List a tenant's API keys
Lists every key that can act in the tenant, active and revoked, oldest first, and never their secrets — incident response needs to see what exists before deciding what dies.
/v1/tenants/{tenantId}/api_keysLists every key that can act in the tenant, active and revoked, oldest first, and never their secrets — incident response needs to see what exists before deciding what dies.
Requires a staff token with a platform role. Merchant-bound keys appear here too, carrying the merchant's id; a tenant key carries a null one.
Note that the objects in keys are serialised with Go field names
(ID, TenantID, …), not the snake_case used elsewhere on the
platform. This is documented as it is rather than as it ought to be;
changing it would break existing portal callers.
Authorization
staffToken A portal staff session JWT (typ=staff), either minted by this service through POST /v1/auth/login or, where SSO is configured, issued by the configured identity realm. The operator endpoints additionally require a platform role (platform_ops or global_admin).
In: header
Path Parameters
The tenant's uuid.
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/v1/tenants/497f6eca-6276-4993-bfeb-53cbbbba6f08/api_keys"{ "keys": [ { "ID": "4a1f8e6b-2c3d-4e5f-9a8b-7c6d5e4f3a2b", "TenantID": "2b9a0c55-2d3e-4a19-8f77-0c9a1b2d3e4f", "ClientID": null, "Env": "live", "Name": "checkout-backend", "Scopes": [ "users:write", "transfers:write" ], "Status": "active", "CreatedAt": "2026-09-20T09:00:00Z", "ExpiresAt": "2027-09-20T09:00:00Z", "LastUsedAt": null } ]}