List the org's API keys

GET/o/{org}/api-keys
View .md

Every live key, without its secret. Org admins only, signed in; an API key cannot call this.

Authenticate with a signed-in session token (an API key cannot call this route).

Path parameters

orgstringrequired

The org's slug or id. A caller with no role in the org gets 404.

Responses

200The keys.
dataarray of ApiKeyrequired
12 item fields
idstringrequired

key_…; use it in the key routes.

namestringrequired
prefixstringrequired

The secret's first characters, to tell keys apart.

scopesarray of stringrequired
max_concurrentintegerrequired
webhook_urlstring | nullrequired
expires_atstring | nullrequired
Format date-time
created_byobjectrequired
2 fields
idstringrequired
emailstring | nullrequired
last_used_atstring | nullrequired
Format date-time
created_atstringrequired
Format date-time
secretstringoptional

The key's secret. Only in the create and rotate responses; never shown again.

webhook_secretstringoptional

The webhook signing secret. Only in the update response that minted it.

401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
404No such resource for the caller, including one that exists in an org the caller cannot see.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional