# List the org's API keys

`GET /o/{org}/api-keys`

Every live key, without its secret. Org admins only, signed in; an API key cannot call this.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `org` | path | string | yes | The org's slug or id. A caller with no role in the org gets `404`. |

## Example request

```bash
curl "https://api.prix.dev/o/$RUSH_ORG/api-keys" \
  -H "Authorization: Bearer $RUSH_TOKEN"
```

```typescript
const org = process.env.RUSH_ORG;

const res = await fetch(`https://api.prix.dev/o/${org}/api-keys`, {
  headers: {
    Authorization: `Bearer ${process.env.RUSH_TOKEN}`,
  },
});

console.log(res.status, await res.json());
```

```python
import os

import requests

org = os.environ["RUSH_ORG"]

res = requests.get(
    f"https://api.prix.dev/o/{org}/api-keys",
    headers={"Authorization": f"Bearer {os.environ['RUSH_TOKEN']}"},
)

print(res.status_code, res.json())
```

## Responses

### 200

The keys.

- `data` (array of ApiKey, required)
  - `id` (string, required): `key_…`; use it in the key routes.
  - `name` (string, required)
  - `prefix` (string, required): The secret's first characters, to tell keys apart.
  - `scopes` (array of string, required)
  - `max_concurrent` (integer, required)
  - `webhook_url` (string | null, required)
  - `expires_at` (string | null, required)
  - `created_by` (object, required)
    - `id` (string, required)
    - `email` (string | null, required)
  - `last_used_at` (string | null, required)
  - `created_at` (string, required)
  - `secret` (string, optional): The key's secret. Only in the create and rotate responses; never shown again.
  - `webhook_secret` (string, optional): The webhook signing secret. Only in the update response that minted it.

### 401

No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.

### 404

No such resource for the caller, including one that exists in an org the caller cannot see.

## Example response (200)

```json
{
  "data": [
    {
      "id": "key_Zq3T9vB1mN4pX8cR2wYe",
      "name": "ci-runner",
      "prefix": "rk_live_Q7f2",
      "scopes": [
        "runs:read",
        "runs:write"
      ],
      "max_concurrent": 4,
      "webhook_url": "https://hooks.acme.dev/rush",
      "expires_at": "2027-01-01T00:00:00.000Z",
      "created_by": {
        "id": "5b8e2c1d-3f4a-4b6c-9d7e-8f9a0b1c2d3e",
        "email": "dana@acme.dev"
      },
      "last_used_at": "2026-10-06T15:20:41.000Z",
      "created_at": "2026-10-06T15:00:00.000Z"
    }
  ]
}
```
