List API Keys
Lists the caller's API keys, newest first. **No form of the secret is returned here — not even a masked one.** Each entry carries only `keyPrefix`, the first 8 characters of the key, which is enough to tell keys apart in a list. If you lose a secret, rotate the key. Session-authenticated only — an API key cannot be used to manage API keys.
Internal session cookie for local development.
In: cookie
Query Parameters
1 <= value <= 50200 <= value01-based page index. An alternative to offset.
1 <= value1Alternative spelling of limit. Takes precedence over limit when both are sent.
1 <= value <= 50Response Body
application/json
application/json
curl -X GET "https://example.com/api/v1/api-keys"{ "success": true, "message": "API keys fetched successfully", "data": { "items": [ { "id": "cmnu7awv4000063lk18zpon2m", "name": "My Documentation Key", "keyPrefix": "vw_a1b2c", "isActive": true, "createdAt": "2026-04-11T10:37:35.584Z", "lastUsed": "2026-04-25T19:35:44.409Z" } ], "total": 1, "limit": 20, "offset": 0, "page": 1, "pageSize": 20, "totalPages": 1, "hasMore": false, "pagination": { "mode": "offset", "nextOffset": null, "nextCursor": null } }}API Keys Module
Manage programmatic access tokens for external integrations and developer tools.
Get API KeyGET
Returns the full metadata record for one of the caller's keys — name, scopes, rate limit, expiry, revocation state, and last-used timestamp. **The secret is not returned**, and cannot be: only an HMAC-SHA256 hash of it is stored. If you have lost a key's value, rotate it. `keyPrefix` and `keySuffix` are the only fragments kept, and neither is enough to reconstruct the key. Session-authenticated only — an API key cannot be used to manage API keys.