API7 Docs

List Consumer Credentials

GET /apisix/admin/consumers/{username}/credentials

GET /apisix/admin/consumers/{username}/credentials

Interactive request editor loads with JavaScript.

Authorization

X-API-KEY<token>

Admin API key configured in config.yaml under deployment.admin.admin_key. You can also pass the key as a query parameter api_key or cookie x_api_key.

In: header

Path Parameters

username*string

Consumer username.

Match^[a-zA-Z0-9_\-]+$
Length1 <= length <= 256

Query Parameters

name?string

Filter list by name (regex match).

label?string

Filter list to resources with the given label key.

page?integer

Page number (1-based).

Range1 <= value
Default1
page_size?integer

Items per page (10–500). When omitted, no pagination is applied and the full list is returned.

Range10 <= value <= 500

Response Body

application/json

application/json

curl -X GET "http://127.0.0.1:9180/apisix/admin/consumers/jack/credentials?label=env&page=1&page_size=20"

Successful response.

{
  "total": 2,
  "list": [
    {
      "key": "/apisix/consumers/john/credentials/cred-john-basic-auth",
      "value": {
        "update_time": 1725991703,
        "id": "cred-john-basic-auth",
        "plugins": {
          "basic-auth": {
            "password": "john-pass",
            "username": "john-key"
          }
        },
        "create_time": 1725991529
      },
      "createdIndex": 42,
      "modifiedIndex": 44
    },
    {
      "key": "/apisix/consumers/john/credentials/cred-john-key-auth",
      "value": {
        "update_time": 1725991703,
        "id": "cred-john-key-auth",
        "plugins": {
          "key-auth": {
            "key": "john-key"
          }
        },
        "create_time": 1725991703
      },
      "createdIndex": 43,
      "modifiedIndex": 43
    }
  ]
}
Complete operation details and schema variants

GET /apisix/admin/consumers/{username}/credentials

List Consumer Credentials

Retrieve all credentials for a specific consumer.

Parameters

  • username (path, string, required): Consumer username.
  • name (query, string, optional): Filter list by name (regex match).
  • label (query, string, optional): Filter list to resources with the given label key.
  • page (query, integer, optional): Page number (1-based).
  • page_size (query, integer, optional): Items per page (10–500). When omitted, no pagination is applied and the full list is returned.

Responses

  • 200: Successful response.
  • total (integer, required):
  • list (array, required):
  • list[].key (string, required):
  • list[].value (object, required): Credential configuration. Stores exactly one authentication plugin for a consumer.
  • list[].value.id (object, optional): Unique identifier for the resource. Can be a string (1–64 characters, alphanumeric with -, _, .) or a positive integer.
  • anyOf variant 1: String ID
  • anyOf variant 2: Integer ID
  • list[].value.name (string, optional): Human-readable name.
  • list[].value.desc (string, optional): Description of this credential.
  • list[].value.labels (object, optional): Key-value pairs for categorizing and filtering resources. Values must be non-empty strings (max 256 characters).
  • list[].value.create_time (integer, optional): Unix timestamp of creation. Read-only.
  • list[].value.update_time (integer, optional): Unix timestamp of last update. Read-only.
  • list[].value.plugins (object, optional): Exactly one authentication plugin configuration (e.g., key-auth, basic-auth, jwt-auth).
  • list[].createdIndex (integer, optional):
  • list[].modifiedIndex (integer, optional):
  • 401: Unauthorized — The API key is missing, invalid, or lacks permission.
  • error_msg (string, required): Authentication error message.
  • description (string, optional): Detailed reason for the authentication failure.

cURL

curl -X GET 'http://127.0.0.1:9180/apisix/admin/consumers/{username}/credentials'