Skip to main content
GET
JavaScript
Everything about a key except the one thing you might be hoping for: spec.token is omitted on every read. That is the security model, not an oversight. If you need the raw value again, rotate.
The scope list you read back can be shorter than the one you sent at creation: stored scopes are normalized, so objectives:manage absorbs objectives:read. See how scopes work.

List API keys

Every key in the workspace at once.

Rotate an API key

The only way to see a token again.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

workspaceId
string
required

The workspace the API key belongs to (path).

Example:

"workspace_01HXKD2E5NQM3T9AYWCF133E3Q"

id
string
required

The API key to retrieve.

Example:

"apikey_01HXKD2E5NQM3T9AYWCFCSPNQY"

Response

OK

An API key. Every key belongs to exactly one workspace and is managed via the workspace-scoped API key routes. The only exception is the system-managed global account key, which spans all workspaces and is managed via the account global_api_key routes.

metadata
object
required

AccountResourceMetadata is used to represent a resource that is associated to an account but not to a workspace.

spec
object
required

Configuration for an API key.

state
enum<string>
required
read-only

The current lifecycle state of the API key. Output only. Keys are created STATE_ENABLED; use the :disable and :enable actions to transition between states.

Available options:
STATE_UNSPECIFIED,
STATE_ENABLED,
STATE_DISABLED
info
object