ApiKeyList

  • data
    Type: array object[] · ApiKey[]
    required

    The account’s API keys.

    Metadata about an API key. The secret itself is never included here.

    • actor
      Type: string | null
      required

      Audit label recorded when this token was delegated for a sub-agent, or null. Set via the actor field of POST /v1/token.

    • createdAt
      Type: string
      required

      ISO 8601 timestamp of when the key was created.

    • expiresAt
      Type: string | null
      required

      ISO 8601 timestamp when the key expires and stops authenticating, or null if it never expires.

    • id
      Type: string
      required

      Unique key identifier (prefixed key_). Use it to revoke the key.

    • keyPrefix
      Type: string
      required

      The non-secret prefix of the key, safe to display so you can tell keys apart. The full secret is only ever returned once, at creation.

    • lastUsedAt
      Type: string | null
      required

      ISO 8601 timestamp the key was last used to authenticate, or null if never.

    • name
      Type: string
      required

      Human-readable label for the key.

    • parentKeyId
      Type: string | null
      required

      For a delegated token (minted via POST /v1/token), the id of the key it was derived from; null for a root key. Revoking the parent invalidates this token.

    • revokedAt
      Type: string | null
      required

      ISO 8601 timestamp the key was revoked, or null if still active.

    • scopes
      Type: array string[] | null
      required

      The capabilities this key is limited to, as a list of scope tokens (e.g. submissions:read) plus optional form:<id> constraints. null means the key is unrestricted (full account access).