Skip to content

API keys

List API keys

Returns all keys of the workspace, newest first. Revoked keys stay in the list with revoked: 1. The secret key itself is never included.

GET/api/v1/keys
  • Console only: owner or admin
  • Workspace: X-Tenant-ID

Headers

  • Cookiestringrequired

    The whatsappx_session cookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.

    Example
    whatsappx_session=…
  • X-Tenant-IDuuidrequired

    Workspace id. Required for session requests. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Response

200 OKapplication/json

  • []array<APIKey>

    Keys, newest first.

    Show child attributesHide child attributes7
    • iduuid

      Key id. Use it to delete the key.

    • namestring

      Name you gave the key.

    • prefixstring

      First 16 characters of the key (for example pk_live_3f9a1c0b), so you can recognise it.

    • scopeenum

      read or write.

    • created_atinteger

      Creation time in Unix seconds.

    • expires_atinteger

      Expiry time in Unix seconds (365 days after creation).

    • revokedinteger

      1 once the key has been deleted (revoked), otherwise 0.

Status codes

  • 200OK. An array of keys (not wrapped in an object).
  • 401Unauthorized. No signed-in session (unauthorized).
  • 403Forbidden. API keys can never call this endpoint (API keys cannot administer workspaces). A signed-in user who is not an owner or admin gets admin required; a user who is not a member of the workspace gets forbidden.
  • 500Server error. The keys could not be loaded.