API keys
List API keys
Returns all keys of the workspace, newest first. Revoked keys stay in the list with revoked: 1. The secret key itself is never included.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Response
200 OKapplication/json
[]array<APIKey>Keys, newest first.
Show child attributesHide child attributes7
iduuidKey id. Use it to delete the key.
namestringName you gave the key.
prefixstringFirst 16 characters of the key (for example
pk_live_3f9a1c0b), so you can recognise it.scopeenumreadorwrite.created_atintegerCreation time in Unix seconds.
expires_atintegerExpiry time in Unix seconds (365 days after creation).
revokedinteger1once the key has been deleted (revoked), otherwise0.
Status codes
- 200OK. An array of keys (not wrapped in an object).
- 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden. - 500Server error. The keys could not be loaded.