Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Query Parameters

limit
integer

How many keys to return, 1 to 200. A larger value is refused, not shortened, so a caller is never left believing they received everything they asked for.

Required range: 1 <= x <= 200
before
string

Opaque cursor from a previous page's nextBefore. Returns only keys older than it. Treat it as opaque: its form is not part of this contract. An empty value is refused rather than read as no cursor, because that reads back as an org with no keys.

Response

A page of the org's keys.

A page of API keys, newest first.

keys
object[]
required

For an admin, the full summary. For a member, the same entries without lastUsedAt or rotatedFrom.

Maximum array length: 200
nextBefore
string

Send back as before for the next page. ABSENT on the last page, which is how paging ends.