---
title: "List"
method: GET
path: "/credentials"
tags: ["Credentials"]
---

# List

`GET /credentials`

List all tunnel authtoken credentials on this account

## Query parameters

- `before_id` string
- `limit` string
- `filter` string

## Headers

- `ngrok-version` integer, required

## Response `200`

List all tunnel authtoken credentials on this account

- CredentialList
  - `credentials` Credential[] — the list of all tunnel credentials on this account
    - `id` string — unique tunnel credential resource identifier
    - `uri` string — URI of the tunnel credential API resource
    - `created_at` string — timestamp when the tunnel credential was created, RFC 3339 format
    - `description` string — human-readable description of who or what will use the credential to authenticate. Optional, max 255 bytes.
    - `metadata` string — arbitrary user-defined machine-readable data of this credential. Optional, max 4096 bytes.
    - `token` string — the credential's authtoken that can be used to authenticate an ngrok agent. **This value is only available one time, on the API response from credential creation, otherwise it is null.**
    - `acl` string[] — optional list of ACL rules. If unspecified, the credential will have no restrictions. The only allowed ACL rule at this time is the `bind` rule. The `bind` rule allows the caller to restrict what domains, addresses, and labels the token is allowed to bind. For example, to allow the token to open a tunnel on example.ngrok.io your ACL would include the rule `bind:example.ngrok.io`. Bind rules for domains may specify a leading wildcard to match multiple domains with a common suffix. For example, you may specify a rule of `bind:*.example.com` which will allow `x.example.com`, `y.example.com`, `*.example.com`, etc. Bind rules for labels may specify a wildcard key and/or value to match multiple labels. For example, you may specify a rule of `bind:*=example` which will allow `x=example`, `y=example`, etc. A rule of `'*'` is equivalent to no acl at all and will explicitly permit all actions.
    - `owner_id` string — If supplied at credential creation, ownership will be assigned to the specified User or Service User. Only admins may specify an owner other than themselves. Defaults to the authenticated User or Service User. Accepts one of: User ID, User email, or SCIM User ID.
  - `uri` string — URI of the tunnel credential list API resource
  - `next_page_uri` string — URI of the next page, or null if there is no next page

## Other responses

- `4XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.
- `5XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.

## Changes

- **2025-12-16** `602cd080d3a7` — 1 info
  - added the new optional `query` request parameter `filter`

[Change history](https://skmtc.dev/ngrok/apis/ngrok-openapi/changes/credentials/get.md)

---

[API](https://skmtc.dev/ngrok/apis/ngrok-openapi.md) · [All operations](https://skmtc.dev/ngrok/apis/ngrok-openapi/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ngrok/ngrok-openapi/revisions/c697539ac350/schema)
