List Caller API Keys
GET /admin/v1/api_keys
GET /admin/v1/api_keysInteractive request editor loads with JavaScript.
Authorization
AdminBearer AuthorizationBearer <token>
Admin key from config.admin.admin_keys.
In: header
Response Body
application/json
application/json
application/json
curl -X GET "http://127.0.0.1:3001/admin/v1/api_keys"OK
[
{
"id": "string",
"revision": 0,
"value": {
"allowed_agents": [
"string"
],
"allowed_models": [
"string"
],
"disabled": false,
"expires_at": "2019-08-24T14:15:22Z",
"key_hash": "string",
"mcp_access": {
"allow": [
"string"
],
"deny": [
"string"
]
},
"rate_limit": {
"concurrency": 0,
"rpd": 0,
"rph": 0,
"rpm": 0,
"rps": 0,
"tpd": 0,
"tpm": 0
}
}
}
]Missing or invalid admin key
{
"error_msg": "string"
}Configuration store operation failed
{
"error_msg": "string"
}Complete operation details and schema variants
GET /admin/v1/api_keys
List Caller API Keys
List caller API keys with plaintext credentials redacted.
Parameters
Responses
200: OK[].id(string, required): Resource ID, as assigned by the active resource source.[].revision(integer, required): Monotonic resource revision: the etcd mod_revision of the entry, or the load generation in file mode.[].value(object, required): Stored caller API key configuration with plaintext credentials redacted.- allOf variant 1
[].value.allowed_agents(array,null, optional): A2A agents this key may reach, named by their registered names. Entries are matched as single-*globs:"*"grants every agent and an entry without a*matches one agent exactly. When omitted, set tonull, or set to an empty list, the key has no A2A agent access — access is granted explicitly.[].value.allowed_models(array, required): Model aliases this caller API key may use.[].value.disabled(boolean, optional): Administratively disabled. A disabled key is rejected with401until it is enabled again; the key itself is preserved.[].value.expires_at(string,null, optional): RFC 3339 timestamp after which the key stops authenticating. Requests presenting an expired key are rejected with401. When omitted or set tonull, the key never expires.[].value.key_hash(string, required): SHA-256 hash of the caller-facing plaintext key.[].value.mcp_access(object,null, optional): This key's own layer of the MCP tool ACL, as namespaced<server>__<tool>glob patterns. Intersected with the environment and team MCP access policies: every present layer must allow a tool and no layer may deny it. When omitted the key adds no constraint of its own; with no layer present anywhere the grant is empty.[].value.mcp_access.allow(array, required): Namespaced<server>__<tool>glob patterns this key allows, intersected with the environment and team layers.[].value.mcp_access.deny(array, optional): Namespaced<server>__<tool>glob patterns subtracted from this key's effective grant. Deny always wins.[].value.rate_limit(object, optional): Request, token, and concurrency limits for this key.- allOf variant 1
[].value.rate_limit.concurrency(integer,null, optional): Max concurrent in-flight requests.[].value.rate_limit.rpd(integer,null, optional): Requests per 86,400-second window.[].value.rate_limit.rph(integer,null, optional): Requests per 3,600-second window. There is no per-hour token limit field.[].value.rate_limit.rpm(integer,null, optional): Requests per 60-second window.[].value.rate_limit.rps(integer,null, optional): Requests per 1-second window. There is no per-second token limit field.[].value.rate_limit.tpd(integer,null, optional): Tokens per 86,400-second window.[].value.rate_limit.tpm(integer,null, optional): Tokens per 60-second window.401: Missing or invalid admin keyerror_msg(string, required): Human-readable error message.500: Configuration store operation failed Response fields (application/json): identical toGET /admin/v1/api_keys, response 401 above.
cURL
curl -X GET 'http://127.0.0.1:3001/admin/v1/api_keys'