `status` 'ACTIVE' | 'REVOKED', required — Status (ACTIVE or REVOKED)
      - `createdAt` string, date-time, required — When this key was created
      - `lastUsedAt` string, date-time, nullable, required — When this key was last used
      - `revokedAt` string, date-time, nullable, required — When this key was revoked
      - `createdBy` string, nullable, required — User who created this key (usr_*)
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*)
    - `relationships` object, required — Resource relationships
      - `party` object, required — Party that owns the API key
        - `data` object, required — Related resource identifier
          - `type` 'party', required — Resource type
          - `id` string, required
  - `meta` object, required
    - `pagination` object, required
      - `hasMore` boolean, required
      - `nextCursor` string, nullable, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found — returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/8cc2aed45847/schema)
