---
title: "Find all Secret Keys"
method: GET
path: "/secret-keys"
tags: ["Secret Keys"]
---

# Find all Secret Keys

`GET /secret-keys`

Retrieve a paginated list of Secret Keys

## Query parameters

- `id` object
  - `eq` string
  - `ne` string
  - `like` string
  - `in` string[]
  - `nin` string[]
  - `contains` string
- `createdAt` object
  - `eq` string, date-time
  - `ne` string, date-time
  - `gt` string, date-time
  - `gte` string, date-time
  - `lt` string, date-time
  - `lte` string, date-time
  - `in` string[]
  - `nin` string[]
  - `contains` string, date-time
- `updatedAt` object
  - `eq` string, date-time
  - `ne` string, date-time
  - `gt` string, date-time
  - `gte` string, date-time
  - `lt` string, date-time
  - `lte` string, date-time
  - `in` string[]
  - `nin` string[]
  - `contains` string, date-time
- `active` object
  - `eq` boolean
  - `ne` boolean
  - `contains` boolean
- `sortDirection` 'ASC' | 'DESC' | 'asc' | 'desc'
- `sortBy` 'id' | 'createdAt' | 'updatedAt'
- `page` number
- `pageSize` number
- `limit` number
- `cursor` string

## Response `200`

OK

- object
  - `pagination` union
    - OffsetPageMetaDTO
      - `mode` 'offset', required — Discriminator identifying offset-based pagination metadata.
      - `pageSize` number, required — Number of items per page.
      - `hasNextPage` boolean, required — Whether a next page exists.
      - `hasPreviousPage` boolean, required — Whether a previous page exists.
      - `page` number, required — Current page number (1-indexed).
      - `itemCount` number, required — Total number of items across all pages.
      - `pageCount` number, required — Total number of pages.
    - CursorPageMetaDTO
      - `mode` 'cursor', required — Discriminator identifying cursor-based pagination metadata.
      - `pageSize` number, required — Number of items per page.
      - `hasNextPage` boolean, required — Whether a next page exists.
      - `hasPreviousPage` boolean, required — Whether a previous page exists.
      - `nextCursor` string, nullable, required — Opaque cursor for fetching the next page. Null when there is no next page.
      - `prevCursor` string, nullable, required — Opaque cursor for fetching the previous page. Null when there is no previous page.
  - `data` SecretKeyPartialDTO[]
    - `createdAt` string, date-time, required — The date and time when the entity was created.
    - `updatedAt` string, date-time, nullable, required — The date and time when the entity was last updated.
    - `metadata` object, nullable — Metadata used by merchants to store additional information about the entity.
    - `id` string, required — Unique identifier of the secret key
    - `active` boolean, required — Whether the secret key is active and can be used for API authentication
    - `maskedValue` string, required — Masked representation of the secret key, showing only the last four characters
    - `note` string, nullable, required — User-provided note for identifying this secret key
    - `permissions` string[], required — Permissions of the secret key

## Other responses

- `202` — The merchant is entitled but its environment is not provisioned yet. Provisioning has been kicked off (exactly once) and is in progress; retry the request — it succeeds once the environment is ready. Returned only for identity-token (dashboard) requests bound to a merchant, not for secret-key API calls; any such endpoint can return it while provisioning is underway.
- `400` — The request was rejected. `type` is `invalid_request_error` when the request itself is at fault — `errors` then lists every problem found, with field-attributable entries prefixed by the field’s path; `invalid_state_error` when the request was well-formed but the resource is not in a state that allows it; or `payment_error` when the payment was refused by the issuer or processor.
- `401` — No API key was supplied, or the key is not valid. `type` is `authentication_error`.
- `403` — The API key is valid but lacks the permission this operation requires. `type` is `permission_error`.
- `429` — Too many requests. The rate limit is applied per client across all operations. `type` is `rate_limit_error`.
- `500` — The request could not be completed because of an unexpected error. `type` is `api_error`.
- `504` — The request exceeded the processing time limit and was abandoned. `type` is `api_error` and `code` is `timeout` — unlike a plain 500 the request may still have taken effect, so retry with the same idempotency key rather than blindly.

---

[API](https://skmtc.dev/odus/apis/odus-orchestration-api.md) · [All operations](https://skmtc.dev/odus/apis/odus-orchestration-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/odus/odus-orchestration-api/revisions/d5fdcba31576/schema)
