List API keys
Retrieve a paginated list of API keys for dashboard and administrative interfaces.
Use this to build key management dashboards, filter keys by user with externalId, or retrieve key details for administrative purposes. Each key includes status, metadata, permissions, and usage limits.
Important: Set decrypt: true only in secure contexts to retrieve plaintext key values from recoverable keys.
Required Permissions
Your root key must have one of the following permissions for basic key listing:
- api.*.read_key (to read keys from any API)
- api.<api_id>.read_key (to read keys from a specific API)
Additionally, you need read access to the API itself:
- api.*.read_api or api.<api_id>.read_api
Additional permission required for decrypt functionality:
- api.*.decrypt_key or api.<api_id>.decrypt_key
Request body
Example request
{
"apiId": "api_1234abcd",
"cursor": "key_1234abcd",
"externalId": "user_1234abcd"
}Response
Successfully retrieved paginated keys. Use the pagination cursor for additional results when hasMore: true.
Example response
{
"meta": {
"requestId": "req_123"
},
"data": [
{
"keyId": "key_1234567890abcdef",
"start": "sk_test_abc123",
"enabled": true,
"name": "Production API Key",
"createdAt": 1701425400000,
"updatedAt": 1701425400000,
"lastUsedAt": 1701425400000,
"expires": 1735689600000,
"permissions": [
"documents.read",
"documents.write"
],
"roles": [
"editor",
"viewer"
],
"credits": {
"remaining": 1000,
"refill": {
"interval": "daily",
"amount": 1000,
"refillDay": 15
}
},
"identity": {
"ratelimits": [
{
"id": "rl_1234567890abcdef",
"name": "api_requests",
"limit": 1000,
"duration": 3600000,
"autoApply": true
}
]
},
"plaintext": "sk_test_abc123def456",
"ratelimits": [
{
"id": "rl_1234567890abcdef",
"name": "api_requests",
"limit": 1000,
"duration": 3600000,
"autoApply": true
}
]
}
],
"pagination": {
"cursor": "eyJrZXkiOiJrZXlfMTIzNCIsInRzIjoxNjk5Mzc4ODAwfQ==",
"hasMore": true
}
}Changes
Changed in 6 of the 90 revisions of this API.7
- ○
the endpoint scheme security
dashboardwas removed from the APIapi-security-removed
- ○
the endpoint scheme security
rootKeywas removed from the APIapi-security-removed
This revision also has 5 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ○
- ○
the response property
paginationbecame required for the status200response-property-became-required
- ○
- ○
the endpoint scheme security
dashboardwas added to the APIapi-security-added
This revision also has 1 change that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ○
- ○
added the optional property
data/items/lastUsedAtto the response with the200statusresponse-optional-property-added
- ○
- ○
added the non-success response with the status
429response-non-success-status-added
- ○
- ○
api operation id
listKeysremoved and replaced withapis.listKeysapi-operation-id-removed
- ○