Skip to content
GET
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/service-principals/{principalId}/api-keys

List API Keys for an Environment-scoped ServicePrincipal

Return bounded safe credential metadata without any secret or hash.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
stringA Cantora Project identifier, prefixed with `proj_`.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
stringA Cantora Environment identifier, prefixed with `env_`.
  • maximum length 64
  • pattern ^env_[\s\S]+$
principalIdpathYes
The Principal to address.
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
cursorqueryNo
The opaque continuation token returned by the preceding page.
string
  • maximum length 2048
  • minimum length 1
  • pattern ^[A-Za-z0-9_-]+$
limitqueryNo
The maximum number of resources to return, from 1 through 100.
string
  • pattern ^[+-]?\d*\.?\d+(?:[Ee][+-]?\d+)?$

Responses

200ApiKeyPage
application/json
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json

Reusable schemas

ApiKeyPageEncoded

object
  • unknown properties allowed false
itemsrequired
arrayThe resources in this page, in stable order.
nextCursorrequired
The opaque continuation token for the next page, or null after the final page.
Any of
string
  • maximum length 2048
  • minimum length 1
  • pattern ^[A-Za-z0-9_-]+$
null

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ApiKeyMetadataEncoded

object
  • unknown properties allowed false
apiKeyIdrequired
stringThe identifier of the issued API key.
  • maximum length 64
  • pattern ^apikey_[\s\S]+$
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
creationIdempotencyKeyrequired
The caller-chosen issuance key that identifies this committed credential.
Any of
null
namerequired
stringThe human-readable resource name.
displayPrefixrequired
stringThe non-secret leading characters used to distinguish this credential.
createdByPrincipalIdrequired
stringThe Principal that created this immutable record.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time
expiresAtrequired
stringWhen the resource expires, in UTC, or null when it does not expire.
  • format date-time
lastUsedAtrequired
Approximately when this credential was last presented, in UTC, or null before its first use.
  • format date-time
Any of
string
null
revokedAtrequired
When the resource was revoked, in UTC, or null while it remains active.
  • format date-time
Any of
string
null
revokedByPrincipalIdrequired
The Principal that revoked this resource, or null while it remains active.
Any of
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
null

IdempotencyKey

stringA caller-chosen key of 1–200 visible ASCII characters that makes an identical request safe to retry.
  • maximum length 200
  • minimum length 1
  • pattern ^[!-~]+$